setup_bridge_with_wifi_subnet
Bridge LAN and Wi-Fi ports on a MikroTik router, placing Wi-Fi in its own subnet with optional DHCP and VLAN isolation.
Instructions
Put all LAN ports and Wi-Fi in a bridge, with Wi-Fi in its own subnet.
wifi_gateway (REQUIRED, ask the user, never invent): router IP + mask for the
Wi-Fi subnet, as '192.168.20.1/24' or '192.168.20.1 255.255.255.0'.
lan_address: only if the user wants to set/change the LAN gateway (same formats).
If omitted, the current LAN address is kept (shown in the dry run; confirm it).
dhcp_range: optional pool 'first-last' (e.g. '192.168.20.100-192.168.20.200').
Default: the usable range after the first 9 addresses. Confirm with the user.
mode='vlan' (default): ONE bridge with VLAN filtering. LAN ports untagged on
VLAN 1, Wi-Fi ports on wifi_vlan_id, router IP on a VLAN interface.
Caution: on many non-CRS3xx models this disables hardware offload (CPU switching).
mode='separate_bridge': LAN ports in bridge, Wi-Fi in wifi_bridge.
wan_interface: excluded from bridging (default: members of the WAN interface list).
lan_ports / wifi_ports: default all Ethernet (minus WAN) / all Wi-Fi interfaces.
isolate_wifi_from_lan: block traffic between Wi-Fi and LAN; Wi-Fi gets internet,
DNS and DHCP only (no router management from Wi-Fi).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| dhcp | No | ||
| mode | No | vlan | |
| name | No | router | |
| bridge | No | bridge | |
| dry_run | No | ||
| lan_ports | No | ||
| dhcp_range | No | ||
| wifi_ports | No | ||
| lan_address | No | ||
| wifi_bridge | No | bridge-wifi | |
| wifi_gateway | Yes | ||
| wifi_vlan_id | No | ||
| wan_interface | No | ||
| rollback_minutes | No | ||
| isolate_wifi_from_lan | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |