InterVLAN routing with two CRS326-24S+2Q+

Hi,

we have two CRS326-24S+2Q+ (actual OS) with the following configs:

Router 1:

# 2026-07-02 11:17:35 by RouterOS 7.23.2
# software id = xxxx-xxxx
#
# model = CRS326-24S+2Q+
# serial number = HMxxxxxxxx
/interface bridge
add name=bridge vlan-filtering=yes
/interface vlan
add interface=sfp-sfpplus24 name="vlan100" vlan-id=100
add interface=sfp-sfpplus24 name="vlan200" vlan-id=200
/interface bridge port
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus1 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus2 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus3 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus4 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus5 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus6 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus7 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus8 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus9 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus10 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus11 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus12 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus13 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus14 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus15 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus16 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus17 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus18 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus19 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus20 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus21 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus22 pvid=200
add bridge=bridge frame-types=admit-only-vlan-tagged interface=sfp-sfpplus24
/interface bridge vlan
add bridge=bridge tagged=sfp-sfpplus24 vlan-ids=100,200
/system routerboard settings
set enter-setup-on=delete-key

Router 2:

# 2026-07-02 11:20:19 by RouterOS 7.23.2
# software id = xxxx-xxxx
#
# model = CRS326-24S+2Q+
# serial number = HKxxxxxxxx
/interface bridge
add name=bridge vlan-filtering=yes
/interface vlan
add interface=sfp-sfpplus24 name="vlan100" vlan-id=100
add interface=sfp-sfpplus24 name="vlan200" vlan-id=200
/interface bridge port
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus1 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus2 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus3 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus4 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus5 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus6 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus7 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus8 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus9 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus10 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus11 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus12 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus13 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus14 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus15 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus16 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus17 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus18 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus19 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus20 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus21 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus22 pvid=100
add bridge=bridge frame-types=admit-only-vlan-tagged interface=sfp-sfpplus24
/interface bridge vlan
add bridge=bridge tagged=sfp-sfpplus24 vlan-ids=100,200
/system routerboard settings
set enter-setup-on=delete-key

Now we want to establish interVLAN routing between Vlan100 and Vlan200.
Vlan100: 192.168.0.0/24
Vlan200: 192.168.10.0/24
Windows domains with DHCP and DNS running in each VLan.
No connection to external networks like internet.

In some HowTo's/Forumtopics (https://manual.mikrotik.com/docs/bridging-and-switching/#bridge-vlan-filtering) I have read that the only steps to perform are:

/ip/address
add address=192.168.0.251/24 interface=Vlan100
add address=192.168.10.251/24 interface=Vlan200

In which Switch should these IP addresses be configured? 1 or 2 or both (with second IP)?
I had configured them in Switch 1, but cant Ping the Gateway address from a host in Vlan100, connected to Switch 1.

What am I missing?

Are these acting as switches or routers and where is a network diagram to see how they fit into a larger context? For example no idea why you are identifying two vlans vice just the management vlan ( do you have a management vlan )?

Some additional context:
This is the complete setup, no larger context, no management VLAN, the switches are configured via MAC address.

Switch1 is located at Building A
Switch2 is located in Building B
They are connected via sfp-sfpplus24
They should act as Switches.

The VLANs are built up to separate the two Windows Domains with their DHCP servers.

wrong idea NM.

Nice hw, these support hw routing: L3 Hardware Offloading | RouterOS Manual

currently routing is not cofigured, hence you'll need to add it and enable HW handling (link above)

adding addresses on both vlans is first step

check ip/settings/ip forwarding is enabled

Thnks for you answer sebastia and all others....but...
I only want to establish a simple inter vlan routing, like shown in these examples (Link to Docs)

Your link directs me to a full L3 routing config.

My setup (Switch 1 on the left):

The purpose is: Separate the two Domains on VLAN100 and VLAN200 as they handle DHCP requests.

