Translate the terms into behavior #
| Term | Operational question |
|---|---|
| Access port | Which VLAN serves this endpoint's ordinary untagged traffic? |
| Trunk port | Which VLANs can cross the link, and how are they represented? |
| Tagged membership | Does this VLAN leave the port with an 802.1Q tag? |
| Untagged membership | Is this VLAN's tag removed on egress? |
| PVID | Which VLAN classifies an untagged frame on ingress? |
| Native VLAN | How does this platform handle untagged traffic on a trunk? |
PVID and untagged membership describe related but different directions. With ordinary VLAN filtering, a MikroTik port's PVID classifies untagged and priority-tagged ingress traffic; it does not replace a normal received nonzero VLAN ID. Membership and ingress filtering also matter. A port can therefore have the intended PVID while still permitting an unintended tagged VLAN.
Compare the complete link #
For an example uplink carrying tagged VLANs 20 and 30, write down the allowed list and untagged behavior at both ends. If untagged traffic is expected for VLAN 99, both sides must map that traffic consistently. If no untagged traffic is intended, configure and verify that behavior explicitly using the platform's supported controls.
Native VLAN behavior is not identical on every vendor or interface family. Some platforms require an explicit setting before a trunk accepts untagged data. Native tagging options further change what appears on the wire. Check the actual settings instead of assuming that a familiar default transfers across vendors.
Inspect before changing #
RouterOS bridge examples:
Inspect before changing
Vendor-neutral / RouterOS examples · RouterOS bridge CLI
/interface bridge port print detail/interface bridge vlan print detailRead PVID, admitted frame types, ingress filtering and tagged/untagged membership together. Include the bridge's CPU-facing membership when troubleshooting management or routed VLAN services. Do not enable VLAN filtering remotely until the management path is accounted for.
Follow one affected VLAN #
A trunk can carry one VLAN correctly while dropping another. Trace the failing VLAN through each hop, checking membership and learned MAC addresses. If a client receives an address from the wrong subnet, investigate untagged classification and unexpected DHCP reachability. If Layer 2 membership is correct but inter-VLAN access fails, move to gateway, routing and firewall checks; adding more allowed VLANs is not a substitute for identifying the failed stage.
Sources
Documentation reviewed: 8 October 2026