WAN over VLAN - Please help me

Hello everyone,
For over five days, I have been trying to route the WAN from my FTTH connection to my RB4011 via VLAN.
Here is my network setup:

Deutsche Telekom's Fiber-Optic Modem 2 is currently connected to the CRS 309 SFP 8. The modem operates using untagged VLAN 7.

I have configured the following on the CRS 309:

/interface bridge add name=VLAN-Bridge1 vlan-filtering=yes
/interface ethernet set [ find default-name=ether1 ] name=eth01-MGMT
/interface ethernet set [ find default-name=sfp-sfpplus1 ] name=sfp01-Link_A1-RB4011
/interface ethernet set [ find default-name=sfp-sfpplus2 ] name=sfp02-Link_A3-CRS326
/interface ethernet set [ find default-name=sfp-sfpplus3 ] disabled=yes name=sfp03-Reserve
/interface ethernet set [ find default-name=sfp-sfpplus4 ] disabled=yes name=sfp04-Reserve
/interface ethernet set [ find default-name=sfp-sfpplus5 ] disabled=yes name=sfp05-Reserve
/interface ethernet set [ find default-name=sfp-sfpplus6 ] disabled=yes name=sfp06-Reserve
/interface ethernet set [ find default-name=sfp-sfpplus7 ] disabled=yes name=sfp07-Reserve
/interface ethernet set [ find default-name=sfp-sfpplus8 ] name=sfp08-WAN-FTTH

/interface vlan add interface=VLAN-Bridge1 name=VLAN1-MGMT vlan-id=1
/interface vlan add interface=VLAN-Bridge1 name=VLAN5-Services vlan-id=5
/interface vlan add comment="VLAN-ID 7 -> Telekom" interface=sfp08-WAN-FTTH name=VLAN7-WAN-Telekom-FTTH vlan-id=7
/interface vlan add comment="WAN-FTTH <--> VLAN" interface=VLAN-Bridge1 name=VLAN8-WAN-Telekom-LTE vlan-id=8
/interface vlan add interface=VLAN-Bridge1 name=VLAN20-Main vlan-id=20
/interface vlan add interface=VLAN-Bridge1 name=VLAN22-Main-NoWAN vlan-id=22
/interface vlan add interface=VLAN-Bridge1 name=VLAN25-Guest vlan-id=25
/interface vlan add interface=VLAN-Bridge1 name=VLAN30-Multimedia vlan-id=30
/interface vlan add interface=VLAN-Bridge1 name=VLAN32-Menage vlan-id=32
/interface vlan add interface=VLAN-Bridge1 name=VLAN40-Camera vlan-id=40
/interface vlan add interface=VLAN-Bridge1 name=VLAN50-Server vlan-id=50
/interface vlan add interface=VLAN-Bridge1 name=VLAN53-NEW-Netz-WAN vlan-id=53
/interface vlan add interface=VLAN-Bridge1 name=VLAN54-NEW-Netz-LMN vlan-id=54
/interface vlan add interface=VLAN-Bridge1 name=VLAN55-Energie vlan-id=55
/interface vlan add interface=VLAN-Bridge1 name=VLAN60-Printer vlan-id=60
/interface vlan add interface=VLAN-Bridge1 name=VLAN70-Studio-System vlan-id=70
/interface vlan add interface=VLAN-Bridge1 name=VLAN74-Studio-Main vlan-id=74
/interface vlan add interface=VLAN-Bridge1 name=VLAN78-Studio-Guest vlan-id=78
/interface vlan add interface=VLAN-Bridge1 name=VLAN80-VoIP vlan-id=80

/interface bridge port add bridge=VLAN-Bridge1 frame-types=admit-only-untagged-and-priority-tagged interface=eth01-MGMT pvid=20
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp01-Link_A1-RB4011
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp02-Link_A3-CRS326
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp03-Reserve
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp04-Reserve
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp05-Reserve
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp06-Reserve
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp07-Reserve
/interface bridge port add bridge=VLAN-Bridge1 frame-types=admit-only-untagged-and-priority-tagged interface=sfp08-WAN-FTTH pvid=7

