NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
cryan411
Oct 22, 2024Aspirant
NetGear GS728TP config for Wireless Access Points with 2 SSID's
Walking into a new environment and just double checking all the configs.
Switch purpose: 5 POE wireless access points that serve 2 different SSID's that should egress separate internet circuits.
SSID 1 - Corp Wifi Traffic (VLAN 1) - route through corporate firewall/internet
SSID 2 - Guest Wifi Traffic (VLAN 2) - route through basic broadband cable modem
- Port 1 is going to broadband circuit modem/router
- Access Points are in ports 2-6
- Port 23 is going to corporate switch stack, which routes to corp firewall
Port 1 is set to PVID 2 | Admit all frames | Ingress filter - enabled
Remaining ports are set to PVID 1 | Admit all frames | ingress filter - enabled
VLAN MEMBERSHIP (VLAN 1)
Port 1 - blank (no tagged or untagged)
Ports 2-24 - Untagged
VLAN MEMBERSHIP (VLAN 2)
Port 1 (Untagged)
Ports 2-6 (Tagged)
Ports 7-24 Blank (no tagged or untagged)
Everything seems to work, but just wanna make sure this is best practice on what we need.
3 Replies
- schumakuGuru - Experienced User
cryan411 wrote:
Port 1 is set to PVID 2 | Admit all frames | Ingress filter - enabled
VLAN MEMBERSHIP (VLAN 1)
Port 1 - blank (no tagged or untagged)...
VLAN MEMBERSHIP (VLAN 2)
Port 1 (Untagged)
...
Everything seems to work, but just wanna make sure this is best practice on what we need.
This looks a little bit suspect, if not simply wrong or very risky.
A single port can be configured as an access port (VLAN membership [U]ntagged, PVID set) for a sinlge VLAN only, any other VLAN membership must be [T]agged.
This can apply to an AP which is lsop administered over the first untagged VLAN and IP subnet, while the second VLAN is isolated.
For an simple wireless access port you intend to be manged on the VLAN 1 use
Port for the AP:
VLAN 1 [U]ntagged
VLAN 2 [T]agged
PVID 1
Corp-net port (assume you operate it untagged) - this makes up a simple access port for VLAN 2:
VLAN 1 [ ] ... no mebership
VLAN 2 [U]ntgged
PVID 2
Guest-net port (assume you operate it untagged) - this makes up a simple access port for VLAN 1:
VLAN 1 [U]ntgged
VLAN 2 [ ] ... no mebership
PVID 1
Since this isn't a managed switch I've already suggested a moderator to move it to the appropriate community section Plus and Smart Switches Forum section to discuss Smart Switches (T) and Plus Switches (E), including Local and Remote Management
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!