× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

GS308E changing Management VLAN

Retired_Member
Not applicable

GS308E changing Management VLAN

Dear all,

I need to change the Management VLAN on a trunk of multiple GS308E Plus switches. How can one do that?

 

Thanks a lot

Message 1 of 8
schumaku
Guru

Re: GS308E changing Management VLAN

Netgear should post  KB entry on these kind of questions.

 

Like (almost, with a few exceptions only) all Plus GSxxxxE[n][n] switches, there is no managed core, and no management VLAN, never was. Management access is indeed possible from any VLAN, _and_ on untagged connections only, and in case there is IP access configured only for that specific IP (again on any untagged) connection configured to any VLAN. Tagged connections ie. over a trunk don't allow any management access when I have it right (or one could consider this as a bug).

 

Regards,

-Kurt

Message 2 of 8
Retired_Member
Not applicable

Re: GS308E changing Management VLAN

Thank you, thats a major security flaw. Is there a possibilty to report this at Netgear?

Message 3 of 8
DaneA
NETGEAR Employee Retired

Re: GS308E changing Management VLAN

@Retired_Member,

 

Welcome to the community! 🙂

 

Be informed that the GS308E does NOT support Management VLAN since it is a Smart Managed Plus Switch.  It is by design.

 

Smart Managed Plus Switch Models gives user the flexibility to configure certain static layer 2 settings in order to improve network efficiency and performance.  The configurable features are Port Mirroring, VLAN, QoS, Rate Limit, and Broadcast Storm Filtering.

 

If ever you want to implement a Management VLAN to your network, I suggest you either of the following switch models below.  Click the links to learn more:

 

Smart Managed Pro Switches

 

Insight Managed Smart Cloud Switches

 

Fully Managed Switches

 

 

Regards,

 

DaneA

NETGEAR Community Team

Message 4 of 8
Retired_Member
Not applicable

Re: GS308E changing Management VLAN

Thanks @DaneA - we bought a lot of them without knowing about this.

Where can I report this?

This is not a missing feature, this is a serious security flaw and needs to be reported - where can I do this?

Message 5 of 8
schumaku
Guru

Re: GS308E changing Management VLAN

These switches offer exactly the functionality described by the IEEE 802.3 standards, the 300 Series Plus Gigabit Ethernet Switches, User Manual Gigabit Ethernet Plus Switches Models GS105Ev2 GS105PE GS108Ev3 GS108PEv3 GS116Ev2 GS305..., or the NETGEAR 5-Port and 8-Port Gigabit Ethernet Smart Managed Plus SOHO Switch Model GS305E and GS308E In... 

 

You can always deploy as many GS308E in a network with trunked connections as you desire, keep the management on the untagged network on the trunk, while operate as many tagged VLANs as the system specs allow. The same applies to all Netgear Plus Managed Network Switches 

 

Anything else does come from pure educational, university, or other theoretical studies. A tagged network on a trunk is neither more secure or private than an untagged network.  For many deployments and customers, the plus switches are an absolute reasonable product.

 

If you have concerns that untrained or bad players can connect whatever system to what makes up your network "backhaul" giving physical access to any VLAN in the trunk, you need to work on the physical security.

 


@Retired_Member wrote:

we bought a lot of them without knowing about this.

All the documentation is readily available. If a need for a tagged exclusive management VLAN is a requirement (for whatever reason or interoperability eg. with an existing network). before buying large number of devices, set-up a test environment on a smaller amount of devices would be a common advise.

 

You acquired and probably already deployed web configurable unmanaged core switches at the per-port cost of an unmanaged switch, expect business class features. For just a few bucks more for the switch, Netgear offers the Smart Managed Switches and the Smart Cloud Managed Switches with management VLAN implementation as per your books.

 


@Retired_Member wrote:

Where can I report this?

This is not a missing feature, this is a serious security flaw and needs to be reported - where can I do this?


Of course it's a missing feature. Netgear does know about the limitations, so do the community members here. What do you expect now?

 

You still owe us the effective security flaw you are so keen for reporting. There are a few possible ones which can be "designed" by the unaware admin or network engineer over-spanning the scope of this simple design, e.g. by implementing multi VLAN networks, especially when other networks are exposed as untagged access ports.  However, this isn't what these switches are intended for.

 

As a community member, i can just point to my initial reply from a few days ago https://community.netgear.com/t5/Plus-and-Smart-Switches-Forum/GS308E-changing-Management-VLAN/m-p/2272244/highlight/true#M21733 - this would avoid similar discussions in the future.

Message 6 of 8
Retired_Member
Not applicable

Re: GS308E changing Management VLAN

Thanks for being such a delight to write to.

I will make sure not to use Netgear products in the future, thanks to your jack assery :).

Message 7 of 8
schumaku
Guru

Re: GS308E changing Management VLAN

Some monkeys don't like fact and truth .... typical style: Asking questions, talking about vulnerabilities, and not answering questions - just bail out. Hey, it's my personal private time and bandwidth I'm spending here.

Message 8 of 8
Top Contributors
Discussion stats
  • 7 replies
  • 2414 views
  • 5 kudos
  • 3 in conversation
Announcements