NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
sentur
Oct 18, 2023Tutor
Help setting VLANs on Netgear GS908E switch? Not receive an IP in the correct VLAN tagged IP range
I'm trying to set up VLAN tags on a Netgear GS908E switch. But I'm either not understanding or getting something very wrong. Here's a network diagram. VLAN tags are set on my gateway Unifi UDR. T...
- Oct 18, 2023
sentur wrote:
- UDM is managing the IoT VLAN and all other VLANs for that matter.
- It’s doing Gateway / Router / VLAN tag and network management and DHCP for all VLANs.
- UDM (LAN Port 2) is connected to Negear switch (LAN Port 1)
You must understand and know how your UDM is is configured providing the VLAN 1 and 20 on what becomes the trunk port for the GS908E. If you can connect a computer to this port, and you get DHCP from what is serving the VLAN 1, it's most likely not tagged. .
sentur wrote:
I think this is correct?
- VLAN ID 1:
- Tagged → Ports 1, 2, 4, 6, 7, 8
- Exclude → Ports 3, 5
- VLAN ID 20: IoT
- Tagged → Ports 3, 5
- Exclude → Ports 1, 2, 4, 6, 7, 8
Why oh why you changed all 1..8 to be tagged? It's only the trunk where you carry multiple VLANs which is all tagged (or one VLAN runs untagged).
- VLAN ID 1:
- Tagged → Ports 1 .. under the assumption the VLAN 1 is delivered as tagged. This is the de-facto standard for trunk links carrying multiple VLANs. It could be also used untagged for VLAN 1 with the PVID set to 1.
- Untagged as access ports → 2, 4, 6, 7, 8 with PVID set to 1
- Exclude → Ports 3, 5
- VLAN ID 20: IoT
- Tagged → Ports 1 ... this will be your uplink carrying the trunk of VLAN 1 and VLAN 20?
- Untagged → Ports 3, 5 with PVID set to 20 ...
- Exclude → Ports 1, 2, 4, 6, 7, 8
In general, I tent to suggest some "logical" port organization. Port 1 VLAN Trunk uplink, port 2...6 access ports for standard LAN 1, port 7, 8 access ports for IoT.
sentur wrote:
What’s the difference between Untagged and Excluded?
Excluded means the port is not participating in that VLAN.
Untagged means the frames leaving the switch on this post are untagged -and- the PVID defines the VLAN incoming untagged frames are assigned to.
- UDM is managing the IoT VLAN and all other VLANs for that matter.
sentur
Oct 18, 2023Tutor
Thanks Kurt.
- UDM is managing the IoT VLAN and all other VLANs for that matter.
- It’s doing Gateway / Router / VLAN tag and network management and DHCP for all VLANs.
- UDM (LAN Port 2) is connected to Negear switch (LAN Port 1)
What’s the difference between Untagged and Excluded?
I think this is correct?
- VLAN ID 1:
- Tagged → Ports 1, 2, 4, 6, 7, 8
- Exclude → Ports 3, 5
- VLAN ID 20: IoT
- Tagged → Ports 3, 5
- Exclude → Ports 1, 2, 4, 6, 7, 8
schumaku
Oct 18, 2023Guru - Experienced User
sentur wrote:
- UDM is managing the IoT VLAN and all other VLANs for that matter.
- It’s doing Gateway / Router / VLAN tag and network management and DHCP for all VLANs.
- UDM (LAN Port 2) is connected to Negear switch (LAN Port 1)
You must understand and know how your UDM is is configured providing the VLAN 1 and 20 on what becomes the trunk port for the GS908E. If you can connect a computer to this port, and you get DHCP from what is serving the VLAN 1, it's most likely not tagged. .
sentur wrote:
I think this is correct?
- VLAN ID 1:
- Tagged → Ports 1, 2, 4, 6, 7, 8
- Exclude → Ports 3, 5
- VLAN ID 20: IoT
- Tagged → Ports 3, 5
- Exclude → Ports 1, 2, 4, 6, 7, 8
Why oh why you changed all 1..8 to be tagged? It's only the trunk where you carry multiple VLANs which is all tagged (or one VLAN runs untagged).
- VLAN ID 1:
- Tagged → Ports 1 .. under the assumption the VLAN 1 is delivered as tagged. This is the de-facto standard for trunk links carrying multiple VLANs. It could be also used untagged for VLAN 1 with the PVID set to 1.
- Untagged as access ports → 2, 4, 6, 7, 8 with PVID set to 1
- Exclude → Ports 3, 5
- VLAN ID 20: IoT
- Tagged → Ports 1 ... this will be your uplink carrying the trunk of VLAN 1 and VLAN 20?
- Untagged → Ports 3, 5 with PVID set to 20 ...
- Exclude → Ports 1, 2, 4, 6, 7, 8
In general, I tent to suggest some "logical" port organization. Port 1 VLAN Trunk uplink, port 2...6 access ports for standard LAN 1, port 7, 8 access ports for IoT.
sentur wrote:
What’s the difference between Untagged and Excluded?
Excluded means the port is not participating in that VLAN.
Untagged means the frames leaving the switch on this post are untagged -and- the PVID defines the VLAN incoming untagged frames are assigned to.
- senturOct 18, 2023Tutor
- VLAN ID 1:
- Tagged → Ports 1 .. under the assumption the VLAN 1 is delivered as tagged. This is the de-facto standard for trunk links carrying multiple VLANs. It could be also used untagged for VLAN 1 with the PVID set to 1.
- Untagged as access ports → 2, 4, 6, 7, 8 with PVID set to 1
- Exclude → Ports 3, 5
- VLAN ID 20: IoT
- Tagged → Ports 1 ... this will be your uplink carrying the trunk of VLAN 1 and VLAN 20?
- Untagged → Ports 3, 5 with PVID set to 20 ...
- Exclude → Ports 1, 2, 4, 6, 7, 8
Thank you. This makes a lot more sense to me now. As to what needs to be tagged and untagged in each of the VLANs.
Thank you for taking the time to explain it schumaku
- VLAN ID 1:
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!