In the given Examples (Link at top of Post) is said that the only thing to do is, to add addresses to interfaces bound to the bridge:

I added my gateway addresses, 192.168.0.251/24 -> VLAN100 and 192.168.10.251/24 -> VLAN200 on Switch 1
but I cannot ping the Gateway from a >Client connected to Port1 on the same Switch.

Anyone an idea?

My best guess, but only if you assign a management vlan on your attached windows servers.

Lets give R1 192.168.99.1/24
Lets give R2 192.168.99.2/24

I also would assign an offbridge port to ether1 and do my config from there and is an emergency access place as well. Just connect PC to ether1, change IPV4 settings to 192.168.77.2 and with username and password you should be in.

Config:

/interface bridge
add name=bridge vlan-filtering=yes frame-types=admit-only-vlan-tagged
/interface vlan
add interface=bridge name=vlanMGMT vlan-id=99
/interface bridge port
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus1 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus2 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus3 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus4 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus5 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus6 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus7 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus8 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus9 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus10 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus11 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus12 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus13 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus14 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus15 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus16 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus17 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus18 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus19 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus20 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus21 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus22 pvid=200
add bridge=bridge frame-types=admit-only-vlan-tagged interface=sfp-sfpplus24
/interface bridge vlan
add bridge=bridge tagged=bridge,sfp-sfpplus24 vlan-ids=99
add bridge=bridge tagged=sfp-sfpplus24 vlan-ids=100 { untagged auto added }
add bridge=bridge tagged=sfp-sfpplus24 vlan-ids=200 { untagged auto added }
/ip address { switch1 }
add address=192.168.77.1/32 interface=OffBridge1 network=192.168.77.0
add address=192.168.99.1/24 interface=vlanMGMT network=192.168.0.0
/interface**
add name=MGMT
/interface list members
add interface=vlanMGMT list=MGMT
add interface=OffBridge1 list=MGMT
/ip neighbor discovery-settings
set discover-interface-list=MGMT
/ip service
set winbox address=192.168.99.0/24,192.168.77.2 port=xxxxxx
/tool mac-server
set allowed-interface-list=none
/tool mac-server mac-winbox
set allowed-interface-list=MGMT
/system routerboard settings
set enter-setup-on=delete-key

It isn't clear to me what gateway address you are trying to ping from a host in vlan100.

Be aware that these are primarily switches, and while they can run RouterOS, they are not meant to be used as routers. You can compare the switching speeds with the Ethernet speeds in the specifications

If you have only a small amount of traffic to route between 192.168.0.0/24 and 192.168.10.0/24 then it can route it, but it has only a single core 650MHz CPU, so the routing performance will be significanlty less than a RB750Gr3.

In the configuration you posted, you would normally choose one of the two switches to create the vlan interfaces for vlan100 and vlan200 on, and give those vlan interfaces the ip addresses. The vlan interfaces are the switches "connection" to the routing engine (the CPU). The the switch with the two vlan interfaces, each with their own ip subnet will then have "connected routes" to both 192.168.0.0/24 and 192.168.10.0/24 subnets, and if you don't do anything to prevent it, the traffic will be routed by the CPU.

Are your backup servers also your dhcp servers?

As sebasia noted, the switches have switch chips with the ability to do L3 routing, but the routing it can do is more limited than what can be done by the CPU, but what it can do is very fast; it's like a dragster, it is very fast but not a very good for general use. For example, no stateful firewall (at least that I am aware of).

Hi buckeye, thanks for answering...

