Stage 2 → VLAN

VLAN Generator for MikroTik Bridge and Trunk Networks

Build a VLAN plan that explains trunk/access roles before you enable bridge VLAN filtering.

Free to use · Runs locally in your browser · Last reviewed 2026-09-26
Review before deployment: Bridge VLAN filtering can disconnect management when tagged and untagged ports are wrong. Keep an out-of-band or safe-mode recovery path before enabling it.

Inputs

vlan-config.rsc
Change an input to recalculate.

How to use this result

Tagged ports carry VLAN headers; untagged ports receive and transmit frames without a tag while the bridge assigns the configured PVID. A trunk and an access port are not interchangeable. Add the bridge CPU port when the router itself must participate in the VLAN, and test management access before enabling filtering.

Related tools

Sources and safe-use notes

This page follows the RouterOS documentation and the networking standards linked below. RouterOS syntax, hardware limits, and packet direction depend on your exact release and topology. Export a backup, test one controlled case, and keep a rollback path before applying generated output.

MikroTik documentation · RouterOS manual · RFC 4632 — CIDR · RFC 6598 — shared address space · RFC 8200 — IPv6 · MikroTik Bridge VLAN filtering · MikroTik VLAN documentation