NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

pbrady's avatar
pbrady
Aspirant
Oct 25, 2015
Solved

M5300-28G3 Management VLAN Disable Routing

Hey,

 

I'm testing a stack of M5300-G3 switches with the 11.x firmware and just cannot get the managment VLAN figured out.  It seems that whatever I do the managment VLAN becomes a routing VLAN - which I don't want.  What I do have is:

 

  1. a number of other VLANs, both IPv4 and IPV6, all happily routing and switching
  2. DNS, DHCP etc all happy.
  3. Alternate CISCO ASA manages the routing between the normal user subnets and my secure management VLAN

I had this configuration working on firmware 10.x but can't seem to find the magic commands to set an IP address of the device without also setting the management VLAN to a routing VLAN.

 

Thanks in advance,

-pete

  • Hi pbrady,

     

    I regret to inform you that the method in the v10.x firmware of having a non-routable management VLAN is no longer available in the v11.x firmware.  With regard to this, it would be best to implement Access Control Lists or ACLs to restrict unwanted traffic to/from the management VLAN using the v11.x firmware.

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

5 Replies

  • DaneA's avatar
    DaneA
    NETGEAR Employee Retired

    Hi pbrady,

     

    I regret to inform you that the method in the v10.x firmware of having a non-routable management VLAN is no longer available in the v11.x firmware.  With regard to this, it would be best to implement Access Control Lists or ACLs to restrict unwanted traffic to/from the management VLAN using the v11.x firmware.

     

     

    Regards,

     

    DaneA

    NETGEAR Community Team

    • pbrady's avatar
      pbrady
      Aspirant

      No need to apologise - firmware series changes are a chance for vendors to implement changes.  Its just this was not clear from my reading of the V11 documentation.

       

      Is the management VLAN then a full routing VLAN the same as any other VLAN?

       

      If I adjust the routing and ACLs across my network I can use the M5300, with ACLs, as the gateway to my other devices on the secure VLAN?

       

      Thanks in advance,

      -pete

      • DaneA's avatar
        DaneA
        NETGEAR Employee Retired

        Hi pbrady,

         

        pbrady wrote:

        Is the management VLAN then a full routing VLAN the same as any other VLAN?


        Yes.

         


        pbrady wrote:

        If I adjust the routing and ACLs across my network I can use the M5300, with ACLs, as the gateway to my other devices on the secure VLAN?

         


        The VLAN interface will act as the default gateway for the device in that VLAN.

         

         

        Regards,

         

        DaneA

        NETGEAR Community Team

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More