If enabling bridge VLAN filtering cuts off management, add the bridge itself to the management VLAN and put the management VLAN interface on that bridge. The recovery fixes below cover a missing CPU membership, a wrong PVID and a blocked SSH/WinBox service.
Scope: RouterOS bridge VLAN filtering; example management VLAN 99 and access VLAN 30.
Management VLAN used in the examples
Example: ether2 is a tagged trunk, ether3 is an untagged VLAN 30 port and ether4 is untagged management VLAN 99. The router has 10.42.99.1/24 on mgmt99. Set the wired administrator on ether4 to 10.42.99.10/24; this example has no DHCP server. At the far end of ether2, allow VLANs 30 and 99 tagged. Only VLAN 99 reaches the bridge CPU; VLAN 30 is switched between ports.
Fix management access from a console or recovery port
Use console or a working port outside the affected bridge. Run /interface/vlan/print detail and /ip/address/print. For this example, mgmt99 must use interface=br-vlan, vlan-id=99 and address 10.42.99.1/24. Correct a wrong parent with /interface/vlan/set [find where name=mgmt99] interface=br-vlan vlan-id=99.
If ether4 has the wrong PVID, use /interface/bridge/port/set [find where interface=ether4] pvid=99.
For a wrong static VLAN99 row, use /interface/bridge/vlan/set <VLAN99-static-row-id> tagged=br-vlan,ether2 untagged=ether4; on an existing design preserve its other required members.
If membership is correct but management is still dropped, watch /ip/firewall/filter/print stats where chain=input during a fresh connection and correct that rule’s match or position.
Safe Mode can revert uncommitted changes after the controlling session is lost. Disabling VLAN filtering removes isolation as well as the failed filter; keep untrusted ports out of that temporary recovery path.
Commit Safe Mode after verifying management and the intended VLAN boundary.
New configuration: prepare management before enabling filtering
Use console or an already tested management port outside ether2–ether4. Enter Safe Mode with Ctrl+X before editing. The following creates a new bridge on free ports. Run /interface/bridge/port/print detail first; ports already assigned to another bridge require editing that existing design rather than pasting these additions.
/interface/bridge/add name=br-vlan vlan-filtering=no ingress-filtering=yes frame-types=admit-only-vlan-tagged
/interface/bridge/port
add bridge=br-vlan interface=ether2 ingress-filtering=yes frame-types=admit-only-vlan-tagged
add bridge=br-vlan interface=ether3 pvid=30 ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged
add bridge=br-vlan interface=ether4 pvid=99 ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged
/interface/bridge/vlan
add bridge=br-vlan vlan-ids=30 tagged=ether2 untagged=ether3
add bridge=br-vlan vlan-ids=99 tagged=br-vlan,ether2 untagged=ether4
/interface/vlan/add name=mgmt99 interface=br-vlan vlan-id=99
/ip/address/add address=10.42.99.1/24 interface=mgmt99Prepare IP management before enabling filtering:
/ip/firewall/filter/print detail where chain=input
/ip/service/printIf the input policy would drop the new management source, insert this permit before that drop. Replace <input-drop-id> with its displayed rule number. In an empty input chain, omit place-before. The rule opens SSH/WinBox only from the example wired administrator.
/ip/firewall/filter/add chain=input action=accept in-interface=mgmt99 src-address=10.42.99.10 protocol=tcp dst-port=22,8291 place-before=<input-drop-id> comment="VLAN99 administrator"In the service list, the chosen service must be enabled and its address list must include 10.42.99.10 or a covering prefix. If SSH is disabled, use /ip/service/enable [find where name=ssh]. To add the new source to a restricted service list, use /ip/service/set [find where name=ssh] address=<complete-allowed-prefix-list>, preserving the recovery session’s source in that list. The firewall permit does not enable a disabled service.
Enable filtering and inspect the effective path
/interface/bridge/port/print detail
/interface/bridge/vlan/print detail/interface/bridge/set br-vlan vlan-filtering=yesRe-run both print commands after enabling filtering. For VLAN 99 expect current-tagged to include br-vlan and ether2, and current-untagged to include ether4. VLAN 30 should have ether2 tagged and ether3 untagged. From 10.42.99.10 on ether4, open a new SSH session to 10.42.99.1; an existing session alone is insufficient. Test VLAN 30 between ether3 and a host behind the far trunk using addresses in the same test subnet. VLAN 30 should not reach the router’s management IP through this bridge.
Recent RouterOS builds can add dynamic CPU memberships: VLAN interfaces add tagged bridge membership from 7.16, and switch-CPU entries appear in additional paths from 7.20. The bridge reference explains their origin; do not delete dynamic rows to imitate an older example.