17
Votes

ER7212PC can't assign profiles to switch ports.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
 
17
Votes

ER7212PC can't assign profiles to switch ports.

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
48 Reply
Re:ER7212PC can't assign profiles to switch ports.
2023-04-26 07:25:47

Hello @LordPayder,

 

Thank you for your reply, and thank you @sradman for your instruction!

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
#35
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-05-07 11:02:50 - last edited 2023-05-07 11:04:21

  @LordPayder Hi all!
I am using ER7212PC (sw: 1.0.3) and in fact it's possible to configure VLAN ID per port.
Still, I am wondering how ER7212PC -> SG2210P (switch in my setup) works as I've assigned one of the ports to VLAN ID 1 (which is my mgmt) and I have 2 additional networks with assigned VLANs. And the ER7212PC somehow manages to send tagged packages with all VLANs to SG2210P.

 

So I guess, the convention is that whenever you set VLAN ID on ER7212PC's port it sends it untagged and rest of VLANs are sent tagged. Making ER7212PC ports "Profile aware" is something I am looking for.

 

Additionally it has been pointed out - but I am not able to define ACL for ER7212PC as I can do for SG2210P. I.e. one network can/can't talk to second and vice-versa.

 

Dear tp-link, please make ER7212PC visible as a switch in Omada. I think you could actually make it easy by displaying the ER7212PC itself as 3 separate devices in Odama's "Device" tab.

I doubt you aim to confuse your customers with false-advertisement. The ER7212PC is in fact 3-in-1, but you should know what can be expected from "business" customers.

 

In my case I can't return the device. I am looking for improvements.

Thank you!

#36
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-09 10:09:41

  @Fae 

 

I managed to assing a vlan to a Lan port, with this new firmware.

The behavior is like untagged vlan on Lan3.

Every device on this port now is in my Vlan 100.

 

But the question that remains:

 

How to I prevent traffic between this vlan and the default lan and/or a second Vlan.

I tried using the switch ACL, but this doesn't work.

 

In my opinion traffic between VLAN should be block by default and you should have a choise to allow it.

 

Forcing to add a managed omada with this product for this is a design failure. Otherwise this product is perfect for small envirements.

 

Regards Maikel

#37
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-12 04:13:52 - last edited 2023-06-12 04:14:51

Hello @Maikel-K,

 

The ER7212PC is an Omada 3-in-1 Gigabit VPN Router, not a switch. You may configure Gateway ACL instead to block the communication between VLAN interfaces if you don't have an Omada managed switch in your network.

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
#38
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-12 13:02:38

  @Fae 

 

Hi Fae. 

 

I tried this with no luck.

 

Can you give me an example on how to configure this?

 

Regards Maikel

#39
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-13 02:58:35

Hello @Maikel-K,

 

To assist you efficiently, please kindly elaborate on your network topology and requirement (what you want to achieve) by starting a new thread here. Thank you for your cooperation and patience!

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
#40
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-23 15:13:46

  @Fae 

 

Hi Fae.

 

It is quit simple.

 

I want the default Vlan1 on Lan1 and Vlan2 on Lan2 and Vlan3 on Lan3 and want to block traffic between them.

 

Vlan1 = subnet 192.168.0.0/24

Vlan2 = subnet 192.168.20.0/24

Vlan3 = subnet 192.168.30.0/24

 

I managed to get working:

 

PC on Vlan1 - Port Lan1 gets dhcp address in of subnet 192.168.0.0/24

PC on Vlan2 - Port Lan2 gets dhcp address in of subnet 192.168.20.0/24

PC on Vlan3 - Port Lan3 gets dhcp address in of subnet 192.168.30.0/24

 

But they can all communicate with each other.

How can I configure this in the ER7212PC to block it. 

 

With wireless clients on a omada EAP it is working great.

 

While wireless clients are connected to AP on Lan4 with wifi networks for all three Vlans I can prevent traffic with EAP ACL Rules.

But probably this is already blocked on the EAP itself?

 

Hope you can help.

Normally I would expect this to be configured at the switch ACL tab, but for some stupid reason this is not the case.

 

regards Maikel

 

 

 

#41
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-27 20:04:10

Hello @Fae,

 

I am sorry, but I believe there has been a mistake at TP-Link which migth explain these misunderstandings. Someone accedentially changed the description of the ER7212PC from being a "PoE switch" to now erroneously being shown as "PoE output". - To aid in the investigation, the mixup has happended at some point after 10-APR-2023.

 

All, being on the same page, please advice on how to utilize the switch and switch-ACL capabilities of the ER7212PC.

 

Thank you :o)

 

/3660

 

 

https://web.archive.org/web/20230410112519/https://www.tp-link.com/no/business-networking/omada-sdn-router/er7212pc/

#42
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-28 20:09:22

nice catch :D
 

in polish version it still says "Switch" (you have to trust me :)

BTW. because of all of the limitations I've returned the ER7212PC and I bought ER7206 + OC200 + TL-SG2210P instead
well, that's exactly what tp-link wants
however, this is my last SDN branded "tp-link"

#43
Options
Re:ER7212PC can't assign profiles to switch ports.
2023-06-29 08:20:37 - last edited 2023-06-29 08:20:56

Hello @Maikel-K,

 

Maikel-K wrote

I want the default Vlan1 on Lan1 and Vlan2 on Lan2 and Vlan3 on Lan3 and want to block traffic between them.

 

EAP ACL rules will only be applied to clients whose traffic passes through the Omada managed EAP, similarly, Gateway ACL rules will be applied to clients whose traffic passes through the Omada managed Gateway.

 

For your case, you need to block the traffic that will pass through the gateway, so EAP ACL or Switch ACL could not fully help.

 

With Gateway ACL, you may block traffic between the VLAN1, VLAN2 and VLAN3 by creating Deny ACL rules with LAN->LAN direction.

See example below.

 

 

>> Omada EAP Firmware Trial Available Here << *Try filtering posts on each forum by Label of [Early Access]*
#44
Options