× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

Re: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

jleon71
Aspirant

GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Hello everyone, I have been trying to configure multiple vlans to be accessible on my unifi AP. I read similar post where people indicated they were successful, however I have not been lucky enough to be successful.  Here is my harware info. I will appreciate if anyone can help me troubleshot/setup.   thanks in advance.

 

1 Unifi USG-3

1 UAP-AC-PRO

1 netgear GS324TP S350

 

USG3 port1 ---> netgear GS324TP Port1

UAP-AC-PRO ---> netgear GS324TP Port5

 

USG3 network and wireless config

Networking 

internetofthings VLAN10 172.16.10.1/24

SecurityCam  VLAN20 172.16.20.1/24

VLAN1  192.168.2.1/24

 

Wireless Networks (inherit the above network IP)

internetofthings ---> internetofthings network

SecurityCam ---> SecurityCam network. 

 

Netgeat GS324TP

Port 1.  Untaged VLAN ID 1 / Taged VLAN ID 10 and 20

Port 5.  Untaged VLAN ID 1 / Taged VLAN ID 10 and 20

Port 1 to 26 : untaged VLAN ID 1

 

The access point is able to see the device attemtping to connect, but it is unable to obtain IP address. I am sharin couple screen capture for reference.

 

NetgearGS324TP-VLANPVIDPORT.pngUSG-3-Devices-tab.pngUSG-3-Network-Config.pngUSG-3-Networks.pngUSG-3-SecurityCam-Settings.pngUSG-3-System-Config.pngUSG-3-Wireless-Networks.png

 

 

 

 

Model: GS324TP|NETGEAR® S350 Series 24-Port Gigabit PoE+ Ethernet Smart Managed Pro Switch with 2 SFP Ports
Message 1 of 12
jleon71
Aspirant

Re: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Pictures did not appear on the first post. NetgearGS324TP-VLANPVIDPORT.png

 

USG-3-SecurityCam-Settings.png

 

USG-3-Devices-tab.png

 

USG-3-Network-Config.png

 

USG-3-System-Config.png

 

USG-3-Wireless-Networks.png

 

USG-3-Networks.png

 

Message 2 of 12
schumaku
Guru

Re: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

@jleon71 

 

Based on the NetgearGS324TP-VLANPVIDPORT.png and assuming USG and AP are connected to the two ports configured accordingly, there isn't anything wrong with your VLAN config. Back to the UniFi config I'd say...

 

PS. The in-line images are under mandatory moderation, so it will take a while until visible.

 

 

Message 3 of 12
DietmarItsMe
Aspirant

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Hi Jelon71,

 

I have a very similar problem using a Unify Dream Machine  and  a GS348T switch  +  a Unify U6-Lite AP.

The AP  plugged into the Unify Dream Machine works perfect, when I plug it into my switch  it does no longer.

My assumption is that the DHCP requests  do not get through, but  I 'm just not sure  what I need to configure .

My config on the switch VLAN looks exactly like yours.

Is there any other traffic that needs to be allowed  on the switch?

 

Did you find the problem?

 

Thanks

 

Dietmar

 

Message 4 of 12
schumaku
Guru

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO


@DietmarItsMe wrote:

My assumption is that the DHCP requests  do not get through,


Where exactly, which VLAN, ...? The basic untagged (?) UniFi management VLAN or any other VLAN accessed by some dedicated SSID(s)?

Message 5 of 12
DietmarItsMe
Aspirant

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Hi  schumaku,

 

I have  3 WIFI Networks , lets call them WIFI_PRIVATE, WIFI_GUEST, WIFI_IOT and according to these 4 VLANs  

WIFI_PRIVATE = 5 (DM Port 1 - Switch Port  1) PVID 5 Tagged 5

WIFI_GUEST = 15(DM Port 2 - Switch Port  15) PVID 15 Tagged 15

WIFI_IOT = 35(DM Port 3 - Switch Port  20) PVID 35 Tagged 35

Management LAN = 1(DM Port 4 - Switch Port  30) PVID 1 Tagged 1

AP = Switch Port 31 - Tagged for  1,5,15,35 and  PVID  1

The WIFI Networs all do have wired network as well.

And there are 4 DHCP  Servers configured in my Dream Machine

 

I use 4 uplink cables from my Dream Machine to  the switch . One for each VLAN (I  know  this is not needed, but made it easier for mybrain 🙂

 

The switch is configured on VLAN 1 to be management VLAN

My thought was, that the AP needs to acquire an IP Address, which should be on the Management VLAN, as this defaults to 1 (I assume) it should come through from Port 31 to 30 and should reach the DHCP there.

