[HELP] Simple VLAN Config

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

[HELP] Simple VLAN Config

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
[HELP] Simple VLAN Config
[HELP] Simple VLAN Config
2020-03-28 06:51:17
Model: EAP245  
Hardware Version: V3
Firmware Version: 2.4.0

Hi - 

 

Very new to VLAN and thought I'd configured everyone correctly but just can't get it to work.

 

In short, I'm attempting to have a seperate WiFI SSID for IoT devices and keep them seperate from the rest of the network.  Trying to protect from hacks into our network from that new fancy coffee maker.  I've gotten stuck at creating the first VLAN...whenever I turn on VLAN on the access point, all the IOT devices can no longer connect to the internet (perhaps because they can't get an IP from the router but that's just a guess)

 

Here's my config (which isn't working):

  • I have EAP-245 access points and have an IOT specific SSID called NAISH_IOT on VLAN 30
  • I have a TL-SG108PE switch and have the EAP-245 access point on physical port 1 and a router (with DHCP) on physical port 8
  • On the switch I have configured two VLANS (so far) - 
    • VLAN 1: Untagged ports 1-8
    • VLAN 30: Tagged port 1, Untagged port 8

 

If I remove all VLAN stuff all the IOT devices connect just fine to the NAISH_IOT SSID and then onwards to the internet.  With all the VLAN stuff configured, as per above, it looks like the IOT devices are attempting to connect to the EAP-245 but ultimately no traffic flows to/from the internet.

 

Again, I'm very new to this stuff and any pointers would greatly be appreciated!

 

  0      
  0      
#1
Options
1 Reply
Re:[HELP] Simple VLAN Config
2020-03-28 09:24:12 - last edited 2020-03-28 09:35:00

@DiscoUnixg, you did set up two networks (VLAN ID 1 and ID 30), but your router on untagged port 8 is either a member of VLAN 1 only (if the port's PVID is 1) or a member of VLAN 30 only (if the port's PVID is 30). This can't work.

 

To use two or more isolated wireless networks your router must support multiple networks and VLAN-tagging.

 

In other words: the switch port to which the router is connected to must be tagged and the router must be able to direct traffic tagged with VLAN ID 30 to a separate network (not the LAN).

 

See this HowTo for implementing a separate network using EAPs. Substitute »Guest Network« with »IoT network« for your use case.

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
  0  
  0  
#2
Options