@UnWired
Thanks for taking the time to respond and provide information.
As it turns out, the design IS correct, but there was an additional wrinkle that came to light after posting the original question.
The test case is to support Netgear WiFi6 Orbi mesh systems under this specific set of conditions:
- The Orbi router needs to be in a remote location from the wiring patch panel and ISP connection.
- One or more Orbi satellites need to be connected to the router with a 'wired' (Ethernet) connection.
- The Orbi system must need the Guest WiFi network enabled.
Guest WiFi is the key. Netgear engineered the WiFi6 Orbi products to use VLAN 4093 for communication between the router and satellites for anything related to Guest WiFi. Other traffic is ordinaty untagged frames. Thus, the design has to add VLAN 4093 on any managed switch port connecting the Orbi router LAN port, Orbi satellite LAN port, and the trunk ports connecting the two switches. (If only physical cable or unmanaged Ethernet switches connect the router and satellites, then both untagged and "tagged" frames pass directly to/from router and satellite. It is the need to run both WAN and LAN traffic over a single Ethernet cable that causes the problem.
I have tested the new configuration using both Netgear and TP-Link managed switches. It was a bit of a "oh, my" moment that the advanced 802.1Q VLAN configuration allows a port to be set up as both
- Untagged for one VLAN, and
- "Tagged" for VLAN 4093 (or others).
The "A" solution remains: install a second Ethernet cable between the patch panel location and the router location. However, for many of us, installation of such a cable would be many times the cost of the cable itself. A pair of managed switches can be considerably less costly. (Even less costly with TP-Link switches than with Netgear.)