Management VLAN Access

Management VLAN Access

Management VLAN Access
Management VLAN Access
2025-06-03 21:30:17 - last edited 2025-06-05 00:41:14
Model: TL-SG2008  
Hardware Version: V4
Firmware Version: 4.20.0 Build 20230818 Rel.72032

I am trying to set up a management vlan in standalone mode on several new SG2008 switches. On each switch I have configured a new vlan (50) and also created another interface under L3 features with an address in the 192.168.50.0/24 network. My router is a third party router (Synology) which is a good vlan router. The problem I am having is when I try to access the switch via the management IP address from my primary vlan on a different subnet. I can see the router's firewall rules that allow the needed inter-vlan routing are incrementing the hit count so the problem is not with the router but with the switch, If I try to access the switch with a laptop connected to the same management vlan, there is no problem. It appears the switch is not accepting packets from a different subnet. Am I missing something here?  For example, in my EAP610, there is an option for L3 accessibility but there is no such option in the SG2008.

 

Any guidance would be most appreciated.

 

1x ER706W 1x OC300 4x SG2008 1x EAP610 2x EAP650
  0      
  0      
#1
Options
1 Accepted Solution
Re:Management VLAN Access-Solution
2025-06-05 08:24:07 - last edited 2025-06-05 08:29:08

  @Clive_A 

 

I have solved the issue!  Here is what needs to be done in case someone else runs into the same problem.

 

1. Ensure the only interface is the management vlan interface.  In this case the switch has an IP address of 192.168.50.7.

 

 

2. As the switch has no default gateway, create a static route to the other network.  The Next Hop should be the router's IP address on the management vlan.

 

 

3. Ensure the new static route appears in the routing table.

 

 

4. Click Save to save the changes..

 

I can now access the switch from the primary vlan.  The original problem was due to the switch not knowing where to send its response packets as they needed to be routed outside of the management vlan.

 

1x ER706W 1x OC300 4x SG2008 1x EAP610 2x EAP650
Recommended Solution
  0  
  0  
#6
Options
6 Reply
Re:Management VLAN Access
2025-06-04 05:37:55
  0  
  0  
#2
Options
Re:Management VLAN Access
2025-06-04 09:06:38

  @Clive_A 

 

The link you provided did not help. Let's see if I can explain this a little better so that you understand what I am trying to do. I have a primary network and a management network configured on the router.  The primary network has a subnet of 192.168.10.0/24 and is an untagged vlan.  The management network has a subnet of 192.168.50.0/24 and has a vlan tag of 50.  In the GUI of the SG2008, there are two interfaces configured as shown below:

 

 

With a PC on the primary network, I can not access the switch on the management vlan even though the routing is configured properly in the router.  The routing is correct because I can access an EAP610 configured in the same management network with no problems.  With the PC, I can also ping the switch with no problems.  It is the web GUI of the switch that does not respond.  The problem is the same with OR without an ACL.  I have tried an ACL with just the management network and later an ACL that includes both interfaces.  Neither work.

 

If I use the same PC, but now connected only to the management network, I can access the switch OK on its management interface.

 

The end goal here is to leave the PC hardwired to the primary network with the capability to access devices on the management network.  As I stated before, it works OK when accessing the EAP610 so there is something with the switch that prevents establishing a connection.  Any ideas?

 

 

  

1x ER706W 1x OC300 4x SG2008 1x EAP610 2x EAP650
  0  
  0  
#3
Options
Re:Management VLAN Access
2025-06-04 09:22:19 - last edited 2025-06-05 08:24:36

  @jra11500 

There is no Omada-alike Management VLAN in standalone mode. The only way to do the "Management VLAN" in standalone mode is like that guide I offered.

And the switch does not have "L3 Accessibility" like the EAP.

  0  
  0  
#4
Options
Re:Management VLAN Access
2025-06-04 09:30:24

  @Clive_A 

 

Thank-you for responding.  Perhaps the adding of a management vlan in standalone mode along with L3 accessibility should be considered as feature requests and be incorporated in future firmware updates.  Thanks again! 

1x ER706W 1x OC300 4x SG2008 1x EAP610 2x EAP650
  0  
  0  
#5
Options
Re:Management VLAN Access-Solution
2025-06-05 08:24:07 - last edited 2025-06-05 08:29:08

  @Clive_A 

 

I have solved the issue!  Here is what needs to be done in case someone else runs into the same problem.

 

1. Ensure the only interface is the management vlan interface.  In this case the switch has an IP address of 192.168.50.7.

 

 

2. As the switch has no default gateway, create a static route to the other network.  The Next Hop should be the router's IP address on the management vlan.

 

 

3. Ensure the new static route appears in the routing table.

 

 

4. Click Save to save the changes..

 

I can now access the switch from the primary vlan.  The original problem was due to the switch not knowing where to send its response packets as they needed to be routed outside of the management vlan.

 

1x ER706W 1x OC300 4x SG2008 1x EAP610 2x EAP650
Recommended Solution
  0  
  0  
#6
Options
Re:Management VLAN Access
2025-06-05 09:05:18

  @jra11500 

That looks like a case from the FAQ ID 887, where you need to set up the static routing. Which was explained in the VLAN Interface config guide.

  0  
  0  
#7
Options