Please see below.
Intermittent connection when accessing VLAN200 devices from VLAN100 (Allowed in firewall rules)
Also weird problem that I could not ping a certain host on VLAN200 with my PC plugged into ether1 of switch. Moved to another port on VLAN 100 and ping worked again.
As per first post would like to know if having bridge set as VLAN100 is a problem?
# jul/23/2021 18:07:30 by RouterOS 6.48.3
# software id = UGF3-0R25
#
# model = CRS226-24G-2S+
# serial number = xxxxxx
/interface bridge
add admin-mac=12:34:56:78:90:AB auto-mac=no comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether1 ] speed=100Mbps
set [ find default-name=ether2 ] speed=100Mbps
set [ find default-name=ether3 ] speed=100Mbps
set [ find default-name=ether4 ] speed=100Mbps
set [ find default-name=ether5 ] speed=100Mbps
set [ find default-name=ether6 ] speed=100Mbps
set [ find default-name=ether7 ] speed=100Mbps
set [ find default-name=ether8 ] speed=100Mbps
set [ find default-name=ether9 ] speed=100Mbps
set [ find default-name=ether10 ] speed=100Mbps
set [ find default-name=ether11 ] speed=100Mbps
set [ find default-name=ether12 ] speed=100Mbps
set [ find default-name=ether13 ] speed=100Mbps
set [ find default-name=ether14 ] speed=100Mbps
set [ find default-name=ether15 ] speed=100Mbps
set [ find default-name=ether16 ] speed=100Mbps
set [ find default-name=ether17 ] speed=100Mbps
set [ find default-name=ether18 ] speed=100Mbps
set [ find default-name=ether19 ] speed=100Mbps
set [ find default-name=ether20 ] speed=100Mbps
set [ find default-name=ether21 ] speed=100Mbps
set [ find default-name=ether22 ] speed=100Mbps
set [ find default-name=ether23 ] speed=100Mbps
set [ find default-name=ether24 ] speed=100Mbps
set [ find default-name=sfp-sfpplus1 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfpplus2 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
/interface vlan
add interface=bridge name=vlan100 vlan-id=100
/interface ethernet switch
set drop-if-invalid-or-src-port-not-member-of-vlan-on-ports="ether2,ether3,eth\
er4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,eth\
er14,ether15,ether16,ether17,ether18,ether19,ether20,ether21,ether22,ether\
23,ether24,ether1"
/interface ethernet switch trunk
add member-ports=ether23,ether24 name=trunk1
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge comment=defconf interface=ether1
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=ether9
add bridge=bridge comment=defconf interface=ether10
add bridge=bridge comment=defconf interface=ether11
add bridge=bridge comment=defconf interface=ether12
add bridge=bridge comment=defconf interface=ether13
add bridge=bridge comment=defconf interface=ether14
add bridge=bridge comment=defconf interface=ether15
add bridge=bridge comment=defconf interface=ether16
add bridge=bridge comment=defconf interface=ether17
add bridge=bridge comment=defconf interface=ether18
add bridge=bridge comment=defconf interface=ether19
add bridge=bridge comment=defconf interface=ether20
add bridge=bridge comment=defconf interface=ether21
add bridge=bridge comment=defconf interface=ether22
add bridge=bridge comment=defconf interface=ether23
add bridge=bridge comment=defconf interface=ether24
add bridge=bridge comment=defconf interface=sfp-sfpplus1
add bridge=bridge comment=defconf interface=sfpplus2
/ip neighbor discovery-settings
set discover-interface-list=none
/interface ethernet switch egress-vlan-tag
add tagged-ports=trunk1,switch1-cpu,ether20 vlan-id=100
add tagged-ports=trunk1,ether20 vlan-id=180
add tagged-ports=trunk1,ether20 vlan-id=200
add tagged-ports=trunk1,ether20 vlan-id=190
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=100 ports="ether1,ether2,ether3,ether4,eth\
er5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,et\
her15,ether16"
add customer-vid=0 disabled=yes new-customer-vid=180 ports=ether20
add customer-vid=0 new-customer-vid=200 ports=ether19,ether21,ether22
add customer-vid=0 new-customer-vid=190 ports=ether18,ether17
/interface ethernet switch vlan
add ports="trunk1,switch1-cpu,ether1,ether2,ether3,ether4,ether5,ether6,ether7\
,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,eth\
er20" vlan-id=100
add ports=trunk1,ether20 vlan-id=180
add ports=trunk1,ether19,ether20,ether21,ether22 vlan-id=200
add ports=trunk1,ether17,ether18,ether20 vlan-id=190
/ip address
add address=192.168.100.2/24 comment=defconf interface=vlan100 network=\
192.168.100.0
/ip cloud
set update-time=no
/ip dns
set servers=8.8.8.8
/ip route
add distance=1 gateway=192.168.100.1
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set winbox address=192.168.100.0/24 port=42123
set api-ssl disabled=yes
/ip ssh
set strong-crypto=yes
/lcd
set enabled=no
/lcd pin
set pin-number=8822
/system clock
set time-zone-name=Europe/London
/system identity
set name=CRS_Switch
/system ntp client
set enabled=yes primary-ntp=82.219.4.30
/tool bandwidth-server
set enabled=no
/tool mac-server
set allowed-interface-list=none
/tool mac-server mac-winbox
set allowed-interface-list=none
/tool mac-server ping
set enabled=no