Free shipping on orders over $499* · Live warehouse stock · Competitive pricing · *See shipping details
Free shipping over $499* · *See details
Skip to content
MikroTik VLAN setup with bridge VLAN filtering how-to

MikroTik VLAN Setup Without the Headache: Bridge VLAN Filtering Explained (2026)

No MikroTik topic generates more confused forum threads than VLANs. If you've come from a traditional managed switch where you just tick "tagged" and "untagged" boxes per port, RouterOS feels backwards at first — and a small mistake means no traffic, or worse, VLANs that leak into each other. The good news: on RouterOS v7 there's one correct, modern way to do it, and once it clicks it's the same every time. Here's the headache-free version.

Why MikroTik VLANs feel confusing

RouterOS doesn't have a per-port VLAN grid. Instead, VLANs live in a single bridge with VLAN filtering turned on, and you describe your network in three places: the Bridge VLAN table (which VLAN IDs exist and which ports carry them tagged or untagged), the PVID on each access port (the VLAN an untagged device lands in), and the bridge itself as a tagged member of any VLAN the router needs to route or manage. Miss one of those and it won't work. Get all three right and it's rock solid.

The modern, correct approach (RouterOS v7)

Do it in this order, and turn VLAN filtering on last:

  1. Create one bridge and add all the LAN/switch ports to it.
  2. In the Bridge VLAN table, add each VLAN ID with its members: tagged = your trunk/uplink ports and the bridge itself; untagged = the access ports for that VLAN.
  3. Set each access port's PVID to its VLAN so untagged devices land in the right place.
  4. Create your VLAN interfaces (for routing/DHCP/firewall) on the bridge, not on physical ports.
  5. Only now, enable vlan-filtering=yes on the bridge — ideally from Safe Mode or a scheduled auto-revert, because this is the step that locks people out.

The gotchas that cause 90% of the pain

  • Enabling VLAN filtering too early. Turn it on before the bridge is a tagged member of your management VLAN and you'll lock yourself out of the router. Do it last, in Safe Mode.
  • Forgetting the bridge as a tagged member. The bridge interface must be a tagged member of any VLAN it needs to manage or route — this is the single most common omission.
  • PVID vs. tagged confusion on hybrid ports. An access port gets a PVID and is untagged for that VLAN; a trunk port is tagged for every VLAN it carries and usually keeps the default PVID.
  • Mixing old and new config. Don't combine legacy switch-chip or per-interface VLAN config with bridge VLAN filtering on the same ports — pick the bridge-VLAN method and keep it consistent.

Where it runs in hardware vs. software

On MikroTik CRS switches, bridge VLAN filtering is offloaded to the switch ASIC, so it runs at wire speed — that's the right place for VLANs with real throughput. On a hAP router or CCR it's handled in software/CPU, which is perfectly fine for a home or small office but something to size for at higher loads. If you're segmenting a network of any size, put the heavy VLAN switching on a CRS and let the router handle inter-VLAN routing and firewalling.

Gear that makes this easy

For a router-plus-Wi-Fi that handles VLANs and inter-VLAN routing in one box, the hAP ax3 (or the smaller hAP ax2) is a great start. When you want hardware-offloaded VLAN switching, the CRS310-8G+2S+IN (eight 2.5G ports) or the 24-port CRS326-24G-2S+IN are the workhorses. Browse the full MikroTik lineup, and if your VLANs will carry PoE devices, our PoE switch guide helps you size the switch. Questions on a design? Javelin Networks is an authorized MikroTik reseller — ask us for a quote.

Frequently asked questions

Why does my MikroTik lose connectivity the moment I enable VLAN filtering?

Because the bridge isn't yet a tagged member of your management VLAN, so your admin traffic has nowhere to go. Add the bridge as a tagged member of the management VLAN first, then enable vlan-filtering — and do it from Safe Mode so a mistake auto-reverts.

Do I set VLANs on the physical ports or on the bridge?

On the bridge. In the modern RouterOS v7 method you use one bridge with VLAN filtering, define VLANs in the Bridge VLAN table, set PVIDs on access ports, and create VLAN interfaces on the bridge for routing.

Should I use a hAP or a CRS for VLANs?

A hAP handles VLANs in software, which is fine for home/small office. A CRS switch offloads VLAN filtering to its ASIC and switches at wire speed, so it's the better choice once throughput matters — often paired with a router for inter-VLAN routing.

What's the difference between PVID and a tagged port?

PVID is the VLAN an untagged device on an access port is placed into. A tagged (trunk) port carries 802.1Q-tagged frames for multiple VLANs. Access ports use a PVID and are untagged for that VLAN; trunks are tagged for every VLAN they carry.

Previous article Your First MikroTik Router: First-Time Setup and Securing RouterOS (2026)
Next article MikroTik SFP, SFP+ & SFP28 Compatibility: Why Your Module Won't Link (2026)