The reason for the original behaviour you saw is because the ports on the MX are configured for Trunk Native VLAN 10 and Access VLAN 10 (for your environment with only the one VLAN, they are pretty much the same thing). Your computer is on the default VLAN (VLAN 1) until it hits the MX at which it is placed onto VLAN 10. When changing the switchport to VLAN 10, you mess up the tagging flow and your traffic is dropped. VLAN segmentation is definitely the way to go. What you've got above is a good start. My suggestions would be: - Keep the Management VLAN and corporate devices VLAN. I personally don't see a need for the "MX84 Appliance VLAN) - Segment the printers and other devices to a different VLAN if possible. - Remove the native VLAN on the MX ports and set the VLAN on the switch access ports instead When making changes like this, ensure you have a decent maintenance window and have someone on-site who can connect locally to the devices should they accidentally go offline from the dashboard. For example, depending on the existing config, it's very easy to take the switch offline when changing the config on the MX.
... View more