Omada VLAN Network without Default Interface not working?

Omada VLAN Network without Default Interface not working?

Omada VLAN Network without Default Interface not working?
Omada VLAN Network without Default Interface not working?
Yesterday
Model: SG2210P  
Hardware Version: V5
Firmware Version:

Hi to all,

 

recently I moved for my homelab to omada devices / management.

 

But I have one one crucial question.

 

I´ve following setup:

pfsense as Firewall Gateway

SG2210P

EAP650

 

Pfsense knows following VLANs (default (1), MGMT (10), TRUSTED (20), IOT (91) and GUEST (92)) - All of them exempt Default are VLANs and not Interfaces. In this is right according to the docu when a "non omada gateway is used".

So far so good. At the end I manage do change the MGMT VLAN (which is not an esy task, avoid loosing connectivity) - but thats not the issue, at least any more wink

 

Port setup:

I´ve used only switch Profiles, like them, even if I have an easy setup.

Port config on SG2210P

Port 1 - TRUSTED (Native network: TRUSTED (20), Tagged Networks (none), Untagged Neworks: TRUSTED (20)) - Result: Works fine. Computer gets an IP from the 20er network and has connectivity.

Port 2 - IOT (Native network: IOT (91), Tagged Networks (none), Untagged  Networks: IOT (91) - Result: all good

Now the strange thing starts.

Port 3 - SWITCH (Native network: MGMT (20), Tagged Networks: TRUSTED (20), IOT (91) and GUEST (92), Untagged Networks: MGMT (20) - Result not working. To Port 3 I have attached the EAP650. EAP650 knows only VLAN, all the traffic has VLAN tags for all Wifi Networks and VLAN 20 set as MGMT. When I activate the SWITCH profile, I lose Hearbeat in omada and the EAP remains stuck in Adopting. I can fix this by changing the SWITCH profile to: (Native network: Default (1), Tagged Networks: TRUSTED (20), IOT (91), GUEST (92), MGMT (20), Untagged Networks: Default (20)

 

Same happens with the Trunk port (which profle is identical to SWITCH, it just has another name for better understanding).

Also the TRUNK port needs to be on default network "Default (1)" and all other VLANS needs to be Tagged.

 

I don´t get it. Why does it work for a "single VLAN Port" without the Default Network but not wor a Trunk port?

Thank you.

 

 

 

  0      
  0      
#1
Options
5 Reply
Re:Omada VLAN Network without Default Interface not working?
Yesterday - last edited Yesterday

  @Frosch1482 

 

You need to edit and clarify your post.  You state that the MGMT VLAN ID is 10 and later you state that it is 20.  It's confusing.

 

1x ER7406 1x OC300 4x SG2008 1x EAP610 3x EAP650-Desktop
  0  
  0  
#2
Options
Re:Omada VLAN Network without Default Interface not working?
Yesterday - last edited Yesterday

cannot fix it, don´t know why. When I edit the post it wants to create a new one and blocks me. Anyhow here the corrected text. it was just copy past mistakes. Port setup: I´ve used only switch Profiles, like them, even if I have an easy setup.

 

Port config on SG2210P

Port 1 - TRUSTED (Native network: TRUSTED (20), Tagged Networks (none), Untagged Neworks: TRUSTED (20)) - Result: Works fine. Computer gets an IP from the 20er network and has connectivity. Port 2 - IOT (Native network: IOT (91), Tagged Networks (none), Untagged  Networks: IOT (91) - Result: all good Now the strange thing starts.

 

Port 3 - SWITCH

Native network: MGMT (10), Tagged Networks: 

TRUSTED (20), IOT (91) and GUEST (92),

Untagged Networks: MGMT (10)

Result not working. To Port 3 I have attached the EAP650. EAP650 knows only VLAN, all the traffic has VLAN tags for all Wifi Networks and VLAN 10 set as MGMT. When I activate the SWITCH profile, I lose Hearbeat in omada and the EAP remains stuck in Adopting.

