NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

cryan411's avatar
cryan411
Aspirant
Oct 22, 2024

NetGear GS728TP config for Wireless Access Points with 2 SSID's

Walking into a new environment and just double checking all the configs.

 

Switch purpose: 5 POE wireless access points  that serve 2 different SSID's that should egress separate internet circuits.

 

SSID 1 - Corp Wifi Traffic (VLAN 1) - route through corporate firewall/internet

SSID 2 - Guest Wifi Traffic (VLAN 2) - route through basic broadband cable modem

 

  • Port 1 is going to broadband circuit modem/router
  • Access Points are in ports 2-6
  • Port 23 is going to corporate switch stack, which routes to corp firewall

 

Port 1 is set to PVID 2 | Admit all frames | Ingress filter - enabled 
Remaining ports are set to PVID 1 | Admit all frames | ingress filter - enabled

 

VLAN MEMBERSHIP (VLAN 1)

Port 1 - blank (no tagged or untagged)
Ports 2-24 - Untagged

 

VLAN MEMBERSHIP (VLAN 2)

Port 1 (Untagged)

Ports 2-6 (Tagged)

Ports 7-24 Blank (no tagged or untagged)

 

Everything seems to work, but just wanna make sure this is best practice on what we need.

3 Replies

  • schumaku's avatar
    schumaku
    Guru - Experienced User

    cryan411 wrote:

    Port 1 is set to PVID 2 | Admit all frames | Ingress filter - enabled 

     

    VLAN MEMBERSHIP (VLAN 1)

    Port 1 - blank (no tagged or untagged)...

    VLAN MEMBERSHIP (VLAN 2)

    Port 1 (Untagged)

    ...

    Everything seems to work, but just wanna make sure this is best practice on what we need.


    This looks a little bit suspect, if not simply wrong or very risky.

     

    A single port can be configured as an access port (VLAN membership [U]ntagged, PVID set) for a sinlge VLAN only, any other VLAN membership must be [T]agged.

     

    This can apply to an AP which is lsop administered over the first untagged VLAN and IP subnet, while the second VLAN is isolated.

     

    For an simple wireless access port you intend to be manged on the VLAN 1 use

     

    Port for the AP:

     

    VLAN 1 [U]ntagged

    VLAN 2 [T]agged

    PVID 1

     

    Corp-net port (assume you operate it untagged) - this makes up a simple access port for VLAN 2:

     

    VLAN 1 [ ] ... no mebership

    VLAN 2 [U]ntgged

    PVID 2

     

    Guest-net port (assume you operate it untagged) - this makes up a simple access port for VLAN 1:

     

    VLAN 1 [U]ntgged

    VLAN 2 [ ] ... no mebership

    PVID 1

     

    Since this isn't a managed switch I've already suggested a moderator to move it to the appropriate community section  Plus and Smart Switches Forum section to discuss Smart Switches (T) and Plus Switches (E), including Local and Remote Management

    • cryan411's avatar
      cryan411
      Aspirant

      Thanks for the feedback. I feel like this is how it's setup, what am I missing?  Vlan2 is what is being used for the guest wifi traffic, and I can manage the AP's through VLAN1.

      • BrianL's avatar
        BrianL
        NETGEAR Moderator

        Hi cryan411,

         

        Welcome to the community!
         

        Not the best setup to be honest. But if this works for you, I will leave it as it is. Here's a sample setup of multiple SSIDs on a network that uses different VLANs.

         

         

        Kind regards,

         

        BrianL

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More