Untagged ports on gateway
My gateway is managed by software Controller. I have 3 VLANs configured as Interfaces; LAN(Default) [1], Trusted [10] and Untrusted [30] with corresponding unique subnets and DHCP.
I have some devices on my network connected to an unmanaged switch. The switch is then connected to LAN2 on the gateway. LAN2 is configured with PVID 10.
PCs connected to the unmanaged switch connect to the Trusted network just fine - they get an IP on the Trusted subnet, can talk to each other and get internet. But I also have some smart TVs connected to the same switch, they receive DHCP configuration for the Trusted network, but otherwise do not connect to the network or get internet, they do not respond to pings (they do when connected to WiFi via EAP). They show up in the Omada Clients list but with 0 Bytes of traffic both directions.
I've tried various combinations of ports and cables to eliminate any possible faults there. It is simply that the PCs connect fine, the smart TVs don't, even when everything else is the same.
I suspect the issue is that egress traffic from the gateway to devices on the switch is tagged with VLAN 10. And that while the PCs handle the tags ok, the TVs do not. I would have thought that egress raffic for the same VLAN as the PVID would be untagged, but it seems to not be the case (I'm not in a position to confirm this with Wireshark or whatever, it's just the explanation that makes the most sense). If anyone knows this suspicion is wrong, let me know.
But assuming I'm correct, the question is: is it possible to configure a gateway port to untag traffic for a VLAN other than the default network? I know Port Profiles can be used to do this with Omada managed switches, but I'm not currently using one.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Hi @cvxliao
Thanks for posting in our business forum.
cvxliao wrote
@MR.S Thanks for the reply.
So just to confirm, am I correct in saying that this is the expected behavior - setting PVID on a gateway port will not result in traffic for that VLAN being untagged? It's not a misconfiguration on my end or a firmware bug or something, but in fact a limitation of the product?
And that this is not possible to achieve with an Omada gateway device, it requires using a Port Profile with a managed switch?
Incorrect. Setting it WILL result in the VLAN being untagged.
PVID determines what is untagged (traffic).
- Copy Link
- Report Inappropriate Content
it's very limited what you can configure on the router, it's only pvid that's it.. so all vlans lurk in the background and create trouble for some devices.
- Copy Link
- Report Inappropriate Content
@MR.S Thanks for the reply.
So just to confirm, am I correct in saying that this is the expected behavior - setting PVID on a gateway port will not result in traffic for that VLAN being untagged? It's not a misconfiguration on my end or a firmware bug or something, but in fact a limitation of the product?
And that this is not possible to achieve with an Omada gateway device, it requires using a Port Profile with a managed switch?
- Copy Link
- Report Inappropriate Content
Hi @cvxliao
Thanks for posting in our business forum.
cvxliao wrote
@MR.S Thanks for the reply.
So just to confirm, am I correct in saying that this is the expected behavior - setting PVID on a gateway port will not result in traffic for that VLAN being untagged? It's not a misconfiguration on my end or a firmware bug or something, but in fact a limitation of the product?
And that this is not possible to achieve with an Omada gateway device, it requires using a Port Profile with a managed switch?
Incorrect. Setting it WILL result in the VLAN being untagged.
PVID determines what is untagged (traffic).
- Copy Link
- Report Inappropriate Content
Ok. In that case I'm stumped and need more help.
The PVID for the port is set to 10 (Trusted network). Multiple PCs connected to that port work fine. But multiple smart TVs (a mix of Android and Tizen) connected to the same port do not. They get DHCP config and an IP within the Trusted subnet then just don't send/receive any data, and the TV reports no network connection.
Manually entering IP/DNS settings makes no difference. There are no ACLs configured. I've tried reserving an IP address for the TV, it gets assigned the reserved IP but otherwise has the same issue. I've tried bypassing the unmanaged switch and connecting the TV directly to the gateway port.
I'm pretty sure the fact that they work over WiFi rules out any issues with the DHCP configuration in Omada. They get an IP address within the correct VLAN based on the SSID they connect to, and connect to internet.
Any other suggestions on what the issue could be?
These are my VLAN and gateway port configs. Any other info you need to assist, let me know.
- Copy Link
- Report Inappropriate Content
Hi @cvxliao
Thanks for posting in our business forum.
cvxliao wrote
Ok. In that case I'm stumped and need more help.
The PVID for the port is set to 10 (Trusted network). Multiple PCs connected to that port work fine. But multiple smart TVs (a mix of Android and Tizen) connected to the same port do not. They get DHCP config and an IP within the Trusted subnet then just don't send/receive any data, and the TV reports no network connection.
Manually entering IP/DNS settings makes no difference. There are no ACLs configured. I've tried reserving an IP address for the TV, it gets assigned the reserved IP but otherwise has the same issue. I've tried bypassing the unmanaged switch and connecting the TV directly to the gateway port.
I'm pretty sure the fact that they work over WiFi rules out any issues with the DHCP configuration in Omada. They get an IP address within the correct VLAN based on the SSID they connect to, and connect to internet.
Any other suggestions on what the issue could be?
These are my VLAN and gateway port configs. Any other info you need to assist, let me know.
Config does not look like a problem.
Will you work with VLAN 1? Does the default VLAN work properly?
If they work in VLAN 1 but not any other VLAN, it could be a problem with your TV Ethernet.
Will you be able to ping the TV IP it gets from a PC in the same VLAN 10?
Is it Internet-based TV which just needs Internet instead of other IPTV stuff to get it working?
- Copy Link
- Report Inappropriate Content
So I was able to do some more troubleshooting with one of the TVs, and in the process it seems the problem resolved itself.
To answer your questions yes these are normal consumer smart TVs, using connectivity for things like streaming apps, DLNA, remote control via phone etc, nothing exotic. When they connect successfully I can ping them from other devices on the network, even different VLANs.
I tried testing with gateway port LAN4: PVID 10, 30, 1 all worked. By that I mean TV was assigned an IP via DHCP in the respective subnet, and connected to LAN/internet.
So I went back the original port LAN2. PVID 1 did not work - didn't even get an IP assigned. PVID 30 worked. Went to PVID 1 again - DHCP took a minute but eventually it worked. Then went back to PVID 10 - and wouldn't you know it, now it worked. Reconnected the unmanaged switch - all 3 TVs working.
I was prepared to whip out Wireshark and inspect the ethernet frames myself, but turns out it wasn't necessary. The config now is exactly the same as it was before. So beats me what the problem was. My suspicion is that maybe the config in Controller hadn't been correctly deployed to the gateway, and that all the troubleshooting updated it. Don't know if that's a thing. Or maybe some bug in the firmware, who knows. It was doing my head in because it seemed I'd done everything right. But I'm happy to report that it's appears to be working for now, the PVID setting is behaving as you described, which is in line with my expectation.
Thanks for the help!
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 257
Replies: 6
Voters 0
No one has voted for it yet.