MH IT SOLUTION — Production Tech Knowledge Base & IT Troubleshooting Guides ▶ YouTube Channel

MikroTik RouterOS 7 VLAN Configuration & Bridge Trunk Setup

MH IT SOLUTION Editorial Team · Updated August 20, 2026 · 10 min readAdvanced

Master VLAN setup in MikroTik RouterOS 7 using bridge VLAN filtering, hardware offloading (L3HW), and inter-VLAN routing with DHCP servers.

Step-by-Step Video Walkthrough   Watch on YouTube ↗

Common Symptoms and Quick Fixes

Symptom Likely Cause Quick Fix
Lose access after enabling VLAN filtering Management port not in a VLAN Enable vlan-filtering last; keep a safe port
VLAN clients get no IP No DHCP on the VLAN interface Add address, pool and DHCP server per VLAN
Trunk drops tagged traffic Trunk port missing from tagged list Add the trunk to tagged= for every VLAN

Method 1: Bridge VLAN Filtering with a Trunk Port

ether1 is the trunk to your switch; ether2 and ether3 are access ports for VLAN 10 and VLAN 20. Paste in order and enable filtering last.

/interface bridge add name=bridge1 vlan-filtering=no
/interface bridge port add bridge=bridge1 interface=ether2 pvid=10
/interface bridge port add bridge=bridge1 interface=ether3 pvid=20
/interface bridge port add bridge=bridge1 interface=ether1
/interface bridge vlan add bridge=bridge1 tagged=bridge1,ether1 untagged=ether2 vlan-ids=10
/interface bridge vlan add bridge=bridge1 tagged=bridge1,ether1 untagged=ether3 vlan-ids=20
Pro Tip for AdministratorsInclude bridge1 in tagged= or the router itself cannot reach the VLAN.

Method 2: Inter-VLAN Routing and DHCP

Create a VLAN interface on the bridge, give it an address, and run DHCP on it. Repeat for VLAN 20, then enable filtering.

/interface vlan add name=vlan10 interface=bridge1 vlan-id=10
/ip address add address=192.168.10.1/24 interface=vlan10
/ip pool add name=pool10 ranges=192.168.10.10-192.168.10.200
/ip dhcp-server add name=dhcp10 interface=vlan10 address-pool=pool10 disabled=no
/ip dhcp-server network add address=192.168.10.0/24 gateway=192.168.10.1 dns-server=1.1.1.1
/interface bridge set bridge1 vlan-filtering=yes

Method 3: Check Hardware Offloading

Ports that are switched in hardware show the H flag.

/interface bridge port print

Frequently Asked Questions (FAQ)

Q: Can I use the default bridge?

Yes, but a dedicated bridge is safer because the default configuration has firewall and DHCP rules tied to the default one.

Q: Does every model support L3HW?

No. Hardware offloading depends on the switch chip; check your model on mikrotik.com.

Leave a Reply

Your email address will not be published. Required fields are marked *