NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
burgler2112
Apr 24, 2025Aspirant
Re: Unable to sign into GS308E
I'm having some issues with this product. I recently purchased it and set it up last week. But as soon as I set it up via the admin page and enable Advance 802.1Q VLANs, then I'm no longer able to ...
schumaku
Apr 27, 2025Guru - Experienced User
Now where we can start to understand your network a little bit more (I think) ...
burgler2112 wrote:
If I do a factory reset, I'm able to reach the switch and redo the setup, but once I do, I can no longer reach the admin page.
A good point to continue might be-which- devices will be connected to the GS308E, -what- and -how- you are going to re-configure your switch(es) repeatedly in 802.1q.
---
One point I don't yet understand: These two ports on your security appliance for connecting the VLAN 10, 20, 30, and 40 - are these [T]agged or [U]ntagged?
This looks to me (on the first view) like four ports [U]ntagged, so access ports for each of the four VLANs.
---
Start with the default config om the GS308E, and set it to 802.1q mode.
Add VLAN 10, 20, 30, and 40.
Go the VLAN Membership, and select the respective VLAN, start with 10.
User Group Operation: [Tag All], then [Apply].
Repeat for VLAN 20, 30, and 40.
- schumakuApr 27, 2025Guru - Experienced User
While talking: The reason you are able to discover the two GS305E and GS308E from the VLAN 40 (from an IP address in the ,40.x range) is that somehow any other switch and/or what is defined as VLAN 40 on your security appliance is somehow misconfigured (or completely unconfigured, or simply cross connected).
The discovery utility won't show any GS305E or GS308E(PP) model (in my testing) if connected to a different VLAN -and- IP subnet - so no NSDP is used anymore, it's pure SSDP. Some older GS1xxE(xx) might be discovered, because these are sill supporting NSDP and have never been updated.
- burgler2112Apr 28, 2025Aspirant
One point I don't yet understand: These two ports on your security appliance for connecting the VLAN 10, 20, 30, and 40 - are these [T]agged or [U]ntagged?
I will use VLAN10 as an example, but all the VLANs are set up in the same basic fashion.
On one of my switches I have VLAN10 assigned to Port 1. I have VLAN10 as “Untagged” on Port 1, but tagged on port’s 3, 7 and 8. The thought process here was that on port 1, the only thing that would be going through that port would be items that should be on VLAN 10.
Port's 3, 7, and 8 would be carrying all data via 99 that would need to be segregated elsewhere.
Here are some screenshots of the setup on one of my other switches:
- burgler2112Apr 28, 2025Aspirant
A good point to continue might be-which- devices will be connected to the GS308E, -what- and -how- you are going to re-configure your switch(es) repeatedly in 802.1q.
One other thing in regards to this, I don't want to have to reconfigure the switch repeatedly. I really wanted to just set it up and forget about it, as I did with my original switches. I just happened to check the new switch after I had done the setup and realized I could no longer access the web interface. And that led me down the rabbit hole of factory resets and troubleshooting and this forum. LOL.
Had I not tried to access the web interface to double check my setup last week, we wouldn't be here right now!
- schumakuApr 28, 2025Guru - Experienced User
Pert of the rabbit hole? Since (most of) these Plus switches don't support any kind of management VLAN, you can't have multiple VLANs with DHCP active, untagged frames using the switch DHCP client can (and will!) receive a device config for a random IP subnet - in an unintended way.
Foer example, in case four of the ports on your GS308E are configured for PVID 10, 20, 30, and 40 (to associate incoming frames to the appropriate VLAN) and each as [U]ntagged fro VLAN 10, and so on - all- traffic is visible to the Plus switch uC. While assuming a correct config is in place eg. the DHCP request will go to the intended VLAN, the uC with it's IP stack, DCHP client, as well as the ICMP snooping, which is aloso handled by that very same uC. I -assume- you have these four security device Ethernet ports connected to the same GS308E (permitting the VLAN config is correct), for example the DCHP server for the relevant VLAN (eg, 10, 20, 30, or 40) will receive all DHCP request traffic. So the DHCP server for these subnets will apparently "leak",
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!