TL-SG3452P VLAN Set up problem

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

TL-SG3452P VLAN Set up problem

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
TL-SG3452P VLAN Set up problem
TL-SG3452P VLAN Set up problem
2023-02-14 23:32:31
Model: TL-SG3452P  
Hardware Version:
Firmware Version:

Hi,

 

I'm trying to help a friend out with the set up of this switch. I'm a sofware developer not a comms engineer, but he thinks anyone who works in IT can sort this out!

 

There are several rooms whichare set up as separate L2 802.1Q VLANS. The WAP is set up as VLAN 800, PoE is enabled for this VLAN and disabled for all other VLANs. Internet access is from a router to port 1. Cross VLAN communication is not to be allowed. When I test this set up with internet access in port 1, my PC in port 3 and WAP in port 13 I find that I can ping the WAP and sign into the WAP from my PC. As these are on different VLANs I wasn't expecting to be able to do this. What am I doing wrong?

 

Any help would be much appreciated.

Rob

 

VLAN Config

 

 

Port Config (1st two pages)

 

 

 

 

 

 

 

 

 

  0      
  0      
#1
Options
1 Reply
Re:TL-SG3452P VLAN Set up problem
2023-02-15 07:34:27

  @LittleRob Assuming the clients are getting the correct IPs and the router ACLs are properly blocking interVLAN traffic.  With all ports selected for VLAN 1, that likely means that VLAN 1 is the untagged VLAN for all ports.  This doesn't match the PVID settings so all the clients will see VLAN 1 data.  Start with setting ports that don't need multiple VLANs to have only one and the VLAN untag is set for the matching PVID for the port (aka change trunk ports to access ports).  There should also be only one untagged VLAN on a port.

 

For example, Port 3 has both VLAN 1 and 200, but a PC usually can't make use of multiple VLANs.  So it would be best to set it to only VLAN 200, by removing VLAN 1 membership to Port 3 (uncheck the untag setting of VLAN 1 for Port 3).  Once VLAN 1 is removed from Port 3, VLAN 200 can be set to untagged for Port 3.

 

For the AP, also remove VLAN 1, unless the AP uses VLAN 1 for management, then VLAN 1 will need to be tagged and VLAN 800 untagged and the AP set correctly for a tagged management VLAN.

  0  
  0  
#2
Options