TL-SG1016PE - 802.1Q VLAN how to assign one port to multiple VLANs

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

TL-SG1016PE - 802.1Q VLAN how to assign one port to multiple VLANs

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
14 Reply
Re:TL-SG1016PE - 802.1Q VLAN how to assign one port to multiple VLANs
2020-06-27 08:25:52 - last edited 2020-06-27 08:26:59

 

Bongo wrote

Other than looking more modern, the New UI looks less functional than the old UI.  It appears to require more switching between screens.  What was the purpose of the change?

In the old UI, everything for a single vlan was in one place.  I am much more interested in function than form.

 

Agreed. I already pointed this out to TP-Link in this thread: https://community.tp-link.com/en/business/forum/topic/172966

 

In my opinion the new web UI is a big step back in terms of useability. Function is much more important for an admin UI than eye candy or fancy CSS/Javascript. But if the latter is preferred, then strictly avoid fixed sizes and assumptions about screen dimensions. It's really hard to scroll in the new web UI's port list, for example. The browser can better decide whether a scroll bar is needed or not - this always depends on the screen size.

 

Anderson, please see above post from Bongo for more feedback to the new web UI.

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
  1  
  1  
#12
Options
Re:TL-SG1016PE - 802.1Q VLAN how to assign one port to multiple VLANs
2020-06-29 00:09:25

 

mariem56 wrote

Thank you sir. It's different from a Cisco concept of VLAN... So for uplink from the L3SW Edge Switch I can use the Port 1/0/1 of TPlink as the tagged port/ uplink port? Then untagged the port that is connected to PC or printer with static address. Then I would connect my AP with VLAN20(WLAN Corporate) VLAN30(Guest) as tagged port? My problem would be getting two VLANs from 1AP connected to TPlink Switch.

@mariem56 

 

I am more familiar with the way vlans are handled on the EdgeRouters than Mikrotik.

 

The Ubitquiti access points expect the configuration to be done with standard ethernet frames (untagged frames).  After the access point has been adopted by the controller, in recent versions of firmware/controller you can tell it to use a vlan for management, but it is easier to just leave it as is.  I don't think you want WLAN Corporate unless you are using a Unifi router (USG or UDM).  If you are using Edgeswitch or TP-Link, then the unifi controller does not control them.  Instead you want to use "vlan only".  Google corporate vs vlan only unifi to find information about the differences.  As @R1D2 said, if you have questions about Unifi setup, the Ubiquiti Unifi forum would be a better place to get configuration help. 

 

So for trusted home lan and guest wifi (if you have separate subnets/vlans for these your MTK router) you want the link to the UAP to have the trusted home network to be (in Cisco terminology, the Native vlan for the trunk) and the guest to be on a tagged vlan (on the wire).  Or if you want to do it like in a business, you would have a separate management vlan, and use tagged vlans for both SSIDs.  At home I just have trusted and untrusted and do management on the trusted vlan/subnet.

 

Every vendor has different ways of setting up switches.  TP-Link, Cisco, HP, MikroTik, Ubiquiti (has two, unifi is different from edgeswitch). 

 

Since you are familiar with Cisco, to setup a trunk with native vlan on the TP-Link (lets say trunk carrying two vlans 10 and 20 with 10 as the native vlan)

define vlan 10 and for the trunk port add as untagged (the port will send traffic from vlan 10 as untagged on egress from the port)

define vlan 20 and for the trunk port add as tagged (the port will send traffic from vlan 20 as tagged on egress from the port)

For the trunk port set the pvid to 10 (the vlan that the port will classify untagged ingress frames into).

 

The big difference that I noticed with TP-Link compared to Ubiquiti is that you must explicitly specify how frames will be sent (tagged or untagged) in addition to specifying what vlan the port will classify with a standard untagged ethernet frame it receives (the pvid).  It is possible to configure asymmetric vlans, somewhat like cisco private vlans where it is possible to receive untagged frames coming from one vlan and respond to them and have the return frame traverse a different vlan in the switch.  So you define what vlans the port is a member of, and whether the frames sent from the switch port will have an IEEE 802.1Q tag or not.  When the switch port receives an ethernet frame, it has to classify it into a single vlan, or drop it.  If the frame it receives is tagged then as long as the port is a member of the vlan specified by the IEEE 802.1Q tag, then the frame will be classified and forewarded on the vlan.  If tagged and port is not a member, frame is dropped.  If the received frame has no IEEE 802.1Q tag, then the frame is classified as belonging to the vlan specified by the PVID (port vlan id) for the port, and it gets forwarded only to members of that vlan, but normally only a single port where the mac was last seen for unicast frames.

 

There really should be a vlan rosetta stone.

  0  
  0  
#13
Options
Re:TL-SG1016PE - 802.1Q VLAN how to assign one port to multiple VLANs
2020-06-29 00:40:35 - last edited 2020-06-30 08:33:01

 

mariem56 wrote

I have this problem too. I owned a TPlink 2600G-52TS and Unifi EdgeSwitch L3SW and UAPs, My plan is to set a L3SW for routing and create an uplink to TPlink Switch then connect my UAPs there but Creating VLANs is so confusing to me. Why is a VLAN called untagged port?

@mariem56 

 

Here's an example config on the only type of vlan-aware TP-Link switch I own (TL-SG108E v4).

 

 

 

Port 1 and 8 are configured as trunk ports with vlans 10, 20 and 30 with vlan 30 as the "native" untagged vlan (see pvid and that 30 is untagged on those ports), and vlan 10 and 20 tagged.

 

Port 3 is an access port for vlan 20 (only a member of vlan 20, port set as untagged on vlan 20 and pvid for port set to 20.

Port 5 is an access port for vlan 10 (only a member of vlan 10, port set as untagged on vlan 10 and pvid for port set to 30.

Ports 2, 4, 6 and 7 are access ports for vlan 30 (only members of vlan 30, ports set as untagged for vlan 30, and pvid for ports set to 30

vlan 1 can't be deleted, but you can remove it from every port.  But you must have a PVID defined for every port (at least on TL-SG108E)

  1  
  1  
#14
Options
Re:TL-SG1016PE - 802.1Q VLAN how to assign one port to multiple VLANs
2021-12-03 17:59:03

@Bongo 

I tried similar configuration on TL-SG108E, but I get disconnected from network once I remove all the ports from default vlan1. My router connection goes to port1. What should be changed here so that setup works?

 

802.1Q VLAN CONFIGURATION

 

VLAN ID

VLAN NAME

MEMBER PORTS

TAGGED PORTS

UNTAGGED PORTS

COMMENTS

1

 Default

 

 

 

 

100

A

1,2,7

1,7

2

 

200

B

1,3,4,7

1,7

3,4

 

300

C

1,5,6,7

1,7

5,6

 

999

Native

1,7,8

 

1,7,8

Native VLAN

 

802.1Q VLAN PVID Setting

 

Port

PVID

Port 1

999

Port 2

100

Port 3

200

Port 4

200

Port 5

300

Port 6

300

Port 7

999

Port 8

999

  0  
  0  
#15
Options