/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=5
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=20
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=22
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=25
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=30
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=32
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=40
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=50
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=53
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=54
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=55
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=56
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=60
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=70
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=74
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=78
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326,sfp03-Reserve,sfp04-Reserve,sfp05-Reserve,sfp06-Reserve,sfp07-Reserve vlan-ids=80
/interface bridge vlan add bridge=VLAN-Bridge1 disabled=yes tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-ids=8
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-ids=7
/interface list member add interface=VLAN7-WAN-Telekom-FTTH list=WAN
/interface list member add interface=sfp08-WAN-FTTH list=WAN

I have configured the following on the RB 4011:

/interface bridge add name=VLAN-Bridge1 port-cost-mode=short vlan-filtering=yes
/interface ethernet set [ find default-name=ether1 ] disabled=yes name=eth01--WAN-DSL
/interface ethernet set [ find default-name=ether2 ] name=eth02--WAN-LTE
/interface ethernet set [ find default-name=ether3 ] disabled=yes name=eth03--WAN-Webinterface-DSL
/interface ethernet set [ find default-name=ether4 ] name=eth04--WAN-Webinterface-LTE
/interface ethernet set [ find default-name=ether5 ] disabled=yes name=eth05--
/interface ethernet set [ find default-name=ether6 ] disabled=yes name=eth06--
/interface ethernet set [ find default-name=ether7 ] name=eth07--Bonding-Cisco-1/4
/interface ethernet set [ find default-name=ether8 ] name=eth08--Bonding-Cisco-2/4
/interface ethernet set [ find default-name=ether9 ] name=eth09--Bonding-Cisco-3/4
/interface ethernet set [ find default-name=ether10 ] name=eth10--Bonding-Cisco-4/4 poe-out=off

/interface vlan add interface=VLAN-Bridge1 name=VLAN1-MGMT vlan-id=1
/interface vlan add interface=VLAN-Bridge1 name=VLAN5-Services vlan-id=5
/interface vlan add interface=sfp-sfpplus1 name=VLAN7-WAN-Telekom-FTTH vlan-id=7
/interface vlan add interface=VLAN-Bridge1 name=VLAN8-WAN-Telekom-LTE vlan-id=8
/interface vlan add interface=VLAN-Bridge1 name=VLAN20-Main vlan-id=20
/interface vlan add interface=VLAN-Bridge1 name=VLAN22-Main-NoWAN vlan-id=22
/interface vlan add interface=VLAN-Bridge1 name=VLAN25-Guest vlan-id=25
/interface vlan add interface=VLAN-Bridge1 name=VLAN30-Multimedia vlan-id=30
/interface vlan add interface=VLAN-Bridge1 name=VLAN32-Menage vlan-id=32
/interface vlan add interface=VLAN-Bridge1 name=VLAN40-Camera vlan-id=40
/interface vlan add interface=VLAN-Bridge1 name=VLAN50-Server vlan-id=50
/interface vlan add interface=VLAN-Bridge1 name=VLAN53-NEW-Netz-WAN vlan-id=53
/interface vlan add interface=VLAN-Bridge1 name=VLAN54-NEW-Netz-LMN vlan-id=54
/interface vlan add interface=VLAN-Bridge1 name=VLAN55-Energie vlan-id=55
/interface vlan add interface=VLAN-Bridge1 name=VLAN56-Shelly vlan-id=56
/interface vlan add interface=VLAN-Bridge1 name=VLAN60-Printer vlan-id=60
/interface vlan add interface=VLAN-Bridge1 name=VLAN70-Studio-System vlan-id=70
/interface vlan add interface=VLAN-Bridge1 name=VLAN74-Studio-Main vlan-id=74
/interface vlan add interface=VLAN-Bridge1 name=VLAN78-Studio-Guest vlan-id=78
/interface vlan add interface=VLAN-Bridge1 name=VLAN80-VoIP vlan-id=80

/interface bonding add mode=802.3ad name=bonding-01-uplink-Cisco slaves=eth07--Bonding-Cisco-1/4,eth08--Bonding-Cisco-2/4,eth09--Bonding-Cisco-3/4,eth10--Bonding-Cisco-4/4 transmit-hash-policy=layer-2-and-3

/interface pppoe-client add allow=pap,chap,mschap2 interface=VLAN7-WAN-Telekom-FTTH name=PPPoE-WAN-Telekom-FTTH password=XXXXX user=XXXXX@t-online.de

