Interface vs. VLAN - a bit confused?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Interface vs. VLAN - a bit confused?

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Interface vs. VLAN - a bit confused?
Interface vs. VLAN - a bit confused?
2021-07-18 00:57:48
Model: ER605 (TL-R605)  
Hardware Version:
Firmware Version:

First let me explain what I'd like to do:

 

I'd like to have a management VLAN that cannot connect to the router to go out to the internet. Simple as that. Its only available externally and ideally through a wireless VLAN only so I can just jump on it from any of my wireless devices. (Hidden, of course.)

 

I go into Wired Networks>LAN and click on "Create New LAN" and have the choice of "Interface" vs. "VLAN" - and VLAN gives me far fewer options (no DHCP server, no interface to presumably route through, domain name, etc.)

 

I'm assuming this simply means that a VLAN is not routable externally (which is perfect for a management VLAN) but that I'd obviously have to provide a DHCP server for that VLAN (not a big deal, I can do that.) 

 

I did look through the documentation for the OC200 as well as do a search on here, but of course I get all kinds of confusing results in a search, and nothing comes up in the OC200 documentation explaining the difference. If someone could point me to some documentation explaining the difference that would be awesome too.

 

 

  0      
  0      
#1
Options
2 Reply
Re:Interface vs. VLAN - a bit confused?
2021-07-22 08:12:42

@Ken73 

The VLAN is based on the 802.1Q VLAN, to achieve network isolation, but currently the controller cannot set up the PVID, so in fact this option is not useful at this moment.

 

The Interface can provide more options such as set up DHCP range, and devices in different IP range can communicate with each other. To set up the isolation, currently only the ACL can do that.

 

The TP-Link website has instruction about how to set up VLAN interface and also using ACL to block the devices.

https://www.tp-link.com/us/support/faq/3091/

  3  
  3  
#2
Options
Re:Interface vs. VLAN - a bit confused?
2021-07-22 22:54:48

@John1234 John, thanks so much - I think this somewhat clarifies it for me. I need to avoid using just a "VLAN" though I had hoped to use it for non-routable networks within my environment (i.e. keeping camera traffic separated from the rest of my network) by tagging ports and SSID's with that particular VLAN. From what you're saying that doesn't work currently? I'm fine with using the same network for the management network, though its not ideal from a security standpoint. Primarily I'm going to try (!!) to keep things simple while still aiming to improve my security posture. Again, thank you for the reply!

  0  
  0  
#3
Options