NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

JFarmer's avatar
JFarmer
Aspirant
Dec 24, 2020
Solved

VLAN Issue - Cannot provision VLAN's

Seasons greetings!

 

I've had a JGS524Ev2, latest 2.6.0.48 firmware, since May of this year, and finally have a firewall that can easily support VLANs to go along with it. When trying to create a dot 1q VLAN on the switch, I get weird issues. I've attached a video below outlining the issues. Overall, I cannot get the VLANs to work correctly, and no matter what I try, I get am IP in my dedicated LAN range of 192.168.5.X. I've tried several different things and can't seem to get it working. 

 

With Basic 802.1Q VLANs:

I can assign a VLAN to the port, with Port 1 on the switch set to "all", which from reading, will make this work much like a trunk port. Port 1 is my incoming directly from my PFSense firewall. Setting the VLAN seems to have no effect. 

 

With Advanced 802.1Q VLANs:

This is where things get even weirder... I can provision a VLAN ID correctly, but cannot add ports to it! Once I navigate to the VLAN Memebership category, I can select my other VLAN, add tagged and untagged ports. Upon clicking apply, the web configurator seems to glitch out, and navigating back to the recently created VLAN ID shows no ports associated with it. 

 

I cannot remove ports from VLAN 1 without changing the PVID, and cannot change the PVID without adding ports to the other VLANs! 

 

 

Any help would be much appreciated at this point. I've been battling this all day and this is what's keeping me from moving on to the next step in rebuilding my network. 

 

-JF

  • Ah, good find! That's why the basic config did not worked then, too. I just prefer the Advanced one as it's easier to see and understand - less hidden stuff.

    Use a different browser, ensure no Internet security *** does interfere with the JavaScript code.

    Never had to, but try to use the anonymous mode session.

5 Replies

Replies have been turned off for this discussion
  • schumaku's avatar
    schumaku
    Guru - Experienced User

    JFarmer wrote:

    With Advanced 802.1Q VLANs:

    I cannot remove ports from VLAN 1 without changing the PVID, and cannot change the PVID without adding ports to the other VLANs!


    Nothing weird here. Except that Netgear does just enforce us admins to get a halfway appropriate config to the switch - kind of a tedious click process I must admit. For correct 802.1Q VLAN (so leaving asymmetric VLAN configs alone which have not much in common with 802.1q):

     

    1. Create the VLAN(s) required
    2. Add the port(s) to the in the mode you want to the VLAN, being [T]agged or [U]ntagged
    3. Change the PVID to the VLAN ID you want untagged frames be assigned to, this is the only VLAN ID you intend to run [U]ntagged 
    4. Remove the port(s) form the VLAN by changing the [U] or [T] to empty [_]
    5. Remove VLAN(s) no longer required
    • JFarmer's avatar
      JFarmer
      Aspirant

      schumaku

       

      Thanks for the advice. This is my first time dealing with VLANs.

       

      My main problem is that it seems the configuration doesn't actually get saved to the switch. For example, when I use the advanced mode for 802.1q, I'll add my tag under Configuration, then move to membership to add the ports to the VLAN. Once I click "Apply", the screen bugs out, and my changes are not applied when re-selecting the VLAN I was editing. If I use 802.1q Basic, it just seems to not do anything! If I add a port to say VLAN 10, I expect to get an IP from that VLAN, but will still get an IP from my LAN network. Yes, DHCP is running on each VLAN interface.

      • schumaku's avatar
        schumaku
        Guru - Experienced User
        Ah, good find! That's why the basic config did not worked then, too. I just prefer the Advanced one as it's easier to see and understand - less hidden stuff.

        Use a different browser, ensure no Internet security *** does interfere with the JavaScript code.

        Never had to, but try to use the anonymous mode session.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More