NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

finnjaeger1337's avatar
Jun 25, 2022

GS108Ev3 VLAN /Non-Vlan mixed

I have a problem getting this to work: 

 

My router is openWRT, and I have the following networks running on eht0

 

-> Lan  192.168.33.0/24

-> VLAN3 192.168.3.0/24

-> VLAN4 192.168.4.0/24 

 

DHCP running on each network. 

 

Now what I want to happen: 

 

-> Set specific ports on the switch to be in either of those networks 

 

What works:

If I set a port to be untagged in lets say VLAN4  and set the PVID to 4  , the port is in VLAN4 clients get ip von the VLAN4 DHCP, all is well. 

 

What doesnt work: 

Getting any client/port into LAN/Management so that a client would get a 192.168.33.0/24 adress 

 

Can this be archived somehow? or do I have to "just" change my whole network to be fully vlan capable and run every switch port over VLAN1 e.t.c?  

1 Reply

  • schumaku's avatar
    schumaku
    Guru - Experienced User

    finnjaeger1337 wrote:

    My router is openWRT, and I have the following networks running on eht0

     

    -> Lan  192.168.33.0/24

    -> VLAN3 192.168.3.0/24

    -> VLAN4 192.168.4.0/24 

     

    DHCP running on each network.  


    Reads like your LAN is operating untagged, VLAN3 and VLAN4 are tagged accordingly. This makes up a trunk port, with VLAN1 (default) untagged, and VLAN3 and VLAN4 tagged. Same config on the switch port connecting to the router port (as well as to any other switch) does bring VLAN1, 3, and 4 to that switch.

     


    finnjaeger1337 wrote:

    What works:

    If I set a port to be untagged in lets say VLAN4  and set the PVID to 4  , the port is in VLAN4 clients get ip von the VLAN4 DHCP, all is well.   


    To make up a port a pure access port e.g. for VLAN4, remove any VLAN memberships except of VLAN4, make VLAN4 [U]ntgged, and PVID 4.

     


    finnjaeger1337 wrote:

    What doesnt work: 

    Getting any client/port into LAN/Management so that a client would get a 192.168.33.0/24 adress  


    Of course this works. Similar to the above, remove any VLAN memberships except of VLAN1, make VLAN1 [U]ntgged, and PVID 1.

     


    finnjaeger1337 wrote:

    Can this be archived somehow? or do I have to "just" change my whole network to be fully vlan capable and run every switch port over VLAN1 e.t.c?  


    To gain a proper segregation of the VLAN1, 3 and 4, all switches in the data path need to be VLAN capable and configured accordingly. A non-managed switch should only be connected to a non-trunk, read an access port for one specific VLAN only, makes it operating as an switch with all access ports for the VLAN the access port it does connect to. 

     

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More