× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973

GS308T VLAN 802.1Q Tags missing in Egress from switch

jtalbert123
Tutor

GS308T VLAN 802.1Q Tags missing in Egress from switch

I have a GS308T switch connected to two test hosts and a management device assd shown in the diagram.test config.jpgPort 5 is connected to Test Host 1, which is set to VLAN-tag all frames for VLAN ID 102.

Port 6 is connected to Test Host 2, which is VLAN-unaware.

I have configured the VLANs as shown below:vlan settings.JPG

 

 

The following scenario seems wrong to me, and is certianly not what I want to happen:

  • Test Host 1 sends an ARP to test Host 2.
    • This ARP is VLAN-tagged and is only forwarded by the switch to Test Host 2 (good so far)
  • Test Host 2 receives the ARP untagged (also good)
  • Test Host 2 replies, and the switch forwards the reply only to Test Host 1
    • The reply is untagged as it exits the switch (BAD)

 

tcpdump shows the tagged request and untagged reply on the same interface of Test Host 1. Can anyone explain how to get the switch to output tagged frames? I want this so I can use my VM infrastructure and/or linux virtual interfaces to assign traffic to VLANs.

 

I've tried using more relaxed ingress filtering policies, but the issue is the lack of tags on the packets, not that I want them to be dropped. In all my experimentation so far, I am unable to generate a config that results in the switch transmitting 802.1q tagged packets to a host.

Model: GS308T|NETGEAR® S350 Series 8-Port Gigabit Ethernet Smart Managed Pro Switch
Message 1 of 5

Accepted Solutions
jtalbert123
Tutor

Re: GS308T VLAN 802.1Q Tags missing in Egress from switch

The issue was that windows removed VLAN tags from incoming packets before handing them to VMs.

The switch is fine, I just made the mistake of assuming that virtualization would bypass the VM Host's network stack.

View solution in original post

Message 5 of 5

All Replies
schumaku
Guru

Re: GS308T VLAN 802.1Q Tags missing in Egress from switch

Test host 1 is on g5 and using tagged frames for VLAN 101 and 102?

Test host 2 is on g3 for VLAN 101, respectively g6 for VLAN 102?

 

 

Message 2 of 5
jtalbert123
Tutor

Re: GS308T VLAN 802.1Q Tags missing in Egress from switch

g3 is not connected to anything, but Test Host 2 is on g6.

 

g5 (Test Host 1) is tagged on 101,102

  • Test Host 1 is configured to transmit tagged frames

g6 (Test Host 2) is untagged on 102

  • Test Host 2 expects/transmits untagged frames

 

Here's the table (since images aren't working in the post).

InterfacePVIDVLAN memberVLAN TagAcceptable FrameIngress FilteringCurrent Ingress FilteringUntagged VLANsTagged VLANsForbidden VLANsDynamic VLANsPort Priority
   
     
g111NoneAdmit AllEnableEnable1NoneNoneNone0
g211NoneAdmit AllEnableEnable1NoneNoneNone0
g3101101NoneAdmit Untagged OnlyEnableEnable101NoneNoneNone0
g411NoneAdmit AllEnableEnable1NoneNoneNone0
g51101-102101-102VLAN OnlyEnableEnableNone101-102NoneNone0
g6102102NoneAdmit Untagged OnlyEnableEnable102NoneNoneNone0
g711NoneAdmit AllEnableEnable1NoneNoneNone0
g811NoneAdmit AllEnableEnable1NoneNoneNone0
Model: GS308T|NETGEAR® S350 Series 8-Port Gigabit Ethernet Smart Managed Pro Switch
Message 3 of 5
schumaku
Guru

Re: GS308T VLAN 802.1Q Tags missing in Egress from switch

The switch config looks perfectly fins - nothing complex. The test result however is certainly showing a problem, I would expect this packet to be tagged on it's way out, too.

Message 4 of 5
jtalbert123
Tutor

Re: GS308T VLAN 802.1Q Tags missing in Egress from switch

The issue was that windows removed VLAN tags from incoming packets before handing them to VMs.

The switch is fine, I just made the mistake of assuming that virtualization would bypass the VM Host's network stack.

Message 5 of 5
Top Contributors
Discussion stats
  • 4 replies
  • 2110 views
  • 2 kudos
  • 2 in conversation
Announcements