SG2008P Port Security

SG2008P Port Security

SG2008P Port Security
SG2008P Port Security
2025-02-24 00:45:01 - last edited 2025-02-24 04:31:30
Tags: #port security
Model: SG2008P  
Hardware Version: V3
Firmware Version: 3.20.0 Build 20230818 Rel.72032

I have a SG2008P in my Omada Controller where one of the ports is connected to an outdoor AP. I need to configure port security on this port to prevent anyone from plugging in. I don't see anything in the switch config on the controller but the manual says it supports port security. Does anyone know how to configure this?

  0      
  0      
#1
Options
1 Accepted Solution
Re:SG2008P Port Security-Solution
2025-03-04 19:20:27 - last edited 2025-03-04 20:31:44

Amazing this is still not possible.

 

In 2022 this was already indicated as an inssue and it would be forwardedn to the R&D appartment.

 

Now it's 2025 and it is still not possible to do this in the controller interface.....

Recommended Solution
  1  
  1  
#9
Options
10 Reply
Re:SG2008P Port Security
2025-02-24 00:46:28

Hi @someguy1234 

Thanks for posting in our business forum.

Port Security is currently a proprietary function that is available in the standalone mode.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#2
Options
Re:SG2008P Port Security
2025-02-24 01:54:53

  @Clive_A Thanks for the reply. So you mean I have to disassociate it from my Omada controller? Why isn't it supported in the controller? Why did I spend 100 dollars on this switch only to use it in standalone mode?

  0  
  0  
#3
Options
Re:SG2008P Port Security
2025-02-24 02:26:06 - last edited 2025-03-04 20:31:49

Hi @someguy1234 

Thanks for posting in our business forum.

someguy1234 wrote

  @Clive_A Thanks for the reply. So you mean I have to disassociate it from my Omada controller? Why isn't it supported in the controller? Why did I spend 100 dollars on this switch only to use it in standalone mode?

You are correct. Have to disassociate it from the controller.

Unfortunately, that's the case now. This feature was never added to the Controller mode. No such feature in Controller mode, and it does not support CLI configuration to enable it.

I think it could be a limitation on the Controller. Similar requests have been sent but this feature was not fulfilled ever since the Omada Controller was published.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:SG2008P Port Security
2025-02-24 04:31:22

  @Clive_A Thanks for the quick replies.

  1  
  1  
#5
Options
Re:SG2008P Port Security
2025-02-24 08:49:50

Hi @someguy1234 

Thanks for posting in our business forum.

someguy1234 wrote

  @Clive_A Thanks for the quick replies.

Noticed someone suggested MAC address learning on Reddit. Will that work for you? MAC learning might be an alternative to doing what you want.

Set the MAC-learned address count to 1 and connect your AP to it. It should only allow this single device to get the Internet.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#6
Options
Re:SG2008P Port Security
2025-02-24 13:22:59 - last edited 2025-03-04 20:26:12

  @someguy1234 

 

 

you can look at this link, i used it for a while but then it stopped working at some point and i haven't gotten it to work again, but it's possible i did something wrong somewhere. i haven't spent much time on it.
what is not stated in this link is that you have to set 802.1X Control to auto on the switch port otherwise all devices will connect.

nice if you test and give feedback, for me it doesn't work anymore,

 

https://community.tp-link.com/en/business/forum/topic/714314

  0  
  0  
#7
Options
Re:SG2008P Port Security
2025-02-24 13:47:01 - last edited 2025-02-24 14:25:11

  @someguy1234 

 

I hadn't double-clicked the port, but now it works again

 

 

  0  
  0  
#8
Options
Re:SG2008P Port Security-Solution
2025-03-04 19:20:27 - last edited 2025-03-04 20:31:44

Amazing this is still not possible.

 

In 2022 this was already indicated as an inssue and it would be forwardedn to the R&D appartment.

 

Now it's 2025 and it is still not possible to do this in the controller interface.....

Recommended Solution
  1  
  1  
#9
Options
Re:SG2008P Port Security
2025-03-04 19:31:28

  @MarcelvE haha yeah. I saw that discussion but couldn't believe it was still an issue. What does RnD do all day?

  0  
  0  
#10
Options
Re:SG2008P Port Security
2025-03-04 19:58:50 - last edited 2025-03-04 20:36:12

  @MR.S That method sort of worked. The authentication on the port worked and in testing unauthorized devices were blocked just like I wanted. But the switch would drop off the network after a bit. Logs said something about the uplink port being blocked. And even though testing showed it was functioning correctly, the port that was set for RADIUS authentication would be apparently randomly be blocked too. Ping tests would randomly fail. Rebooting the switch would fix it until a few minutes later when it would happen again. Very weird. Disabiling the whole RADIUS port auth fixed these random issues.

  0  
  0  
#11
Options