ER605 gateway multi VLAN connectivity

ER605 gateway multi VLAN connectivity

ER605 gateway multi VLAN connectivity
ER605 gateway multi VLAN connectivity
3 weeks ago - last edited Friday
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.0 Build 20250428

Hello everyone,
I’m new to Omada SDN systems, and I hope that’s the reason I can’t figure out a problem I’m struggling to interpret.

 

I’ve set up an Omada system consisting of:

  • 1 gateway ER605 v2.0 – firmware 2.3.0 Build 20250428

  • 1 switch SG2210P v5.20 – firmware 5.20.10 Build 20250307 Rel.72554

  • 2 access points EAP615-Wall(EU) v1.0 – firmware 1.5.4 Build 20250515 Rel.67108

 

Everything is managed by the Omada Software Controller version 5.15.24.19.

Currently, all devices are on the default network (which I modified to 192.168.178.x/24). All switch ports currently have the “All” profile (default untagged and all others tagged), and everything works fine (DHCP, routing, etc.).

I decided to add a VLAN for my IoT devices. I followed the official guides and several YouTube tutorials:

  • I created a new “Interface” type network.

  • Assigned 2 out of 3 LAN ports of the gateway to it ( the first one is the uplink to the switch )

  • Then I set one switch port to the explicit “IoT” profile and connected my PC to that port.

I do get an IP address of the "IoT" network, but I can’t ping the gateway (which also acts as the DNS server) from the "IoT" network.
The same happens with the two EAP615 APs — devices can ping each other within the VLAN, but there’s no way to reach the ER605.

I tried rebooting the ER605, but it didn’t help.

 

P.S. If I ping the IoT network gateway (192.168.10.1) from the default network ( 192.168.178.x), it responds (I haven’t configured any firewall or switch policies yet).

 

Does anyone know what could be causing this? or what should I check?

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER605 gateway multi VLAN connectivity-Solution
Friday - last edited Friday

We’d like to clarify a few points:

You mentioned that the two EAP615 APs exhibit the same issue—devices inside the VLAN can ping each other, but they cannot reach the ER605.
Both of your EAP615 APs are on the default LAN. Do you mean:

  1. The two APs themselves can ping each other on the default LAN but cannot ping the ER605, or
  2. Clients connected to the EAP615s can ping each other but those clients cannot ping the ER605?

We need to be sure because we want to know whether the problem exists on both the IoT LAN and the default LAN.

Recommended test:

  1. Connect a test PC directly to the ER605 v2.
  2. Start a packet capture on the default LAN (192.168.178.0/24) and on the newly-created IoT LAN (192.168.10.0/24).
  3. Verify that the PC can reach 192.168.178.1 and 192.168.10.1, and check whether DNS resolution and Internet access work on both subnets.
    If everything works while the PC is wired straight into the ER605, the router itself is most likely functioning correctly.
Recommended Solution
  0  
  0  
#7
Options
6 Reply
Re:ER605 gateway multi VLAN connectivity
3 weeks ago

  @Trevis 

Thanks for your post. You might want to check if the IDS/IPS feature is enabled—go to Settings > Network Security and take a look. By the way, try connecting a PC or phone to the IoT network and see if you can ping the gateway.

  0  
  0  
#2
Options
Re:ER605 gateway multi VLAN connectivity
3 weeks ago - last edited 3 weeks ago

  @Ethan-TP thank you very much for your feedback. I've double checked and no IDS/IPS feature is enabled. The configuration is really basic and, to simplify the problem determination, no extra feature has been enabled out of the standard one.

 

As stated above, a pc on the iot network cannot ping the gateway and cannot query the dns, so logically isolated from Internet. Two PCs on Iot network can reach each other without any problem.

 

Really cannot understand. I've tried to delete and re-create the network but no luck.

  0  
  0  
#3
Options
Re:ER605 gateway multi VLAN connectivity
3 weeks ago

  @Trevis 

 

What ACL rules do you have?

  0  
  0  
#4
Options
Re:ER605 gateway multi VLAN connectivity
3 weeks ago

  @GRL all empty..

 

 

 

 

  0  
  0  
#5
Options
Re:ER605 gateway multi VLAN connectivity
a week ago

  @Trevis 

Thank you so much for taking the time to post the issue on the TP-Link community!

To better assist you, I've created a support ticket via your registered email address and escalated it to our support engineer to look into the issue. The ticket ID is TKID251064801 please check your email box and ensure the support email is well received. Thanks!

Once the issue is addressed or resolved, welcome to update this topic thread with your solution to help others who may encounter the same issue as you did.

Many thanks for your great cooperation and patience!

  0  
  0  
#6
Options
Re:ER605 gateway multi VLAN connectivity-Solution
Friday - last edited Friday

We’d like to clarify a few points:

You mentioned that the two EAP615 APs exhibit the same issue—devices inside the VLAN can ping each other, but they cannot reach the ER605.
Both of your EAP615 APs are on the default LAN. Do you mean:

  1. The two APs themselves can ping each other on the default LAN but cannot ping the ER605, or
  2. Clients connected to the EAP615s can ping each other but those clients cannot ping the ER605?

We need to be sure because we want to know whether the problem exists on both the IoT LAN and the default LAN.

Recommended test:

  1. Connect a test PC directly to the ER605 v2.
  2. Start a packet capture on the default LAN (192.168.178.0/24) and on the newly-created IoT LAN (192.168.10.0/24).
  3. Verify that the PC can reach 192.168.178.1 and 192.168.10.1, and check whether DNS resolution and Internet access work on both subnets.
    If everything works while the PC is wired straight into the ER605, the router itself is most likely functioning correctly.
Recommended Solution
  0  
  0  
#7
Options