• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

VLAN questions

Valentino

n00b
Joined
Dec 8, 2018
Messages
6
Hello ,

I'm a very young student that is learning and reading stuff about networking. It's a bit hard for me because I'm learning english lang too. Sry for bad english

I'm interested in vLan configuration.
I have got a managed switch and I created 2 vlan following this tutorial : https://www.tp-link.com/us/faq-788.html

and this is my configuration
pvid.jpg
vid.jpg

By this desktop I'm on VLAN2 and I'm not able to ping client on VLAN3 and viceversa. It's right.
Everything works , but I have few doubts.

From an other tutorial I can read:
<<
Untagged: a VLAN that is untagged is also sometimes referred to as the "Native VLAN". Any traffic that is sent from a host to a switch port that doesn't have a VLAN ID specified, will be assigned to the untagged VLAN.
>>


1) if there are no tags , How you can garantee it isolates the two client ?


Thanks so much for any help
 
There's basically two ways a port on a switch can act - as a 'trunk' port, belonging to many VLANs, or an 'access' port belonging to one vlan.

In the access port configuration, it's assumed the client attached to the port won't be sending any vlan tags, so the traffic from that client will be assigned to the vlan that the switchport belongs to. In your case above, you've assigned a vlan to a switch port so whatever is plugged in to that switchport will be on that vlan.

In a trunk configuration, typically used for switch to switch traffic but not always, the switch is expecting to see tagged traffic. If it received traffic that is untagged, it will assign that traffic to the 'native' vlan. In a lot of networks, the 'native' vlan for untagged traffic is typically blackholed, i.e. you use a native vlan that doesn't really exist anywhere else, so if someone is trying to send untagged traffic or a device is misconfigured then the traffic won't go anywhere.

It's of course a lot more technical than that, just a 10,000 ft view.
 
There's basically two ways a port on a switch can act - as a 'trunk' port, belonging to many VLANs, or an 'access' port belonging to one vlan.

In the access port configuration, it's assumed the client attached to the port won't be sending any vlan tags, so the traffic from that client will be assigned to the vlan that the switchport belongs to. In your case above, you've assigned a vlan to a switch port so whatever is plugged in to that switchport will be on that vlan.

In a trunk configuration, typically used for switch to switch traffic but not always, the switch is expecting to see tagged traffic. If it received traffic that is untagged, it will assign that traffic to the 'native' vlan. In a lot of networks, the 'native' vlan for untagged traffic is typically blackholed, i.e. you use a native vlan that doesn't really exist anywhere else, so if someone is trying to send untagged traffic or a device is misconfigured then the traffic won't go anywhere.

It's of course a lot more technical than that, just a 10,000 ft view.
"Trunk" is probably the wrong term. "Tagged" is better, and a bit closer to accurate.

Why is "trunk" bad? Because a lot of switches use that term to indicate several physical links combine into a single virtual link ( think: shotgun modems, if you're old enough to remember those ). Not all; HP and Cisco used "trunk" in the way you do, or at least did in the past.

OP: VLANs are pretty easy though; all ports deliver "untagged" packets ( packets with no vlan header attached ). The untagged vlan is the Primary Vlan ID ( PVID ) in the OP's diagram. Some ports can be configured to be vlan ports, which means in addition to their untagged traffic they also get tagged traffic; as many vlans will be delivered to that port as you configure.
 
There's basically two ways a port on a switch can act - as a 'trunk' port, belonging to many VLANs, or an 'access' port belonging to one vlan.

"Trunk" is probably the wrong term. "Tagged" is better, and a bit closer to accurate.

Why is "trunk" bad? Because a lot of switches use that term to indicate several physical links combine into a single virtual link ( think: shotgun modems, if you're old enough to remember those ). Not all; HP and Cisco used "trunk" in the way you do, or at least did in the past.

OP: VLANs are pretty easy though; all ports deliver "untagged" packets ( packets with no vlan header attached ). The untagged vlan is the Primary Vlan ID ( PVID ) in the OP's diagram. Some ports can be configured to be vlan ports, which means in addition to their untagged traffic they also get tagged traffic; as many vlans will be delivered to that port as you configure.

Hello !
Thanks for your long answers.

Reading your answers I understand this:

- Trunk = Tagged
- Access Port = untagged port = Native port

Case A)
If I config switch for untagged port ( or Access Port) then every ports can "host" one vlan only.

Case B)
if I config switch for tagged port ( or Trunk port) then every ports can "host" multiple vlan based on different TAGs.
That is I have different machines on the "same ethernet cable"

************************************************

Case A : goal achieved ( https://www.tp-link.com/us/faq-788.html)

Case B : from https://www.tp-link.com/us/faq-788.html

if port 2 was tagged :

TAGGED.jpg


How Do I wire the second machine on the vLan 2 ? Does I need to use another port ( i.e VLAN 1-2-4) on the switch or I need a second switch ?
Multiple vlan tagged are on the same cable ( save money) so I don't understand how I have to wire them

Thanks
if you need clarification cause my not so good english , pls let me know. Thank
 
There's no reason to do a trunk port (sorry, 'tagged') from the switch to a PC. You'd typically only use it in switch to switch links, or to something like a vm host (hyperv, vmware, etc, that would host VM's on multiple vlans)
 
Hello !
Thanks for your long answers.

