NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Quazimodo
Nov 22, 2024Aspirant
Unable to Use Guest Wifi in AP Mode and a Switched Wired Backhaul
Hi, Summary: Need a solution to run a Guest Network on a Orbi 970 Wifi 7 system in AP mode with a switched and wired backhaul I have a Firewalla Gold Pro router feeding internet into a Netgea...
Quazimodo
Nov 22, 2024Aspirant
Hi,
Thank you all for the replies.
Given that VLAN tagging is a 26 year old protocol (IEEE 802.1Q), and that it should be quite easy to implement the software given hardware that clearly supports it, I'm left to wonder why they chose something that I feel is a lot more complicated. Further, it seems this was supported in previous Orbis. This could not have come from the engineering department.
For now, I've temporarily removed the switch in between the Orbi and the satellites even though the manual clearly shows this is supported. I am able to have the guest network working by using the 10Gbps LAN port and a 2.5Gbps LAN port to connect to the satellites. But this solution is one 10Gbps LAN port short of being acceptable. I bought this for 10Gbps support.
Kurt: are you saying that there is a layer 3 hack that I can implement on a different switch that could make this work? Then I might get a the Mikrotik CRS-304 to replace my layer 2 5-port switch.
Given the directions of some of the comments I feel the need to make some clarifications about my use case.
a) This is for a home, not a business. I want simplicity, 10Gpbs, low latency and a large coverage area.
b) I came to chose the Orbi 970 series system because it was the only one that has a 10Gbps backhaul that I could find. This network will be used for gaming, AV, local file transfers, uncompressed video and future proofing applications such as virtual reality. So high speed and low latency switching are factors in this choice. Solutions such as Unifi Wifi 7 have 2.5Gbps wired backhaul. That takes the 7 out of Wifi 7, I'm not sure why anyone using Unifi for Wifi doesn't stop at Wifi 6e. I read 168 page Orbi manual from cover before buying (which is easier than it sounds, there is a lot of repetition) and I felt informed that it met my needs. The good reviews were also a factor.
c) The small switch after the Orbi RBE971 was not there originally. I have a couple of professional layer 3 switches taking care of everything in my network but I had to add the switch after a number of lengthy support calls to Netgear. My regular Wifi was not working on the satellites, let alone the Guest network. Turns out Orbi has other limitations on the wired backhaul due the non-standard proprietary nature of their mechanism. I don't know the exact reason as details were not provided. But from what I deduce you need to have something in place that looks like a hardwired Minimal Spanning Tree or else the Orbi system can't deal with it. Even the regular Wifi SSID wouldn't work. So the switch was added. But then that breaks the Guest Network due to the 192.168.2.X business. I do not know of any product that Netgear makes that is comparable (small, fanless full 10Gbps switch). The most powerful I've seen is the Mikrotik CRS304-4X at $199 which has layer 3 features and 3 redundant power supplies. So I can't really get a Netgear switch, it doesn't exist as far as I can tell. I saw netgear M4350 at ~$4700 switch that came close though. But at that price, even if it did...
d) The Firewalla Gold Pro is an extremely capable device targeting the home user such as myself. I can even get rid of my Unifi Cloud Key (or a Dream machine) by running Unifi Network in a container on its OS. It is a wonderful device and I don't have to spend hours configuring it like my two layer 3 switches. I can't say enough about it, let's not underestimate it.
Thanks.
schumaku
Nov 22, 2024Guru - Experienced User
Quazimodo wrote:
Given that VLAN tagging is a 26 year old protocol (IEEE 802.1Q), and that it should be quite easy to implement the software given hardware that clearly supports it,
I would expect the primary WLAN SSID does run transparent untagged on the wired backhaul anyway - no hacks required - but I can be wrong of course.
Quazimodo wrote:
I'm left to wonder why they chose something that I feel is a lot more complicated.
Nothing to dispute with me, these Orbi are consumer systems as of writing.
Have-no- experience on these recent Orbi and Orbi Pro (which rumors told me there won't be any WiFi 7 Orbi Pro coming soon).
This is why the VLAN config features of the Orbi Pro and the consumer Orbi we're facing here are not deployed as deep as we would expect.
Quazimodo wrote:
Further, it seems this was supported in previous Orbis. This could not have come from the engineering department.
Don't know what Orbi models you have in mind. Best guess you compared to some Orbi Pro.
Quazimodo wrote:
For now, I've temporarily removed the switch in between the Orbi and the satellites even though the manual clearly shows this is supported. I am able to have the guest network working by using the 10Gbps LAN port and a 2.5Gbps LAN port to connect to the satellites. But this solution is one 10Gbps LAN port short of being acceptable. I bought this for 10Gbps support.
Therefore, I have never looked into the currnt Orbi WiFi 7 systems yet, not done any reverse engineering, too.
Quazimodo wrote:
Kurt: are you saying that there is a layer 3 hack that I can implement on a different switch that could make this work? Then I might get a the Mikrotik CRS-304 to replace my layer 2 5-port switch.
Have -no- experience on these recent Orbi and Orbi Pro (which rumors told me there won't be any WiFi 7 Orbi Pro coming soon).
This is why the VLAN config features of the Orbi Pro and the consumer Orbi we're facing here are not deployed as deep as we would expect.
CrimpOn would be more your partner on that side here.
When operating a more complex network with such a security appliance, mutlple SSIDs and two our more VLANs, I would opt for one of the ubiquitous VLAN capapble 10G/MultiGig switch, like the MS510TXUP, PoE++ capable, and some WBE75x APs. And for simplicity, I have opted for using Insight Managed switches and APs here in my new home along with a decent security appliance.
So please keep me posted and in the loop.
Regards,
-Kurt.