Routing and access
VLAN switching and isolation
Run separate networks, such as staff, guests and cameras, over the same switches and cabling.
What it is
A virtual LAN (VLAN) divides one physical network into several separate ones. MikroTik devices can switch VLANs in a bridge, and many models can do it in hardware on a built-in switch chip. Keeping networks apart is only half of isolation: the router or firewall decides what is allowed to pass between them.
Type: Wired. Works on cabled (Ethernet) networks.
Separate staff and guests
Give visitors Internet access without reaching internal systems.
Group cameras and devices
Keep cameras, phones or building systems on their own network.
Share one cable
Carry several networks to another switch or access point over a single trunk link.
Capabilities and hardware
What RouterOS provides for this solution, as described in MikroTik's documentation. Features depend on the RouterOS version, the hardware model and its licence level.
Bridge VLAN filtering
A bridge can filter VLANs using a bridge VLAN table that states which VLANs are allowed on each port. MikroTik recommends this feature over other, error-prone VLAN setups.
Wire-speed switching on supported models
Many MikroTik devices have built-in switch chips that can switch VLANs in hardware, giving wire-speed performance when configured correctly. The method differs across models.
Hardware offloading varies
Some devices can run some bridge protocols in hardware; MikroTik documents which devices support it.
Choosing hardware
Look for managed switches and routers with several Ethernet ports. Whether VLANs are switched in hardware depends on the model's switch chip, so check the documentation for the model you plan to use.
Check before you buy. Features depend on the RouterOS version, the hardware model and its licence level, and not every MikroTik product supports every solution. Check the product page for the exact model before you buy.
Product recommendations for this solution are not listed yet: they are added once the product data is confirmed.
Help choosing
Who it helps
- Managed IT providersKeep each client's staff, guest and device networks apart on shared equipment.
When it is a good fit
- Different users or devices must not see each other's traffic
- You want to carry several networks over one cable
- You are using managed switches or routers with several ports
- You need guest and internal networks on the same equipment
- You can plan which VLANs may talk to each other
Planning your setup
- Define the networks. List the VLANs you need, what each is for, and which ports and devices belong to each.
- Decide trunk and access ports. Trunk ports carry several VLANs between switches and routers; access ports connect a device to one VLAN.
- Decide what may cross. Traffic between VLANs passes through a router, so firewall rules there decide what is allowed.
- Check hardware switching on your model. The configuration method differs between models, and hardware switching is supported on some and not others.
Related solutions
Not sure which one fits?
Tell us about your network and we will help you choose.
Talk to MikroTik CanadaSources
- MikroTik documentation: Bridge VLAN Table (checked 2026-10-01)
- MikroTik documentation: Basic VLAN switching (checked 2026-10-01)
- MikroTik documentation: Bridging and Switching (checked 2026-10-01)
Capabilities are as described in the sources when they were checked. They depend on the RouterOS version, the hardware model and its licence level: confirm them for your model before you buy.