TanodTools
EN

MikroTik VLAN generator

Describe your VLANs and which ports carry them, and get the RouterOS v7 bridge VLAN filtering configuration, ordered so filtering is switched on last.

Runs in your browser; nothing you type leaves your device

Bridge
VLANs
    Ports

      Lock-out risk. Turning on VLAN filtering cuts off any port that isn't a member of a VLAN with a router address. Test in a lab, or turn on Safe Mode (Ctrl+X in the terminal) first.

      Generates RouterOS v7 bridge VLAN filtering (the method MikroTik recommends for current devices) with one bridge. Older switch-chip menus (/interface ethernet switch) are not used. Addresses are IPv4. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.

      How to configure VLANs on a MikroTik bridge

      1. List the VLANs with an ID, a name and, for VLANs the router should route, the router's address in that VLAN.
      2. List the ports: access ports carry one VLAN untagged, trunk ports carry VLANs tagged, hybrid ports do both.
      3. Read the lock-out note, turn on Safe Mode (Ctrl+X in the terminal) and run the script; VLAN filtering is enabled in the very last line.

      Bridge VLAN filtering, the v7 way

      On current RouterOS the recommended way to run VLANs is one bridge with vlan-filtering=yes. Each bridge port has a pvid, the VLAN that untagged frames arriving on it belong to, and frame-types, which says whether it accepts untagged frames, tagged frames or both. The bridge VLAN table under /interface bridge vlan then lists, for each VLAN ID, which ports send it tagged and which untagged. With ingress-filtering=yes a port also drops tagged frames for VLANs it isn't a member of.

      The router joins a VLAN through a VLAN interface created on the bridge, with the bridge listed as a tagged member of that VLAN. That interface gets the IP address and becomes the gateway, DHCP server and firewall boundary for the VLAN. Older guides configure VLANs in the switch chip menu or with a separate bridge per VLAN; on devices that offload bridge VLAN filtering, the single-bridge method is both simpler and fast.

      Applying it safely

      • Build everything with filtering off, then enable it in one step at the end, as the script does. Use Safe Mode or a serial console when working remotely.
      • Give each routed VLAN its own DHCP server with the DHCP server generator, and keep guests away from other VLANs with forward-chain rules from the firewall generator.
      • Compare the configuration before and after with the RouterOS export diff.

      Questions

      Why does enabling vlan-filtering lock people out?

      Until vlan-filtering is on, the bridge forwards everything and VLAN settings have no effect. The moment it is switched on, frames are only accepted where the VLAN table allows them. If the port you are connected through is not a member of a VLAN that has a router address, your session drops. That is why the script turns it on last, and why Safe Mode matters: if the connection breaks, RouterOS rolls the change back.

      What is the difference between access, trunk and hybrid ports?

      An access port connects one device that knows nothing about VLANs: incoming untagged frames are put into the port's PVID and leave untagged. A trunk port connects another switch or an access point and carries several VLANs with 802.1Q tags. A hybrid port does both, typically an IP phone or access point with an untagged management or data VLAN and tagged others.

      Why is the bridge itself tagged in some VLANs?

      The bridge interface is the router's own port into the switch. For the router to have an address in a VLAN, through a VLAN interface on the bridge, the bridge must be a tagged member of that VLAN. VLANs that are only switched between ports don't need it.

      Do I still need /interface vlan on top of bridge VLAN filtering?

      Only for VLANs the router takes part in: the VLAN interface is where its IP address, DHCP server and firewall rules attach. Pure layer 2 VLANs need just the bridge VLAN table.

      Is this hardware-offloaded?

      On CRS3xx switches, and on some other devices with recent RouterOS v7, bridge VLAN filtering runs in the switch chip. On others it runs on the CPU, which costs throughput. Check the H flag on the ports in /interface bridge port print after applying.

      Is my configuration sent anywhere?

      No. The script is generated in your browser.