Hello,
Thank you for your patience.
I recreated a test environment matching your topology as closely as possible and performed a series of tests to verify the behaviour of ZeroTier Ethernet Bridging.
Below is a summary of each concern and the corresponding test results.
- Does Ethernet Bridging work with VLAN interfaces?
Yes.
I created separate bridges for individual VLANs and added the corresponding ZeroTier interfaces to each bridge. The router successfully attached the ZeroTier interfaces to the bridges, and remote MAC addresses were learned on the bridge, confirming that Layer-2 Ethernet frames were traversing the ZeroTier network.
- Can multiple ZeroTier networks be bridged independently?
Yes.
I tested two independent ZeroTier networks, each assigned to its own VLAN and Linux bridge. Both ZeroTier interfaces operated independently without interfering with each other, indicating that multiple bridged ZeroTier networks can coexist on the same router.
- Is enabling “Allow Ethernet Bridging” in ZeroTier Central sufficient?
It is a required step, but not the only requirement.
After enabling Allow Ethernet Bridging for the router member in ZeroTier Central, the router correctly reported:
-
bridge: true
-
broadcastEnabled: true
This confirms that bridge mode was successfully enabled.
- Does Layer-2 traffic actually pass through the bridge?
Yes.
Bridge forwarding was verified by observing:
-
dynamically learned remote MAC addresses on the Linux bridge;
-
ARP traffic traversing the bridge;
-
normal Ethernet frame forwarding between the physical interface and the ZeroTier interface.
This confirms that the bridge itself is operating correctly.
- Can devices behind the router communicate through the bridge?
Yes.
LAN devices connected behind the router were able to generate traffic normally, and packet captures confirmed that their traffic was successfully forwarded through the bridge.
- Can a regular ZeroTier client directly access LAN devices behind the bridged router using their LAN IP addresses?
This behaviour could not be reproduced.
Although remote ZeroTier members were able to communicate with other ZeroTier members using their assigned ZeroTier IP addresses, they were not able to communicate directly with LAN devices behind the bridged router using their LAN IP addresses.
During testing, packet captures showed that no ARP requests for the destination LAN device were received from the remote ZeroTier client. Since ARP resolution never occurred, communication with the LAN device could not be established.
Based on these observations, the bridge itself is functioning correctly; however, the remote endpoint does not appear to be participating in the same Layer-2 broadcast domain. Ethernet Bridging extends an Ethernet segment only between members that participate in that bridged segment. A standard routed ZeroTier client remains a Layer-3 endpoint and therefore cannot automatically access devices on the bridged LAN using their native LAN addresses.
Based on the testing performed, I was able to confirm that the bridge configuration itself operates correctly and that Ethernet frames are successfully forwarded through the bridged ZeroTier interfaces. The only behaviour that could not be reproduced was direct access from a standard ZeroTier client to LAN devices behind the bridged router.
To better understand your intended topology, could you please clarify the following?
-
What type of device is acting as the remote ZeroTier client (Windows, Linux, another router, etc.)?
-
Is that remote device configured as a standard ZeroTier client, or is it also participating in an Ethernet bridge?
-
Could you provide a simple network diagram showing both ends of the ZeroTier connection, including which interfaces are bridged and where the end devices are connected?
This information will help determine whether the observed behaviour is expected for the current topology or whether additional bridge configuration is required.
Kind regards,
V.