NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
bcnx
Dec 29, 2021Aspirant
Tagged VLAN not working on a GS324T
Hi all,
I have a peculiar problem that has made me pull my hair out for quite some time.
The setup is easy: A Sophos firewall has 3 VLANs defined next to the default VLAN. We have a trunk from the Sophos firewall to the Netgear GS234T switch (on the latest firmware, 1.0.0.38) with VLAN1 untagged and the other VLAN tagged. Then there is another port with the same VLANs tagged and untagged that connects to the next switch. This switch also has the same tagging and untagging going on to precisely match things.
When we connect a device to this last switch, we cannot ping or scan it.
When we remove the last switch, replace it by this device and change the port on the Netgear to untagged for the VLAN we are testing with, we can succesfully ping it.
So it seems the tested VLAN is present on the Netgear switch, otherwise we could not ping when using this VLAN's untagged port.
But as soon as we add another switch and we go from untagged to tagged, things fail. We tried another switch for the last one in the chain, to no avail.
We do see the devices MAC in the Mac Address Table, proving to me that there is some sort of connection in between the Netgear switch and the next one.
What could be happening here? I know for a fact we need tagging. I'm now in the middle of studying the 365-page manual but I would like your ideas on this,
Cheers,
BC
8 Replies
Replies have been turned off for this discussion
- DaneANETGEAR Employee Retired
bcnx,
Welcome to the community! :)
What is the model/brand of the next switch connected to the GS234T? Is it also a GS234T?
The ports connecting the GS324T and the next switch should be tagged with a PVID of 1.
Also, be informed that you can daisy chain or cascade a number of switches since there is no limit on it. However, the good practice would be up to 2-3 switches daisy chained. Its because the more switch that you daisy chain will add latency on the network.
Regards,
DaneA
NETGEAR Community Team
- bcnxAspirant
Hi DaneA ,
We've tried an HP Aruba and a TPLink switch.
Taqgging with a PVID: we have the problem on the VLANs not tagged by 1. Will tagging with PVID 1 help us in that case? Also, it was my understanding that the default VLAN 1 should never be tagged, correct?
We are currently only daisychaining 2 switches so I think we should be alright there,
Cheers for your input!
BC
- schumakuGuru - Experienced User
bcnx wrote:
Taqgging with a PVID: we have the problem on the VLANs not tagged by 1. Will tagging with PVID 1 help us in that case?
If you want the VLAN 1 untagged, the PVID on these ports must be set to PVID 1, too. This is not about taging the VLAN 1. SImilar of you configure other VLAN access ports (only one of course), the VLAN x and the PVID must be set to x, too.
The PVID does define the VLAN incoming frames are assigned to.
If you configure a different PVID thant the [U]ntaged VLAN, you create some kind of asymmetrical VLAN config, the untagged inboud frames will go to the wrong VLAN - obviously, the VLAN 1 [U]ntagged can't work in a transparent way.
bcnx wrote:
Also, it was my understanding that the default VLAN 1 should never be tagged, correct?
For simplicity, it's a good policy to run the primary VLAN untagged.
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!