First: I'm trying to ping the Gateway 192.168.0.251 from a client connected to VLAN100. Tested from Port1/Switch1 and Port17/Switch2 both VLAN100

Second: No, the Backupdevices are Synology NAS

Next: I've changed the config of Switch2 to:

# 2026-07-02 11:20:19 by RouterOS 7.23.2
# software id = xxxx-xxxx
#
# model = CRS326-24S+2Q+
# serial number = HKxxxxxxxx
/interface bridge
add name=bridge vlan-filtering=yes
/interface vlan
add interface=sfp-sfpplus24 name="vlan100" vlan-id=100
add interface=sfp-sfpplus24 name="vlan200" vlan-id=200
/interface bridge port
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus1 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus2 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus3 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus4 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus5 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus6 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus7 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus8 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus9 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus10 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus11 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus12 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus13 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus14 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus15 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus16 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus17 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus18 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus19 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus20 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus21 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus22 pvid=100
add bridge=bridge frame-types=admit-only-vlan-tagged interface=sfp-sfpplus24
/interface bridge vlan
add bridge=bridge tagged=sfp-sfpplus24 vlan-ids=100,200
/ip/address
add address=192.168.0.251/24 interface=Vlan100
add address=192.168.10.251/24 interface=Vlan200
/system routerboard settings
set enter-setup-on=delete-key

But still pings from client connected to vlan100 to 192.168.0.251 are not successful.
client config (windows through DHCP): IP:192.168.0.65/24 GW: 192.168.0.251

My thought would be to add some routes to your PC's using DHCP option 121
eg. telling the PC on the 192.168.0.0/24 network that to get to 192.168.10.0/24 it needs to use IP address 192.168.0.251. (And visa versa for the device on the 192.168.10.0/24 network)
(You could just add static routes for initial testing)

(Assuming Mikrotik dhcp server)'

/ip dhcp-server option
add code=121 name=to10.0via0.251 value="0x18C0A80AC0A800FB00\$(NETWORK_GATEWAY)"

Then add this option to the dhcp network configuration for the 192.168.0.0/24 network.
When you renew the lease on the PC you should find the additional route in the PC routing table.

You need to add the return route in the 192.168.10.0/24 device routing table before it will work.
(Using a similar Option 121 on that DHCP server)

It should then work, but will be slow (as going via the cpu on the CRS326)
You can then enable hardware L3 offload. (Should likely just require enabling it in switch settings)

Here you are putting the vlan100 and vlan200 interfaces directly on the sfp-sfpplus24 port. However, in the bridge port listing, you have this:

Which means sfp-sfpplus24 is a slave port of the bridge. It won't work like that. You need modify the two VLAN interfaces, and change the parent interface to bridge instead of sfp-sfpplus24.

/interface vlan
set [find name="vlan100"] interface=bridge
set [find name="vlan200"] interface=bridge

for Bridge VLAN Filtering and the IP address assignment to work properly.

You can see here in the example screenshot you made, that interface=bridge1 is set for the VLAN interfaces, not the port interface!

First: Thanks to all participants!

Second: Special thanks are going to cggxannx!

You pointed to my mistake...even the docs are warning about binding the ip direct to the sfp...I had done it.
Reading and changing the config the whole day makes you somewhat blind...
Corrected my config...packets are flying.

My new config for completeness:

# 2026-07-02 11:20:19 by RouterOS 7.23.2
# software id = xxxx-xxxx
#
# model = CRS326-24S+2Q+
# serial number = HKxxxxxxxx
/interface bridge
add name=bridge vlan-filtering=yes
/interface vlan
add interface=bridge name="vlan100" vlan-id=100
add interface=bridge name="vlan200" vlan-id=200
/interface bridge port
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus1 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus2 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus3 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus4 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus5 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus6 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus7 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus8 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus9 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus10 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus11 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus12 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus13 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus14 pvid=200
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus15 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus16 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus17 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus18 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus19 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus20 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus21 pvid=100
add bridge=bridge frame-types=admit-only-untagged-and-priority-tagged interface=sfp-sfpplus22 pvid=100
add bridge=bridge frame-types=admit-only-vlan-tagged interface=sfp-sfpplus24
/interface bridge vlan
add bridge=bridge tagged=sfp-sfpplus24 vlan-ids=100,200
/ip/address
add address=192.168.0.251/24 interface=Vlan100
add address=192.168.10.251/24 interface=Vlan200
/system routerboard settings
set enter-setup-on=delete-key