 

I can fix this by changing the SWITCH profile to: 

Native network: Default (1),

Tagged Networks: TRUSTED (20), IOT (91), GUEST (92), MGMT (10), 

Untagged Networks: Default (1)

Why do I need to use the Default (1) Vlan ot make things work?

  0  
  0  
#3
Options
Re:Omada VLAN Network without Default Interface not working?
Yesterday - last edited Yesterday

Frosch1482 wrote

Port 3 - SWITCH

Native network: MGMT (10), Tagged Networks: 

TRUSTED (20), IOT (91) and GUEST (92),

Untagged Networks: MGMT (10)

Result not working. To Port 3 I have attached the EAP650. EAP650 knows only VLAN, all the traffic has VLAN tags for all Wifi Networks and VLAN 10 set as MGMT. When I activate the SWITCH profile, I lose Hearbeat in omada and the EAP remains stuck in Adopting.

 

I can fix this by changing the SWITCH profile to: 

Native network: Default (1),

Tagged Networks: TRUSTED (20), IOT (91), GUEST (92), MGMT (10), 

Untagged Networks: Default (1)

Why do I need to use the Default (1) Vlan ot make things work?

  @Frosch1482 

 

If your Port 3 on the switch uses the MGMT VLAN (10) for the native network, then the EAP650 should have its management VLAN setting set to Default and not to Custom. If the setting is set to Custom and VLAN 10 is selected, then the EAP650 expects to see tags on the VLAN (10) traffic.

 

1x ER7406 1x OC300 4x SG2008 1x EAP610 3x EAP650-Desktop
  0  
  0  
#4
Options
Re:Omada VLAN Network without Default Interface not working?
23 hours ago

That is one of the questions.

 

PORT 3 is basically the "Trunk port for the EAP".
1) I need to guarantee that the EAP gets an IP from DHCP from the MGMT VLAN.
2) The PORT 3 needs to route traffic from all VLAN (even MGMT because I´m lazy and administrate from the couch).
 

My personal sens of logic told me: Put PORT 3 in MGMT native net, therefore you´ll get an MGMT ip for sure for all attached network devices. the rest is tagged traffic comming form the network devices (EAP) or other switches around the house.

 

and here is where I´am stuck somehow. It works but I don´t understand the reason why I need to create a profile using the Default VLAN 1 as network and as untagged VLAN. It would be greate if someone could explain it to me. unfortunatley chatgpt and gemini do provide answers that makes absolutely no sense =). Is there anything else I´m missing how to define a port as trunk port?

 

Thank you

  0  
  0  
#5
Options
Re:Omada VLAN Network without Default Interface not working?
8 hours ago - last edited 7 hours ago

  @Frosch1482 

 

Your personal logic is correct and I do not fully understand why you are having a problem.  In my case, I have an EAP610 instead of an EAP650 and the configurations should be similar if not identical.


First, the switch…  Here is a screenshot of my switch port configuration (Port 2 instead of Port 3) for the port connected to the EAP. For the network tag setting I am using Custom because not all of my VLANs are used in the AP. For you, the Allow All would probably be most appropriate.

 

Now a screenshot of the EAP configuration:

 

Here is a link to an older support article for setting up a management VLAN.  Since the upgrade of the controllers to v6, the configuration steps are not the same but there are some key points to note:
1.  In paragraph 1, the note states “In default mode, only untagged and VLAN 1 frames can communicate with the device.”
2.  In paragraph 2, the note states “When set to a specific VLAN, only packets carrying that VLAN tag can communicate with the EAP.”


Therefore, if your switch port 3 has its native VLAN set to VLAN 10, then the VLAN 10 traffic is untagged and the other VLANs will be tagged.  The EAP should be set to use the default VLAN (in this case, VLAN 10) and it should be receiving an IP address from that VLAN.


I suspect that if you are continuing to have a problem, there may be an underlying issue with VLAN 1 and the other non-Omada devices.  Perhaps a more experienced contributor can shed some light on this.

 

1x ER7406 1x OC300 4x SG2008 1x EAP610 3x EAP650-Desktop
  0  
  0  
#6
Options