• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

SG2100 and internal switch

Scheduled Pinned Locked Moved Official Netgate® Hardware
9 Posts 3 Posters 1.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    iso667
    last edited by Nov 26, 2020, 3:40 PM

    Hi guys,

    I hope you could help me with the setup of my relatively new SG-2100.

    I want to setup five VLAN's at home network, it could be something like this:

    VLAN5 - Management (also this will be native VLAN)
    VLAN10 - Home Users
    VLAN20 - IoT
    VLAN30 - Guests
    VLAN40 - Servers

    So I've been playing with the internal switch and I've been able to configure two kinds of ports on the SG-2100:

    • Trunk ports, so I have all the VLAN's on this port and also the VLAN5 as "untagged".
    • Access ports, but I need always these ports to be attached to the "native" VLAN.

    What I want to achieve is, for example, to assign port 2 of the switch to VLAN 20, leave port 1 as a trunk port, and leave ports 3 and 4 on the native VLAN.

    My problem is that the SG-2100 has an "especial" or internal port that is port 5. I have to "pass" the traffic through this port to get everything working, and if I change the configuration of this port I lose management of the box.

    My problem comes in here, I have left my VLAN 5 as vlan 1 on the box to not touch a lot the native vlan and also LAN interface.

    4b9383a9-955f-4d45-8325-594229a16c55-image.png

    I configured VLAN's from 10 to 40 correctly, but I have to set the port 5 as "tagged" for these VLANs.

    So if I want to "untag" a VLAN o a port, for example let's say VLAN 20, what do I have to do with port 5? Because this port is already untagged on VLAN 1, and also tagged for the rest of VLAN's for trunks to work.

    I assume that what I want to achieve here is not possible. Or maybe I have to move "all the ports" to this new VLAN and convert this VLAN as my untagged one. Am I right? Anyone able to have "access-ports" on different VLANs in this box?

    BR!

    ISO

    1 Reply Last reply Reply Quote 0
    • I
      iso667
      last edited by Nov 26, 2020, 3:49 PM

      Ok, I'm a bit stupid :) I did this and it worked!

      d09c04dc-eeb1-44ab-9c7d-b1c9eb2d08a0-image.png

      I though I had to "remove" the port number 5 also from the untagged VLAN or configured it as untagged on VLAN 20. But with this small change everything started to work.

      Thanks!

      I can delete the post if you prefer that or leave it here for further reference.

      BR!

      ISO

      1 Reply Last reply Reply Quote 0
      • I
        iso667
        last edited by Nov 26, 2020, 3:57 PM

        No, it is not working :(

        Sorry for the confusion! I have several devices that have a LAN interface and also a WLAN interface, and the device I connected to the SG-2100 was connecting and obtaining its address through WLAN.

        Do you know if it is possible to configure SG-2100 as normal "switch" ports ??

        Thanks!

        ISO

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by Nov 27, 2020, 4:50 PM

          The way you have that configured is correct in the switch on the VLANs tab.

          You would also have to set the PVID on port 2 to 20 on the ports tab. That tags untagged packets arriving on port 2 to VLAN 20.

          As long as VLAN 20 is defined, assigned as an interface and has DHCP running a client connected to port 2 should get an IP there.

          Steve

          1 Reply Last reply Reply Quote 1
          • I
            iso667
            last edited by Nov 27, 2020, 4:56 PM

            Hey Stephen thank you very much for your answer!!!

            I feel like a stupid :D I was looking at this page wondering where to change this...

            84485958-010f-4945-8241-8c3dedc11928-image.png

            Then I realized that if I click on the Port VID field, it is "editable" :D

            a9e5565d-9d2e-4f65-ab60-ee66112c46a5-image.png

            My bad!! I hope it works perfectly now this way :)

            BR!

            ISO

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Nov 27, 2020, 5:18 PM

              Yup, that should do it. Let us know.

              I 1 Reply Last reply Nov 30, 2020, 1:38 PM Reply Quote 1
              • I
                iso667 @stephenw10
                last edited by Nov 30, 2020, 1:38 PM

                @stephenw10 Hi Stephen,

                it is working like a charm :)

                Thank you for your help!!

                1 1 Reply Last reply Jul 17, 2021, 9:00 PM Reply Quote 1
                • 1
                  11_charlie_brown @iso667
                  last edited by Jul 17, 2021, 9:00 PM

                  @iso667 , I am looking at setting up my network in a similar fashion as you have described here. Do you have steps you used to setup this configuration?

                  1 Reply Last reply Reply Quote 0
                  • S
                    stephenw10 Netgate Administrator
                    last edited by Jul 18, 2021, 12:16 PM

                    Beyond the switch config detailed here you only need to create the VLAN interfaces on mvneta1 and apply firewall rules as required.
                    Are you seeing any particular problem?

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received