TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN

TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN

TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN
TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN
Yesterday - last edited 20 hours ago

Hi,

 

I am runing a Mikrotik(MT) router that connects via ether6 to the switch´s ether1.

 

In the MT there a 2 VLANS created:

-BASE-VLAN (pvid=99) > the admin client is here with ip 192.168.0.11

-TEST-VLAN (pvid=100) > a nas is here with ip 192.168.100.40

 

I need to acces from VASE-VLAN 192.168.0.11 to the nas 192.168.100.40.

 

Mikrotiks config for ether6 is Pvid=99 + Frame types=admit all.

 

TL-SG108PE´s config is:

Ether1 Pvid=1 (tagged)

Ether3 Pvid=100 (untagged) > The nas is connected to this port. It does get an ip 192.168.100.40.

Ether7 Pvid=99 (untagged) > The admin is connected to this port. It does get an ip 192.168.0.11.

 

 

Firewall rules are in place in the MT to allow traffic from BASE-VLAN to TEST-VLAN for the admin client (Authorized).

 

This is the LAN MAP:

 

Since I am not a network expert I cannot figure out how to setup the VLANS to allow for admin to communicate to NAS2.

 

My main goal was to isolate all VLANS which has been accomplished. But I need to access the web-admin-page of the nas to work on it.

 

I hope I can get any help on how to set this up so that it works since I think this should be possible to setup.

 

Rgds

 

 

 

 

 

 

 

 

 

  0      
  0      
#1
Options
4 Reply
Re:TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN
Yesterday - last edited 20 hours ago

Hi @ursus34,

 

You need to have VLAN 99 and 100 as tagged members on the MT port 6 and SG108PE port 1.  The untagged member and PVID would be whatever your using for you default VLAN, guessing it's 1, for those ports.  Not sure about the rest of the MT config, but the current VLAN config is problematic.

  0  
  0  
#2
Options
Re:TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN
Yesterday - last edited 20 hours ago

  @D-C 

 

Hi,

 

I have  VLAN 99 and 100 as tagged members on the MT port 6:

/interface bridge vlan
add bridge=BR1 tagged=BR1,ether6 vlan-ids=99
add bridge=BR1 tagged=BR1,ether6 vlan-ids=100

 

Both vlans are also tagged in the switch´s ether1. Ether1 has a pvid or 1.

Then I have marked as untagged vlan99 in ports ether6/7/8 and vlan100 in port ether3.

 

Maybe I misunderstood what you meant but it seems it is as you said, right?

 

 

  0  
  0  
#3
Options
Re:TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN
20 hours ago - last edited 20 hours ago

Hi @ursus34 

Thanks for posting in our business forum.

I don't think you can do it on this switch.

This should be configured as VLAN interface. And if you are using a switch, it should be a switch that's capable of routing.

 

How to Set Up VLAN Interface on the Omada Router

 

And the access to the default gateway is possible. But everything should be based on VLAN interface router and a switch. And configure the IP-Port GW ACL to enable the access. And block the rest of inter-VLAN communication.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#4
Options
Re:TL-SG108PE - setup with 2 VLANS > want admin to be able to ping one of the clients in the other VLAN
8 hours ago

@ursus34, yes the vlan 99/100 traffic needs to flow between the switch and the router. You may have config issues on the MT side too, but I've not used them.

  0  
  0  
#5
Options

Information

Helpful: 0

Views: 62

Replies: 4

Related Articles