NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
I have just bought the BE18000 Wi-Fi 7 router (RS600) and have come to realize that you cannot do VLAN Tagging on the WAN.
I have already read through the thread https://community.netgear.com/t5/Nighthawk-Wi-Fi-5-AC-Routers/WAN-vlan-tagging/m-p/1204117#M46785 and its reference KB https://kb.netgear.com/25724/VLAN-tagging-setup-for-Nighthawk-router?article=25724&cid=wmt_netgear_organic. The issue is that the KB only teaches how to do VLAN Tagging. This does NOT however outline that its not available within the firmware to do VLAN Tagging on the WAN/Internet port.
Options explored/discovered:
1. Support mentioned doing a bridge. I know this will work but its honestly a half baked response. This works but is nowhere near convenient. It takes up space and does not actually solve the problem. Its a duct tape solution.
2. 3rd party firmware. I will not be doing this option as it voids the warranty and can potentially break the device. The issue here isn't that, its the fact that the hardware itself can do VLAN tagging when using the 3rd party firmware. The NETGEAR firmware however, cannot.
3. Using a switch as a buffer between the router and the Optical Network Terminal (ONT) to handle VLAN tagging. I know this works in theory but I don't know how the ISP views the devices. Will they need to trust the switch or the routers MAC Address? This one is too complex for the average user.
Actual Issue: As internet is upgraded and companies move to full fiber infrastructure, we will no longer be needing modems as fiber is digital and not analog. As coax cable is analog the only reason we had modems was to demodulate and modulate data. Since houses are now connected to an ONT it now connects our internet straight to our house via Ethernet and not coax. This means we need to do VLAN Tagging on the WAN
Fix: Add VLAN Tagging to the WAN/Internet port to support upgrading internet infrastructure
I really don't want to return the product as I have had 4 nighthawk devices in the past but this is my first time dealing with Optical Network Terminals
Relevant Discussions (The all point to AP and bridge which is not a fix)
https://community.netgear.com/t5/Nighthawk-with-WiFi-6-AX-and/WAN-VLAN-Tagging-for-Fiber-ONT/m-p/2309291#M33179 
https://community.netgear.com/t5/Nighthawk-Wi-Fi-5-AC-Routers/WAN-vlan-tagging/m-p/1204117#M46785 
5 Comments
- FURRYe38Guru - Experienced User
Check the
"This article applies to:" For what is supported on the router with features.
If ISPs require a VLAN, some may require the use of there equipment.
I show my RS600 having VLAN support options under the Internet section of the UI which would be part of the WAN side:
You would need to check with the ISP to see if this section can be configured for an ISP use.
 - ceterrillFollower
FURRYe38 That table you show with the name internet is the name of the tag group. Not necessarily the internet port. When you click on edit, there should only be 7 options for ports 3 wifi options and 4 for ports 1-4. None of them are available for the WAN/Internet port. I know its possible with 3rd party configs but I am not trying to void my warranty. What I do know is that the hardware can do it. The firmware just needs to be updated to allow this
 - FURRYe38Guru - Experienced User
Something to contact NG support about to check with them then.
 - FURRYe38Guru - Experienced User
Good Luck