/interface list add name=WAN
/interface list add name=WAN-DSL
/interface list add name=WAN-LTE
/interface list add name=ALL-VLAN
/interface list add name=VLAN-NO-GUEST
/interface list add name=VLAN-DSL
/interface list add name=VLAN-LTE
/interface list add name=VLAN-VoIP
/interface list add name=VLAN-NoISP
/interface list add name=LAN-In-Interface-List
/interface list add name=WiFi
/interface list add include=ALL-VLAN name=ALL-VLAN-NoMGMT

/interface bridge port add bridge=VLAN-Bridge1 interface=bonding-01-uplink-Cisco internal-path-cost=10 path-cost=10
/interface bridge port add bridge=VLAN-Bridge1 interface=sfp-sfpplus1 internal-path-cost=10 path-cost=10
/interface bridge port add bridge=VLAN-Bridge1 interface=eth04--WAN-Webinterface-LTE internal-path-cost=10 path-cost=10
/interface bridge port add bridge=VLAN-Bridge1 frame-types=admit-only-untagged-and-priority-tagged interface=eth05-- internal-path-cost=10 path-cost=10

/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=5
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=20
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=22
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=25
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco vlan-ids=30
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=32
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=40
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=50
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=53
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=54
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,eth04--WAN-Webinterface-LTE,bonding-01-uplink-Cisco vlan-ids=55
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=60
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=70
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=74
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=78
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=80
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=1
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1,bonding-01-uplink-Cisco,eth04--WAN-Webinterface-LTE vlan-ids=56
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp-sfpplus1 vlan-ids=7


When I enable PPPoE on the RB 4011, the log only shows:

2026-08-30 10:23:48 pppoe,ppp,info PPPoE-WAN-Telekom-FTTH: initializing...
2026-08-30 10:23:48 pppoe,ppp,info PPPoE-WAN-Telekom-FTTH: connecting...
2026-08-30 10:23:52 pppoe,ppp,info PPPoE-WAN-Telekom-FTTH: terminating...

What did I do wrong? I can't find the error. :anguished_face:

Username and password is ok - Ttested directly on the CRS 309. I get my IP immediately.

If you need any further information, please let me know.

Can you please help me?

Best regards, Jörg

Cranck up the logging to DEBUG level ?? You'll see much, much more info on this...that might already shine some light...

All your other config points to you actually wanting the bridge to be the parent for the vlan interface.

Das müsste auch als "Parent-Interface" die Bridge habe.
Hier:
/interface bridge vlan add bridge=VLAN-Bridge1
fehlt VLAN7.

Deine VLAN-Config ist fehlerhaft, der 309er übermittelt VLAN7 nicht an den 4011.

I have found a problem in your CRS309 config.
/interface vlan add comment="VLAN-ID 7 -> Telekom" interface=sfp08-WAN-FTTH name=VLAN7-WAN-Telekom-FTTH vlan-id=7

When you create VLAN on some interface it is automatically TAGGED, create that VLAN on bridge interface and set "sfp08-WAN-FTTH" as untagged and BRIDGE + SFP link to RB4011 as tagged.

English please :slight_smile:

Hello, I have similar setup but with different setup. I have microwave uplink connected to CRS418 PoE Switch from which I also have 10G optical link to CCR2004-16G-2S+. My Uplink VLAN is VLAN4090, I dont have VLAN from provider just as you, I used VLAN just for transfer.

CRS418: (ether16 is Microwave - UPLINK, sfp+1=CCR2004)

/in vlan add name=VLAN4090 vlan-id=4090 interface=BRIDGE-Main
/in bridge vlan add vlan-ids=4090 bridge=BRIDGE-Main tagged=BRIDGE-Main,sfp-sfpplus1 untagged=ether16 (Microwave is untagged because you do not recieve trunk from provider, but you can tag your device)

CCR2004 (sfpplus1 is CRS418)
/in vlan add name=VLAN4090 vlan-id=4090 interface=BRIDGE-Main
/in bridge vlan add vlan-ids=4090 bridge=BRIDGE-Main tagged=BRIDGE-Main,sfp-sfpplus1

PPPoE client is running on interface VLAN4090, but when you will add MASQUERADE NAT rule you have to set out-interface directly on PPPoE client not on VLAN interface otherwise it will not work. If you will have any questions just ask I can help you.