Then it spans the  WIFI and communicates on the  tagged Networks according to the LAN Config  that is used on each WIFI.

 

But the AP just tries to communicate with my DM and then fails. 

As I said, I assume it is the DHCP, bur maybe it is something that I don't see yet.

Any idea what I do wrong?

 

Thanks

 

 

 

 

 

 

 

Message 6 of 12
schumaku
Guru

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Best guess (at least by default) the UniFi management network is untagged - so keep the port to the AP untagged for the management VLAN 1. PIVD is already set to 1, so now you should be ready to run.

Message 7 of 12
DietmarItsMe
Aspirant

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Hi schumaku,

 

thanks a lot, now it works. I had to switch off my firewall rules between the networks and need to figure out how they need to be set, but this is a different story. 

If there is a hint how to allow management traffic  like DHCP requests m but no other traffic, please let me know 🙂

 

Thanks a lot

 

Message 8 of 12
DietmarItsMe
Aspirant

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Hi schumaku,

 

seems my success was called too early. IAfter rebooting the AP the problem stays as I've seen it before.

Here my question.

The DM does not TAG VLAN 1 , and it is impossible to configure it for VLAN 1. Would it be a good decision to configure the DM  Management LAN with VLAN 2.  The switch needs to have  the Management VLAN to be tagged. If the switch defaults to 1 and DM to no Tag, would they even talk together? I assumed the PVID  and an untagged Port would solve this, but does it?

 

Thanks

Message 9 of 12
schumaku
Guru

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Lot's of training seems to be required here - most general VLAN and Ubiquity specific - very few Netgear switch related.

 


@DietmarItsMe wrote:

The DM does not TAG VLAN 1 , and it is impossible to configure it for VLAN 1.


Yes, this is siilar to what I mentioned ref. the UniFi APs, too. 

 

Configure the ports where you are connecting the DM and the APs for VLAN 1 [U]ntagged and PVID 1. This makes the switch sending VLAN 1 frames untagged, the PVID 1 assigns incoming untagged frames to the VLAN 1. (the second is about the only Netgear switch specific thing).

  


@DietmarItsMe wrote:

The switch needs to have  the Management VLAN to be tagged. If the switch defaults to 1 and DM to no Tag, would they even talk together?


No. Where is this information coming from? The config says the switch does make use the VLAN 1 for the management. How the management access comes to the switch is not relevant.

 

The VLAN 1 traffic be on a trunk port where the VLAN 1 it [T]agged (not just on the switch, also the connecting device to this network link - this is what one would typically do if multiple VLANs are transported on the same link - unless devices require one VLAN untagged), or it can be VLAN 1 frames untagged, the PVID 1 assigns incoming untagged frames to the VLAN 1 as explained. 

  


@DietmarItsMe wrote:

I assumed the PVID  and an untagged Port would solve this, but does it?


See above.

 

  

Message 10 of 12
DietmarItsMe
Aspirant

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Hi schumaku,

 

thanks for filling my knowlege holes 🙂 and helping me out here.

I do have, the DM and AP  on  PVID 1 and [U]ntagged for  VLAN1

All the other VLANs are Tagged on  both ports, my assumption  was that this would be a transparent way through the switch, as a direct connect to the AP to DM on the same DM Port works fine.

The AP  continuously restarts with  "Isolated/Restarting/RFScanning" state. The IP seems to be assigned now.

 

I'm lost, and the guy I pay for handle my Network suggests to buy a new switch from unify.   I don't want to do this.  😞

 

Is there a diagram, video or anything out there explaining how the AP and DM communicate, and what kind of traffic needs to be enabled in order they could find and like each other?

 

 

 

Message 11 of 12
schumaku
Guru

Betreff: GS324TP S350 unable to obtain IP from unifi USG3 and UAP-AC-PRO

Yet another issue that is not a Netgear problem - your config looks fine based on the description, but I would double check things 8-)

 

Reads to me your APs can't reach the UniFi controller - this is either a the UniFi Cloud Key or the DM - is why ever not reachable, or does hang around in another VLAN and/or IP subnet. Again something that should reside on an untagged VLAN 1 by rule of thumb. Also check the APs (without a tagged management configured - just in case) VLAN and the controller are really on the same subnet (and VLAN). 

Message 12 of 12
Top Contributors
Discussion stats
  • 11 replies
  • 2111 views
  • 0 kudos
  • 3 in conversation
Announcements