Commands #
The sample bridge is bridge1. Replace the sample MAC address with the endpoint you are tracing.
Commands
RouterOS v7 · RouterOS v7 terminal; absolute menu paths
/interface/bridge/print detailReplace these example values: bridge1.
/interface/bridge/port/print detail where bridge="bridge1"Replace these example values: bridge1.
/interface/bridge/host/print where bridge="bridge1"Replace these example values: 02:00:00:00:00:10.
/interface/bridge/host/print where mac-address=02:00:00:00:00:10Replace these example values: bridge1.
/interface/bridge/vlan/print detail where bridge="bridge1"/interface/ethernet/switch/print/ip/neighbor/print detailRead the result #
In the host table, inspect the learned interface and, when VLAN filtering is enabled, the VLAN ID. Local entries describe the router's own interfaces; do not mistake them for a downstream endpoint. A downstream switch can place many client MAC addresses behind one port. The table identifies the next Layer 2 direction, not necessarily the final wall socket.
In the port view, compare PVID, frame admission and ingress filtering with the intended role. The VLAN table complements this information with tagged and untagged membership. Pay attention to current membership as well as explicit configuration, because dynamic entries can explain behaviour that is not obvious from a short export.
Hardware offload is a separate question. Check the port flags and the switch model before deciding that all bridge traffic reaches the CPU. Different chip families have different VLAN and offload capabilities. Neighbour discovery can help identify an uplink, but an absent discovery entry does not establish that the cable is disconnected.
Trace one endpoint #
Write down the endpoint MAC, expected VLAN and expected access port. Generate a small amount of normal traffic from that endpoint, then read the host table. If the address appears on an uplink, continue the same inspection on the next switch. If the address appears in the wrong VLAN, compare the ingress port's PVID and the endpoint's tagging behaviour before editing anything.
Once the ingress is accounted for, inspect the egress uplink membership. For traffic addressed to the router itself, also check the bridge CPU path and its VLAN interface. Keep the endpoint test and management access test separate in your notes.
Pitfalls #
An empty table may mean that an endpoint has been quiet or its entry aged out. It is not permission to disable VLAN filtering. Enabling use-ip-firewall also changes packet processing; it is not a visibility switch to toggle during a routine inspection. For changes that affect management reachability, use the dedicated VLAN staging guide linked below.
Sources
Documentation reviewed: 8 October 2026