First of all, thank you very much for your replies and suggestions. :+1: :+1: :+1:

@krcn I’ve changed it that way on the CRS309 now, but it still isn't working.

add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-ids=7

Does it also need to be placed on the bridge on the RB 4011?

Yes, place it on bridge too. on CRS309 also set VLAN-Bridge1 as TAGGED because VLAN interface is created on VLAN-Bridge1 that means tagged traffic is going to VLAN-Bridge1, on RB4011 VLAN on Bridge tagged Bridge and SFP link

Shouldn't the CRS port connected to the Deutsche Telekom fibre modem be set to VLAN 7 tagged

/interface bridge port add bridge=VLAN-Bridge1 frame-types=admit-only-tagged interface=sfp08-WAN-FTTH
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011,sfp08-WAN-FTTH vlan-ids=7

Not directly related:

/interface vlan add interface=VLAN-Bridge1 name=VLAN1-MGMT vlan-id=1 is almost always incorrect as the bridge-CPU interface uses VLAN 1 untagged by default

On a switch you do not need /interface vlan or the bridge-CPU interface to be a tagged member under /interface bridge vlan for any VLANs just passing through the switch, a single /interface vlan for management access from a VLAN is usually sufficient.

Adding untagged= membership under /interface bridge vlan is unnecessary as it dynamically added from the /interface bridge port PVID, this also prevents strange behaviour / communication problems if you change one but not the other when it has been added manually.

On newer versions of RouterOS adding tagged= membership under /interface bridge vlan is also unnecessary as it is dynamically added from /interface vlan attached to the bridge

Should be an easy fix, once all is clear. You need to post complete configs for a proper response/assistance.
It seems you have conflicting or very unclear information regarding TWO WAN interfaces not just one on the switch. you have what appears to be an FTTH connection associated with vlan7 and SFP 8 ( which in my mind you are simply using the vlan to carry the ISP connection to the RB4011), BUT you have this second WAN connection called LTE, which you have attached to the bridge itself, but comes from nowhere???
Yes its associated with vlan8, but on which port??
To make matters worse, is that in your vlan you identify it as WAN-FTTH, whereas that would have been more appropriate to identify in the comment for your WAN connection vice what you did put vlan-id-7!!

Also you have assigned ether1 as your management vlan it seems but the vlan is called MAIN??
To make a point, the reason to have an off bridge management access is for the case where something goes wrong on the bridge, and thus your access via vlan on the switch becomes useless.
The only reason to have a bridge associated management access is if the admin works from that switch on a regular basis, but even still, I would have a separate off bridge access.

For me the RB4011 is the main router and the switches act as switches and there is no use of vlan-id=1, mainly because its the background glue that MT already uses on its devices and thus should not be used for any other vlans data etc.....
So, off the bat, using CR309 as a router is the first mistake to be corrected, which will greatly simplify the setup.

So on the CRS309, the only vlan that needs identification is the management vlan. This is the subnet where all the smart devices talking to the router, get their IP address from." BuT you contradict yourself again, you identify the management vlan as vlan-id=1 BUT THen on your first bridge port setting you use vlan20-Man vlan-id=20. You really need to get your story straight. Lets assume it should be 11 not 20 ( because you identify it as vlan20-Main!

Note: simply change vlan1 id to vlan11, for minimal changes.

Below is the only vlan needed to be identified and it needs and IP address assigned as well.
/interface vlan
add interface=VLAN-Bridge1 name=VLAN1-MGMT vlan-id=11

/ip address
add address=subnet address/24 interface=vlan1-MGMT network=subnet.0
add address=192.168.77.1/30 interface=OffBridge1

/interface ethernet set [ find default-name=ether1 ] name=OffBridge1

So will ignore vlan8 and anything LTE for the moment, it needed simply add the vlan on the RB4011 and mirror what you do for vlan7 on this device..
ON the switch ONLY the management vlan is tagged for the bridge and the offbridge port is not used.

