mikrotik wifi vlan eth2

/interface wireless
  add master-interface=wlan1 name=wlan1.10 ssid=ssid10
  add master-interface=wlan1 name=wlan1.30 ssid=ssid30  
/interface vlan
  add vlan-id=10 interface=ether2 name=ether2.10
  add vlan-id=30 interface=ether2 name=ether2.30
/interface bridge
  add name=native
  add name=vlan1
  add name=vlan10
  add name=vlan30
/interface bridge port
  add bridge=vlan1 interface=ether2
  add bridge=vlan1 interface=wlan1
  add bridge=vlan10 interface=ether2.10
  add bridge=vlan10 interface=wlan1.10
  add bridge=vlan30 interface=ether2.30
  add bridge=vlan30 interface=wlan1.30

/certificate
add name=ca-template common-name=myCa key-usage=key-cert-sign,crl-sign
add name=server-template common-name=server

/certificate 
sign ca-template name=myCa
sign server-template ca=myCa name=server

/certificate
set myCa trusted=yes
set server trusted=yes

/radius
add address=192.168.22.6 secret=testing123 service=ppp,login,hotspot,wireless,dhcp

/interface wireless security-profiles
add authentication-types=wpa2-eap eap-methods=passthrough group-ciphers=aes-ccm \
group-key-update=5m interim-update=0s management-protection=disabled \
management-protection-key="" mode=dynamic-keys name=radius \
radius-eap-accounting=yes radius-mac-accounting=no \
radius-mac-authentication=no radius-mac-caching=disabled radius-mac-format=XX:XX:XX:XX:XX:XX radius-mac-mode=as-username-and-password static-algo-0=\
none static-algo-1=none static-algo-2=none static-algo-3=none static-key-0=""\
static-key-1="" static-key-2="" static-key-3="" static-sta-private-algo=none static-sta-private-key="" static-transmit-key=key-0 \
supplicant-identity="" tls-certificate=myCa tls-mode=dont-verify-certificate unicast-ciphers=aes-ccm wpa-pre-shared-key="" wpa2-pre-shared-key=""


# nakonec jeste pozapinat ty interface
# nezapomenout na ciscu switchport a strcit to do portu 2 na mikrotiku