NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

RCCrosier's avatar
Dec 09, 2021
Solved

Unable to route Netgear FS728TP VLAN 5 to Cisco Meraki MS250-24 switch

Hi,   We have mostly Meraki switches, but our loss prevention manager has Netgear FS728TP switches that all his cameras are on.   In the past 6-8 years, all cameras were on the default VLAN (1, 1...
  • schumaku's avatar
    schumaku
    Dec 10, 2021

    Exactly what I mentioned above about certain brands which are hiding the effecive standard technology. It's about the Meraki partner to tell us how these Meraki trunk ports are configured exactly - then I'm happy to help. Coming back to the start:


    schumaku wrote:

    RCCrosier wrote:

    The Meraki MS250 port #1 is connected to first Netgear port #6.

    Meraki port 1 is Native VLAN 1, Trunk port.

    So yes, appears the VLAN 5 does not exist on the Meraki side - or there is "more" which isn't shown here. ...


    All I can read here is that the port is configured to be a trunk (so not an access port), and the untagged traffic is associated with VLAN 1. 

     

    Note the designation "native VLAN" has a very bad taste with network security world, having caused plenty of holes and vulnerabilities caused (ha, mainly Cisco systems) by having a unchangeable "native VLAN".

     


    schumaku wrote:

    RCCrosier wrote:

    Netgear port 6 is VLAN 1 untagged.  VLAN 5 tagged.  PVID on ALL ports is 1.


     

    Still incomplete (VLAN 5 only on the trunk?), and partially wrong in the PVID aspect. The PVID does define the switch VLAN where untagged frames are associated to.

    For a trunk - and I think I've mentioned this several times - I would expect a config like this on the trunk:

     

    VLAN 1, [U]ntagged, PVID 1
    VLAN 5, [T]agged
    (this makes up a trunk carrying VLAN 1 untagged, and VLAN 5 tagged)

    For the access ports connecting the new cameras it's only:

    VLAN 5, [U]ntagged, PVID 5.

    (and no other VLAN memberships, that makes up an access port for VLAN 5)

    For the access ports connecting the old NVR/cameras on VLAN 1 it's only:

     

    VLAN 1, [U]ntagged, PVID 1.

    (and no other VLAN memberships, that makes up an access port for VLAN 1)

     

    With this config, trunking to whatever brand switch uplink, you have the VLAN 5 and the VLAN 1. Guessing again the VLAN 1 is also used as the management network for the switches et all. Watch your step acordingly in case you plan to change the management VLAN - the uplink trunk must be configued accordingly and workable for all VLANs

     

    Again, it's no rocket science, and that's on how such simple networks with a few VLANs on a trunk are configued for decades. Nothing I show here is "Netgear" specific! You can expect from your Meraki partner that they are able to translate their fancy coloured marketing click UI to the basics resp. configure a trunk port according to the above.

     

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More