Network tools · Vendor-neutral / RouterOS examples

Access, Trunk, Native VLAN and PVID: What Must Match

A VLAN link must agree about what arrives on the wire and how each switch classifies it. Port labels alone are insufficient. For each side, answer three questions: which VLAN receives untagged ingress frames, which VLANs are allowed, and which frames leave with a tag?

Scope: Vendor-neutral concepts with RouterOS bridge inspection commands. Vendor defaults differ; this is not a universal configuration recipe.

Translate the terms into behavior #

TermOperational question
Access portWhich VLAN serves this endpoint's ordinary untagged traffic?
Trunk portWhich VLANs can cross the link, and how are they represented?
Tagged membershipDoes this VLAN leave the port with an 802.1Q tag?
Untagged membershipIs this VLAN's tag removed on egress?
PVIDWhich VLAN classifies an untagged frame on ingress?
Native VLANHow does this platform handle untagged traffic on a trunk?

PVID and untagged membership describe related but different directions. With ordinary VLAN filtering, a MikroTik port's PVID classifies untagged and priority-tagged ingress traffic; it does not replace a normal received nonzero VLAN ID. Membership and ingress filtering also matter. A port can therefore have the intended PVID while still permitting an unintended tagged VLAN.

For an example uplink carrying tagged VLANs 20 and 30, write down the allowed list and untagged behavior at both ends. If untagged traffic is expected for VLAN 99, both sides must map that traffic consistently. If no untagged traffic is intended, configure and verify that behavior explicitly using the platform's supported controls.

Native VLAN behavior is not identical on every vendor or interface family. Some platforms require an explicit setting before a trunk accepts untagged data. Native tagging options further change what appears on the wire. Check the actual settings instead of assuming that a familiar default transfers across vendors.

Inspect before changing #

RouterOS bridge examples:

Inspect before changing
Vendor-neutral / RouterOS examples · RouterOS bridge CLI

Read-only
/interface bridge port print detail
Read-only
/interface bridge vlan print detail

Read PVID, admitted frame types, ingress filtering and tagged/untagged membership together. Include the bridge's CPU-facing membership when troubleshooting management or routed VLAN services. Do not enable VLAN filtering remotely until the management path is accounted for.

Follow one affected VLAN #

A trunk can carry one VLAN correctly while dropping another. Trace the failing VLAN through each hop, checking membership and learned MAC addresses. If a client receives an address from the wrong subnet, investigate untagged classification and unexpected DHCP reachability. If Layer 2 membership is correct but inter-VLAN access fails, move to gateway, routing and firewall checks; adding more allowed VLANs is not a substitute for identifying the failed stage.

Sources

Documentation reviewed: 8 October 2026