/interface bridge port
add bridge=VLAN-Bridge1 interface=sfp01-Link_A1-RB4011 frame-types=admin-only-vlan-tagged
add bridge=VLAN-Bridge1 interface=sfp02-Link_A3-CRS326 frame-types=admin-only-vlan-tagged
add bridge=VLAN-Bridge1 frame-types=admit-only-untagged-and-priority-tagged interface=sfp08-WAN-FTTH pvid=7

Your diagram clearly shows that no other ports are being used on the CRS309.
so for vlans you can see only the one associated with the management vlan, the one used to give the CR309 its IP address needs to be tagged for the bridge, the other vlans are simply being passed through the device. We identify the traffic coming from FTTH with vlan7 tags as it enters the router and this is carried to the RB4011

/interface bridge vlans
add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326 /
vlan-ids=5,20,22,25,30,32,40,50,53,54,55,60,70,74,78,80
add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011,sfp02-Link_A3-CRS326 /
vlan-id=11
add bridge=VLAN-Bridge1 tagged=spf01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-id=7

Much cleaner and simpler.

As for the rest of the config

/interface list
add name=MGMT
/interface list member
add interface=OffBridge1 list=MGMT
add interface=VLAN1-MGM list=MGMT

/ip neighbor discovery-settings
set discover-interface-list=MGMT
/tool mac-server
set allowed-interface-list=none
/tool mac-server mac-winbox
set allowed-interface-list=MGMT

To access the router on ether1, simply connect your laptop after changing IPV4 settings to 192.168.77.2 and with username and password you should gain connection.

To explain a bit: Port 1 on the RB4011 used to be the WAN port for DSL, but that connection no longer exists due to the switch to FTTH. I thought it would be fairly simple to reroute the new FTTH WAN connection, but it turned out not to be the case.

The VLAN8 setup for LTE was just a preliminary step—based on the assumption (as mentioned earlier) that it would be easy to configure—but I’m abandoning that idea and deleting VLAN8.

I’ll post the full configuration for the RB4011 and CRS309 later. Can I leave out the scripts? Otherwise, it might be too much information.

Just try what I said.. I have it the same way and it works without problems.

CRS309_30.Aug.2026.rsc (8.5 KB)

RB4011_30.Aug.2026.rsc (117.9 KB)

Here are the configuration files.

And please don't kill me. :face_with_bags_under_eyes:

I did that, but for some reason it's not working.

EDIT: Could it be that a firewall rule is causing the trouble?

/interface bridge vlan add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-ids=7

add VLAN-Bridge1 as TAGGED too =
/interface bridge vlan add bridge=VLAN-Bridge1 tagged=VLAN-Bridge1,sfp01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-ids=7

also...
/interface bridge port add bridge=VLAN-Bridge1 frame-types=admit-only-vlan-tagged interface=sfp08-WAN-FTTH pvid=7

set admit-all

Disclaimer: I know nothing about Deutsche Telekom's Fiber-Optic Modem other that what I found with google. However, I think that @tdw 's post is relevant, based on this on the Fortigate site: Technical Tip: Configuring FortiGate as a 3rd party router for Deutsche Telekom fiber optic access

Which says

Deutsche Telekom requires the use of VLAN ID 7 when using a non-Telekom router (other Internet Service Providers may use different VLAN IDs). In this example, the physical WAN1 interface is used and an additional subinterface will be added on it:

So the SFP8 port will need to be expecting the internet connection to have a IEEE 802.1Q tag for vlan id 7.

I also assume the CRS326 will have the save vlans as the Catalyst2960? If that's the case then the link between the CRS309 and the RB4011 will need to be a trunk that carries all the vlans carried by the bond between the RB4011 and the C2960 (which will also need to be between the CRS307 and the CRS326) plus vlan id 7 (the only trunk that needs to have vlan 7 is between the CRS309 and RB4011, but it also needs all the other vlans, so the RB4011 can supply the CRS326)

Here are some Screenshots:

It is configured exactly as you described, but unfortunately, it isn't working.

@Buckeye I haven't defined VLAN 7 on the Catalyst 2960 and the CRS326. That’s correct, isn't it? The tagging for VLAN 7 must come from the CRS309.

No need for vlan 7 on c2960 or CRS326.

However the uploaded CRS309_30.Aug.2026.rsc has this in it:

/interface bridge vlan add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011 untagged=sfp08-WAN-FTTH vlan-ids=7

It should be

/interface bridge vlan add bridge=VLAN-Bridge1 tagged=sfp01-Link_A1-RB4011,sfp08-WAN-FTTH vlan-ids=7