where did you find that 7621 switch chip does not support VLANs?
nichky, somewhere on this forum someone of the Mikrotik staff mentioned hardware VLAN support on hEX r3 "in future", but I am unable to find that post now.
So I gave @Jotne the instruction how to do it in software. To see a menu item in Winbox/WebFig/sometimes even CLI does not always mean that the feature actually works. So try to configure something like
/interface ethernet switch port set ether5 vlan-mode=secure or
/interface ethernet switch vlan add vlan-id=20 ports=ether5 switch=switch1. You either get an error message, which means that the "future" mentioned in that post has not come yet, or you'll get no error message and subsequent print will show the command has changed the settings, which will mean that future is here and the manual has not been updated.
Jotne, I wrote the reasons why I've suggested use of VLAN ID 10 instead of VLAN ID 1 in the end of that post. Basically it is because Mikrotik supports the idea of "hybrid" bridge where tagless frames can exist inside the bridge, something you won't find on switches like Cisco Catalyst. Normally, if you set some
pvid value in
/interface bridge port item, tagless frames get tagged on ingress with the VLAN ID specified this way. But if that
pvid value matches the
pvid value set on the bridge itself, they get in tagless.
So the same configuration with VID 1 used instead of VID 10 should look the following, but it is without any warranty and you have to test yourself:
/interface bridge port
add bridge=bridge interface=ether2 pvid=1
add bridge=bridge interface=ether3 pvid=20
add bridge=bridge interface=ether4 pvid=1
/interface bridge vlan
add vlan-ids=1 untagged=bridge,ether2,ether4
add vlan-ids=20 tagged=bridge untagged=ether3
add vlan-ids=30 tagged=bridge,ether2,ether4
/interface vlan
add name=vlan20 vlan-id=20 interface=bridge
add name=vlan30 vlan-id=30 interface=bridge
/ip address
add address=192.168.88.1/24 interface=bridge
add address=192.168.20.1/24 interface=vlan20
add address=192.168.30.1/24 interface=vlan30
/interface bridge set bridge vlan-filtering=yes
On Atheros8227, the VLAN support is weird in terms that it cannot selectively untag only frames belonging to port's pvid on egress. This makes it impossible to use true hybrid ports where the access VLAN would be tagged internally, but you can make use of the fact that tagless frames may exist internally to have pseudo-hybrid ports for one "tagless VLAN" while the rest of VLANs are tagged, and still have hardware switching.