Aha, tak to se omlouvám za dezinformaci. Nějak jsem nepředpokládal, že by to mikrotik řešil na CRS328 jinak než na CRS112.
Tohle je z tik fóra
Each vlan represent a brXX interface,
Each trunk port need to add vlan interfaces: ethX.XX
One logical trunk interface needed, add every trunk interface here: br0
Add each trunk interface's vlan interface to the brXX to have access: br10,br20
# reset switch config
$> /system reset skip-backup=yes no-defaults=yes
# br0 will be the trunk bridge
$> /interface bridge add comment=TRUNK name=br0 protocol-mode=none vlan-filtering=yes
# br10 will be the vlan10 bridge
$> /interface bridge add comment=VLAN10 name=br10 pvid=10 vlan-filtering=yes
# br20 will be the vlan20 bridge
$> /interface bridge add comment=VLAN20 name=br20 pvid=20 vlan-filtering=yes
# add vlan interface for eth1: vlan10 tagged + vlan20 tagged: eth1.10, eth1.20
$> /interface vlan add interface=eth1 name=eth1-vlan10 vlanid=10
$> /interface vlan add interface=eth1 name=eth1-vlan20 vlanid=20
# assign eth1 to br0
$> /interface bridge port add bridge=br0 frames-type=admit-only-vlan-tagged interface=eth1
# assign eth1.10 to br10: VLAN10 managment
$> /interface bridge port add bridge=br10 frames-type=admit-only-untagged-and-priority-tagged interface=eth1-vlan10
# assign eth1.20 and (eth2 to eth24) to br20: VLAN20 PCs:
$> /interface bridge port add bridge=br20 frames-type=admit-only-untagged-and-priority-tagged interface=eth1-vlan20
$> /interface bridge port add bridge=br20 frames-type=admit-only-untagged-and-priority-tagged interface=eth2
...
$> /interface bridge port add bridge=br20 frames-type=admit-only-untagged-and-priority-tagged interface=eth24
# add management ip-address - as you want: VLAN10
$> /ip address add address=192.168.10.10/24 interface=br10 network=192.168.10.0
Thats all.