Reading your answers I understand this:

- Trunk = Tagged
- Access Port = untagged port = Native port

Case A)
If I config switch for untagged port ( or Access Port) then every ports can "host" one vlan only.

Case B)
if I config switch for tagged port ( or Trunk port) then every ports can "host" multiple vlan based on different TAGs.
That is I have different machines on the "same ethernet cable"

************************************************

Case A : goal achieved ( https://www.tp-link.com/us/faq-788.html)

Case B : from https://www.tp-link.com/us/faq-788.html

if port 2 was tagged :

View attachment 126310

How Do I wire the second machine on the vLan 2 ? Does I need to use another port ( i.e VLAN 1-2-4) on the switch or I need a second switch ?
Multiple vlan tagged are on the same cable ( save money) so I don't understand how I have to wire them

Thanks
if you need clarification cause my not so good english , pls let me know. Thank
Think of VLAN tagging as a per port operation, not switch. Further, in most circumstances every port will have 1 untagged VLAN delivered to it.

Reading through that link, I'm not sure what's going on with tp-link equipment; it seems obvious that they're saying you can have multiple untagged vlans on a single port, but I've only ever seen that on cisco gear ( and even then I think it's a bad idea ). To my knowledge, that's impossible; if you deliver multiple untagged VLANs over a single port, how is the receiving device supposed to understand which is which? It only worked for cisco because the end client device knew to expect that traffic and how to differentiate it ( cisco phones ).

Were I you, I'd try this:

Port 1: PVID 1, Tagged VLANS 2,3
Port 2: PVID 2
Port 3: PVID 3
 
Last edited:
Hello ,

I've thought about my question. I think it's has no sense. You're correct.
So I introduced a new component : The routerEdge X.

from what I understand It should make the traffic tagged and the switch identify it and distribute to clients.
is it correct ? Thanks

EdgeRouter
Based on a video tutorial ,
when we want to create a vlan we also have to create a dhcp server.
Why Cant it use the modem/router dhcp server? maybe it is on other class of ip ?

I ask to many question :whistle: If you have no time to discuss about this new component i want to thanks just the same. Thanks ;)
 
Hello ,

I've thought about my question. I think it's has no sense. You're correct.
So I introduced a new component : The routerEdge X.

from what I understand It should make the traffic tagged and the switch identify it and distribute to clients.
is it correct ? Thanks

EdgeRouter
Based on a video tutorial ,
when we want to create a vlan we also have to create a dhcp server.
Why Cant it use the modem/router dhcp server? maybe it is on other class of ip ?

I ask to many question :whistle: If you have no time to discuss about this new component i want to thanks just the same. Thanks ;)



The high-level VLAN setup of an EdgeRouter is basically the same as your other router/AP and as described previously. Ports can either be access (typically one or a few hosts that don't provide tagged frames themselves and the switch itself has to append that info) or trunk (the sending device (a switch, router, or server) provides tagged frames and the receiving device (another switch/router/server) accepts those.

It's unlikely that the DHCP server of a typical consumer-level router/AP is capable of being configured to support multiple scopes, especially those in different subnets. The EdgeRouter's DHCP server can. Well, you don't have to create a new DHCP config for each VLAN/subnet, technically, but that would mean static addressing (yuck).

Also, if you're using the EdgeRouter it should be replacing the old router/AP at the top of the network (just behind the modem). If you still need it to provide wireless service, be sure to disable all services on the unit (e.g., DHCP, DNS), and connect it to your network via its LAN switch (not the WAN port).

The EdgeRouters are much more capable, flexible devices. If you're looking to learn, it's a much better choice than a consumer-level router/AP.
 
Thank you all, seem to be working ! See below

It's unlikely that the DHCP server of a typical consumer-level router/AP is capable of being configured to support multiple scopes, especially those in different subnets. The EdgeRouter's DHCP server can. Well, you don't have to create a new DHCP config for each VLAN/subnet, technically, but that would mean static addressing (yuck).

Understood , thanks :)
Also, if you're using the EdgeRouter it should be replacing the old router/AP at the top of the network (just behind the modem). If you still need it to provide wireless service, be sure to disable all services on the unit (e.g., DHCP, DNS), and connect it to your network via its LAN switch (not the WAN port).

I'm using a combo ( modem+router). I understand that i have to disable all services on the unit. Ok;)

The EdgeRouters are much more capable, flexible devices. If you're looking to learn, it's a much better choice than a consumer-level router/AP.

yes it's just for learning

if I switch the black cable on port 3 , my desktop gets a different IP( not 10.x.x.x but 192.168.x.x) . So I think that vlan work !

IMG_20181210_001400_commenti.jpg


EdgeRouter Dashboard e DNS
IMG_20181210_000855_commenti.jpg


IMG_20181210_000721_commenti.jpg


My Desktop renew the IP
IMG_20181210_000930_commenti.jpg


Swich Configuration

IMG_20181210_000954.jpg



IMG_20181210_001740.jpg
 
Yep, looks good.

Side note: Does the GUI on that switch make anyone else's head hurt? It just seems convoluted to me. And the fact that it allows a port to be set as untagged for multiple VLANs, yikes.
 
Back
Top