NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
bcnx
Dec 29, 2021Aspirant
Tagged VLAN not working on a GS324T
Hi all, I have a peculiar problem that has made me pull my hair out for quite some time. The setup is easy: A Sophos firewall has 3 VLANs defined next to the default VLAN. We have a trunk from t...
bcnx
Dec 30, 2021Aspirant
Hi DaneA ,
We've tried an HP Aruba and a TPLink switch.
Taqgging with a PVID: we have the problem on the VLANs not tagged by 1. Will tagging with PVID 1 help us in that case? Also, it was my understanding that the default VLAN 1 should never be tagged, correct?
We are currently only daisychaining 2 switches so I think we should be alright there,
Cheers for your input!
BC
schumaku
Dec 30, 2021Guru - Experienced User
bcnx wrote:
Taqgging with a PVID: we have the problem on the VLANs not tagged by 1. Will tagging with PVID 1 help us in that case?
If you want the VLAN 1 untagged, the PVID on these ports must be set to PVID 1, too. This is not about taging the VLAN 1. SImilar of you configure other VLAN access ports (only one of course), the VLAN x and the PVID must be set to x, too.
The PVID does define the VLAN incoming frames are assigned to.
If you configure a different PVID thant the [U]ntaged VLAN, you create some kind of asymmetrical VLAN config, the untagged inboud frames will go to the wrong VLAN - obviously, the VLAN 1 [U]ntagged can't work in a transparent way.
bcnx wrote:
Also, it was my understanding that the default VLAN 1 should never be tagged, correct?
For simplicity, it's a good policy to run the primary VLAN untagged.
- bcnxDec 30, 2021Aspirant
Hi again,
schumaku wrote:
bcnx wrote:Taqgging with a PVID: we have the problem on the VLANs not tagged by 1. Will tagging with PVID 1 help us in that case?
If you want the VLAN 1 untagged, the PVID on these ports must be set to PVID 1, too. This is not about taging the VLAN 1. SImilar of you configure other VLAN access ports (only one of course), the VLAN x and the PVID must be set to x, too.
It was my understanding that the PVID is a setting for tagging frames that enter the switch without tagging ID and that you use it for untagged ports. However, I'm not sure how this will help for the traffic on the other VLAN (60) which we need to work. Even more, PVID equal to 1 is the default setting and things did not work with that setting.
The PVID does define the VLAN incoming frames are assigned to.
Exactly, but how does this relate to tagged traffic on a trunk port for another VLAN?
If you configure a different PVID thant the [U]ntaged VLAN, you create some kind of asymmetrical VLAN config, the untagged inboud frames will go to the wrong VLAN - obviously, the VLAN 1 [U]ntagged can't work in a transparent way.
That is how I understand it. Mind you, using the trunk port as an untagged port for the VLAN we like to contact to, did start working when the PVID was set to that particular VLAN. But that was just a test, we need a trunk connection for all VLANs, se we tagged the uplink/trunk port for all VLANs except for the default VLAN which remains untaged.
bcnx wrote:Also, it was my understanding that the default VLAN 1 should never be tagged, correct?
For simplicity, it's a good policy to run the primary VLAN untagged.
Exactly, that is what we do. And PVID has always been set to 1, yet VLAN 60, which is tagged, does not work in combination with another switch. It's still a mystery as to why, both switches have a tagged port for VLAN 60.
Thanks for your input!
BC
- schumakuDec 30, 2021Guru - Experienced User
Afraid, have no GS324T switch at hand, so can't test or judge .... based on many Netgear switch VLAN deployments, these features are typically very reliable.
- bcnxDec 30, 2021Aspirant
schumaku wrote:Afraid, have no GS324T switch at hand, so can't test or judge .... based on many Netgear switch VLAN deployments, these features are typically very reliable.
Well, I can simply reiterate the situation and the problem: we have a trunk port in between the Netgear and the HP switch. On the Netgear side we have an untagged config for VLAN 1 and a tagged config for VLAN 60. The PVID is currently set to 1, as you propose. On the HP side we have the same kind of config on the trunk port, and we have also untagged ports for VLAN 60 to which we connect devices for VLAN 60.
So basically we do what you suggest, however VLAN 60 does not function. So where does it go wrong?
BC
Related Content
NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!