MikroTik VLAN setup: the simple way and bridge VLAN filtering
Last updated: 2 October 2026
A VLAN splits one cable or one switch into several separate networks, for example staff, guests and cameras. MikroTik has a simple way that is enough for most routers, and a bridge way for when the router must also act as a VLAN switch.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
Three words to know
- Tagged (trunk): frames carry the VLAN number. Used between router, switches and access points.
- Untagged (access): frames carry no number. Used for ordinary devices such as a PC or a printer.
- PVID: the VLAN an untagged frame is put into when it enters a port.
The simple way: a VLAN interface on a port
Use this when a managed switch or access point is plugged into one router port and sends the VLANs tagged. Here ether2 is that port and it is not inside a bridge.
/interface vlan add name=vlan10-staff interface=ether2 vlan-id=10
/interface vlan add name=vlan20-guest interface=ether2 vlan-id=20Each VLAN interface now behaves like a port of its own. Give each one an address and a DHCP server:
/ip address add address=192.168.10.1/24 interface=vlan10-staff
/ip pool add name=pool-staff ranges=192.168.10.10-192.168.10.254
/ip dhcp-server add name=dhcp-staff interface=vlan10-staff address-pool=pool-staff disabled=no
/ip dhcp-server network add address=192.168.10.0/24 gateway=192.168.10.1 dns-server=192.168.10.1
/ip address add address=192.168.20.1/24 interface=vlan20-guest
/ip pool add name=pool-guest ranges=192.168.20.10-192.168.20.254
/ip dhcp-server add name=dhcp-guest interface=vlan20-guest address-pool=pool-guest disabled=no
/ip dhcp-server network add address=192.168.20.0/24 gateway=192.168.20.1 dns-server=192.168.20.1More on the DHCP part in DHCP server setup. If ether2 is a port of a bridge, do not put the VLAN on the port. Put it on the bridge (interface=bridge) or use the method below.
Keep the VLANs apart
The router routes between its own networks, so guests can reach staff until you stop it:
/ip firewall filter add chain=forward in-interface=vlan20-guest out-interface=vlan10-staff action=drop comment="guests cannot reach staff"Put this rule below the rule that accepts established and related connections, so that staff can still open connections towards the guest network and get the replies. See basic firewall.
Bridge VLAN filtering: the router as a VLAN switch
Use this when devices plug straight into the router and different ports must belong to different VLANs. In the example ether2 is an access port for VLAN 10, ether3 an access port for VLAN 20, and ether5 a tagged trunk to a switch.
Do it in this order and turn filtering on last.
/interface bridge add name=bridge1 vlan-filtering=no
/interface bridge port add bridge=bridge1 interface=ether2 pvid=10 frame-types=admit-only-untagged-and-priority-tagged
/interface bridge port add bridge=bridge1 interface=ether3 pvid=20 frame-types=admit-only-untagged-and-priority-tagged
/interface bridge port add bridge=bridge1 interface=ether5 frame-types=admit-only-vlan-tagged
/interface bridge vlan add bridge=bridge1 vlan-ids=10 tagged=bridge1,ether5 untagged=ether2
/interface bridge vlan add bridge=bridge1 vlan-ids=20 tagged=bridge1,ether5 untagged=ether3
/interface vlan add name=vlan10-staff interface=bridge1 vlan-id=10
/interface vlan add name=vlan20-guest interface=bridge1 vlan-id=20The bridge itself is listed as tagged because the router needs to take part in each VLAN to give addresses and route. Add the addresses and DHCP servers on vlan10-staff and vlan20-guest exactly as in the simple way. When everything is in place:
/interface bridge set bridge1 vlan-filtering=yesHow not to lock yourself out
- Turning
vlan-filteringon changes at once which ports can reach the router. If your own port is not in the right VLAN, Winbox drops. - Keep one port outside the bridge with its own address for management, for example
ether8with 192.168.99.1/24, and work from that port. - Use Safe Mode. If the connection drops, the router undoes the change.
- Take a backup first.
Check
/interface bridge vlan print
/interface bridge port print
/interface bridge host print
/ip dhcp-server lease printA device on ether2 should get a 192.168.10.x address and one on ether3 a 192.168.20.x address.
Good to know
- On some models, mostly with RouterOS v6, bridge VLAN filtering turns off hardware offload and all traffic passes through the processor. Check the speed after you turn it on.
- The VLAN numbers must match on every switch and access point along the way.
- A hotspot or PPPoE server can run on a VLAN interface like on any other interface.
Where RadiusNest fits
RadiusNest does not create VLANs for you; that is router work. Once a VLAN interface carries a hotspot or a PPPoE server, logins on it are checked centrally like on any other interface, with the speed, data and end date of the customer's package.
Start the free trial See pricing
Questions and answers
Should I use a VLAN interface or bridge VLAN filtering?
If the VLANs arrive tagged on one port from a switch, a VLAN interface on that port is enough. Use bridge VLAN filtering when the router's own ports must be access ports of different VLANs.
Why did I lose Winbox when I turned vlan-filtering on?
Your port was not a member of the VLAN the router address sits in. Manage the router from a port outside the bridge and turn filtering on in Safe Mode.
Can VLANs talk to each other?
Yes, by default the router routes between them. Add forward drop rules between the VLAN interfaces to keep them apart.