ER605 not able to assign vlan1 IP range

ER605 not able to assign vlan1 IP range

ER605 not able to assign vlan1 IP range
ER605 not able to assign vlan1 IP range
Monday - last edited 23 hours ago
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.3.1 Build 20251015 Rel.78291

After upgrading to v6.0.0.34 3 days ago, the gateway refuses to assign 15 EAPs and the SG2210P switch to vlan1 192.168.0.0/24. It will only assign the client IPs to 192.168.188.0/24. I really don't know why this is happening. I do not see any other rogue dhcp servers on the same network. so it cannot adopt all the IPs under 192.168.188.xxx.

 

ER605 v2 firmware 2.3.0 on 192.168.0.1

OC200 latest firmware on 192.168.0.3

SG2210P latest firmware on 192.168.188.72

10 out of 15 EAP225 v3-outdoor on 192.168.188.72

5 out of 15 EAP225 v3-outdoor on 192.168.0.xxx

 

I would like to downgrade the back to v5 to try to resolve, but there is no option do this on omada cloud management. I do not have physical access to the network. Its a 2hr plane ride from my home. I have asked someone onsite to reset the SG2210P switch, but it still shows IP 192.168.188.x. How is this possible unless someone onsite plugged in another dhcp server to the network? I have already rebooted all network hardware multiple time.

 

vlan1 is very basic and nothing special. No other vlans are configured. The SG2210P switch is only used for a couple of EAPs and the controller for power, and an downlink to a POE switch for 10 other EAPs and 2 VIGI NVRs. Again nothing special. I have have asked someone to reset the SG2210P and i assume that it was correctly reset becuase the device name was changed to its MAC address. But it's IP address is still 192.168.188.xxx. At this point i'm ready to reset the this gateway.

 

This install is for my 10 room backpacker villa. So nothing special as far as networking requirments. I have a local ISP and starlink as backup. Can someone please assist on next step tshoot?

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER605 not able to assign vlan1 IP range-Solution
Yesterday - last edited 23 hours ago

@NoMadMan, it does appear there's a DHCP service running somewhere.  I'm doubtful that the upgrade itself caused the issue, other than forcing the devices to re-connect.

 

As a sanity check, make sure your 1000% sure there is only the default network and no other networks/VLANs created.  The SG2210P can run DHCP, but shouldn't if it was reset and still using factory settings.  You mentioned some other POE switches in the network, are these all unmanaged?

 

It would be much easier to troubleshoot if your were there (hope the on-site person has some patience and a little technical knowledge).  Anyway, here's a few options... 

 

Plan A (Process of Elimination)

  1. Disconnect everything from the SG2210P except the controller and the ER605
  2. Reset the SG2210P and see if it works as epected
  3. If the SG2210P gets the correct address, add portions of the network back to see when the 192.168.188.0/24 adresses return

 

Plan B (Hunting Expedition)

  1. Plug a laptop to the network and manually set it's IP/Gateway to be in 192.168.188.0/24 network.
  2. Try to connect to the 192.168.188.1 with a browser (assuming that's the offender) to try to figure out what it is.
  3. If that doesn't work, download an IP scanning app and look for anything that's not one of you APs or the SG2210P.
  4. Try connecting/finding that device.
Recommended Solution
  1  
  1  
#5
Options
12 Reply
Re:ER605 not able to assign vlan1 IP range
Monday

Hi @NoMadMan,

 

I think the VIGI NVR's have a DHCP server option, so maybe one is active.  Try unplug both NVRs and reboot the switch to see if the issue goes away.

  1  
  1  
#2
Options
Re:ER605 not able to assign vlan1 IP range
Monday
@D_C Good point! I'll have someone pull both recorder cables from the switch
  1  
  1  
#3
Options
Re:ER605 not able to assign vlan1 IP range
Tuesday - last edited Tuesday

  @D-C I unplugged both NVRs and rebooted the gateway. devices are still defaulting to 192.168.188.xxx. please see screenshots

 

device list Caption

 

clients category Caption

 

  0  
  0  
#4
Options
Re:ER605 not able to assign vlan1 IP range-Solution
Yesterday - last edited 23 hours ago

@NoMadMan, it does appear there's a DHCP service running somewhere.  I'm doubtful that the upgrade itself caused the issue, other than forcing the devices to re-connect.

