VLAN's on SG-3428 without vlan aware router

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
12

VLAN's on SG-3428 without vlan aware router

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
18 Reply
Re:VLAN's on SG-3428 without vlan aware router
2022-01-12 06:37:07

Dear @surfer1 ,

 

Based on your information, maybe the PVID you set wrong.

 

" I want to accomplish that ports 5,6,7 cannot reach devices on the other ports but can connect to Internet."

This is your needs, we suggest you set the 1,2,3,4,8,9,10 until 24 in vlan 1 and 2, ports 1,2,3,4,8,9,10 until 23 PVID set as 2.

And ports 5,6,7,24 are in vlan 1 and 3, ports 5,6,7 PVID set as 3.

And the port 24 in ALL VLAN 123, PVID set as 1.

 

Please have a try.

 

Best Regards!

 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#12
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-13 17:58:30
Hi Hank, I believe this is also not the solution because i cannot ping the device connected to port 5 and 7 but also not ping a device on the other ports. Lets say i connect the router to port 24, this is the uplink and port 5 & 7 in above config the rest of the ports also just like you are suggeting. When i put a laptop in port1 or 3 and another device in port 5 or 7 i cannot ping it but when i put the device in port 23 or port 4 i still cannot reach that device.... I can only reach all devices on the router or "behind" port 24 when connected to one of the other 23 ports and not the devices on other ports then 24..
  0  
  0  
#13
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-14 06:40:18

Dear @surfer1 ,

 

Of course you can't ping through, they're in different VLANs.

The purpose of setting up VLANs is to separate the two groups so that the devices in each group don't have access to each other, but both have internet access.


Generally speaking, if you find that devices in different VLANs can't ping through to each other, it means that your VLAN has been successfully established.
Doesn't this mean that you have achieved what you said, "I want to accomplish that ports 5,6,7 cannot reach devices on the other ports but can connect to the Internet"?

Please take a look the Example 1: https://www.tp-link.com/support/faq/788/

 

Best Regards!

 

 

 

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#14
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-16 09:38:00
Hi Hank, I have done exactly what you mentioned and after setting the PVID for ports until 23 in PVID 2 the switch was thinking a while and then i loose connection to the switch. The switch has 192.168.0.1 as ipadres and it is not pingable anymore. I have set this ipadres on interface 1 but when i connect a laptop on interface 1 (or on any other interface for that matter) i cannot ping the switch anymore. I have a console cable on tuesday then maybe i can connect to it thru the console and look at the running-config what is wrong, but for now i cannot connect to the main ip of the switch anymore. Strange thing is that every device on the switch is pingable and also the devices on the router which is connected thru port 24 are pingable....
  0  
  0  
#15
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-20 07:40:01

@surfer1

 

So now i can reach the switch again with ipnumber. Hving a look at thru the console port with putty it seemed that all ports i have given PVID 2 exept for ports 5-7 and 24. I think this was the cause that the switch was not accassible thru its ipnumber because it is on interface 1 vlan 1, but am not sure.

I do not know exactly what the PVID does.

 

When putting port 24 in alle 3 vlan;s but with PVID 1 and alle other ports, except 5-7 into vlan 1 and 2 but with PVID 2 and ports 5-7 in vlan 3 and PVID 3, it is not goiing to work. 5 and 7 can then not reach the other ports (thats the intention) but also not on the internet....

 

What role has the PVID setting on a tp-link.

 

On Cisco it does not excist is it the equalivent of Cisco access vlan when not in the trunk vlan?

 

 

  0  
  0  
#17
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-21 04:51:17

Dear @surfer1

 

surfer1 wrote

@surfer1

 

What role has the PVID setting on a tp-link.

On Cisco it does not excist is it the equalivent of Cisco access vlan when not in the trunk vlan?

 

As for PVID, generally each port only has one PVID, if you set port1's PVID is 10, then the data go through this port will be tagged number 10, but in your current network, you only need to set all ports egress rule as untagged, and in my opinion, the cisco's trunk port is similar with this router's tagged port.

 

You can check more articles about VLAN configuration to learn more:

How to configure 802.1Q VLAN on Smart and Managed switches using the new GUI?

How to configure 802.1Q VLAN on TP-Link Easy Smart/Unmanaged Pro Switches?

 

Best Regards!

Best Regards! >> Omada EAP Firmware Trial Available Here << >> Get the Latest Omada SDN Controller Releases Here << *Try filtering posts on each forum by Label of [Early Access]*
  0  
  0  
#18
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-21 10:21:20

@Hank21 

 

Does this mean it cannot work what i want?

  0  
  0  
#19
Options
Re:VLAN's on SG-3428 without vlan aware router
2022-01-22 08:32:06

@surfer1 

 

I will place a new post on this forum with the question if it is possible with the TP-LINK SG-3428 switch to use ACL's for this case. The reason that i am doubting this is that ACL's are based on ingress traffic and not traffic to deny from specific ports.

I have looked at it but when making an ACL and binding the vlan to it where ports 5 and 7 are in then this does not work correct because the mindset is wrong, the mindset is set to egress from ports 5 and 7 and not ingress from router to ports 5 and 7.

 

Is it possible?

  0  
  0  
#20
Options