Setup FRITZBox (Gateway) and TP-Link Omada Devices OC200, EAP610, TL-SG2428P JetStream
Hello, everyone,
I would like to give you feedback on how I performed my setup with a FRITZ!Box 7590 as a gateway/router and TP-Link Omada Devices OC200, EAP610, TL-SG2428P JetStream. Please also give me feedback if I forgot security-related settings or could do the setup differently.
The FRITZ!Box is only used for VPN connections between FB and FB, as well as for telephoning / DECT and the WIFI of the FRITZ!Box is switched off.
First of all, everyone must know that the FRITZ!Box cannot handle VLANs and therefore the TP-Link system VLAN (1 LAN) must not be changed!
(Theoretically, with this setup, you could also use a different router that also doesn't handle VLANs)
However, so that the FRITZ!Box can do something with the different networks, routing tables must be created on the FRITZ!Box.
In this setup, the FRITZ!Box only recognizes the TL-SG2428P JetStream switch
and Omada Controller OC200, both in the VLAN (1 LAN).
The EAPs are directly connected to the TL-SG2428P switch in the VLAN (15 MGMGT)
and are therefore in a different network than the switch and the controller VLAN (1 LAN).
The three EAP610 receive their IP from the TP-Link switch TL-SG2428P through the
internal VLAN interface and DHCP server and therefore the FRITZ!Box does not know them either.
However, so that the Omada controller can find and configure the EAPs in the other VLAN,
the IP address of the Omada controller must be entered on the switch for Interface VLAN (15 MGMT) under "DHCP option 138".
I hope.
With this setup, the internal data traffic (clients, NAS, IOT,...) is completely handled by the TL-SG2428P JetStream switch.
The FRITZ!Box is only required for the Internet.
The two VLANS/Networks 50 Guest and 60 Work are completely isolated and can only access the Internet. ACL rules must be created for this.