 

As a sanity check, make sure your 1000% sure there is only the default network and no other networks/VLANs created.  The SG2210P can run DHCP, but shouldn't if it was reset and still using factory settings.  You mentioned some other POE switches in the network, are these all unmanaged?

 

It would be much easier to troubleshoot if your were there (hope the on-site person has some patience and a little technical knowledge).  Anyway, here's a few options... 

 

Plan A (Process of Elimination)

  1. Disconnect everything from the SG2210P except the controller and the ER605
  2. Reset the SG2210P and see if it works as epected
  3. If the SG2210P gets the correct address, add portions of the network back to see when the 192.168.188.0/24 adresses return

 

Plan B (Hunting Expedition)

  1. Plug a laptop to the network and manually set it's IP/Gateway to be in 192.168.188.0/24 network.
  2. Try to connect to the 192.168.188.1 with a browser (assuming that's the offender) to try to figure out what it is.
  3. If that doesn't work, download an IP scanning app and look for anything that's not one of you APs or the SG2210P.
  4. Try connecting/finding that device.
Recommended Solution
  1  
  1  
#5
Options
Re:ER605 not able to assign vlan1 IP range
Yesterday

  @D-C thanks for the feedback!

 

The SG2210P was reset. The device name was set back to its MAC address. But it still manages to aquire the IP 192.168.188.xxx. So it cannot be adopted. There is only VLAN1 set to 192.168.0.1/24. In fact I deleted the original one and created this one just in case. Thanks for recommending pulling the other cables and leaving the controller, gateway, and SG2210P. I will have someone so this in the morning. There is an unmanaged Omada 18-port POE+ switch down stream from the SG2210P. It is used to the distribute EAP225s to the villas spread across the propery.

 

I've booked a flight for Dec 11 before this started. So I guess it will have to wait if there is nothing I can do on remote. Option A is doable and this will be done in the morning. I've asked everyone not to do any banking transactions until the issue is resolved.

 

I suspect:

 

1. someone/staff plugged in an old router (192.168.188.1/24) thinking it's a switch and didn't tell me

2. a guest plugged in their own network gear and is trying to collect data from other guests

  0  
  0  
#6
Options
Re:ER605 not able to assign vlan1 IP range
23 hours ago

  @D-C 

 

Someone thought it was a good idea to plug in a 5G CPE router to the gateway thinking it was plug and play and they could use it as a 3rd ISP option. I hadn't enabled Port3/wan as wan yet so it and the gateway were running DHCP. The CPE router also has an internal battery so no matter how many gateway restarts, all APs and switch would keep the 192.168.188.0/24 IPs. I had them unplug and hide the CPE router in a locked drawer.

  0  
  0  
#7
Options
Re:ER605 not able to assign vlan1 IP range
21 hours ago

  @NoMadMan 

 

As long as all your devices and clients are downstream of the switch, you can prevent this in the future by enabling this option in vlan settings

 

  1  
  1  
#8
Options
Re:ER605 not able to assign vlan1 IP range
16 hours ago

@NoMadMan, Glad it wasn't anything malicious.  @GRL's sugguestion should help in the future.  This will not apply to your unmanaged switch, so someone could unplug an AP and plug in their own device; the scope however should be limited to down stream devices.

 

Other thoughts...

  • Disable ports on managed switches that are not used.  I don't think you can disable router ports, but you could create a vlan that's not used and assign it to the port.
  • Speaking of vlans, consider using them to isolate management, camera, guest, etc. network traffic.
  1  
  1  
#9
Options
Re:ER605 not able to assign vlan1 IP range
16 hours ago

  @NoMadMan 

 

You can disable router ports.  Manage the gateway, ports > untick "Enable" on each unused ports

 

  1  
  1  
#10
Options
Re:ER605 not able to assign vlan1 IP range
14 hours ago - last edited 14 hours ago

Thank you so much for the tips and the assist @GRL & @D-C!

 

I discovered the Legal DHCP Servers option way too late while I was crossing my t's and dotting my i's making sure I didnt make a mistake. I will definately enable that option. I have disabled the unused ports on the gateway and managed switch. I will train the room cleaners to check the villa cables when they clean the villas. I'm always conserned someone can jack in whenever they want thinking they can get faster internet or "whatever".

 

Yes, I will definately apply vlans to guests, admin, POS, and cameras. As well as implimenting vouchers and train the office staff how to add and use them. 

 

Regards!

  0  
  0  
#11
Options