Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    When OPT port set VLAN tag 200, but nontag laptop RJ-45 plug-in to OPT port will obtain IP from SG-1100 DHCP server.

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    4 Posts 2 Posters 618 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jacy
      last edited by

      I have a question on VLAN setting,
      I set SG-1100 OPT port to VLAN tag 200 and enable DHCP server on OPT port, When I use nonTag laptop RJ-45 plug-in to
      OPT port, It will obtain IP from SG-1100, If I want to drop nonTag traffic, How can I do it,
      Thanks.

      SG-1100 firmware version: 21.02.2

      Topology:

      SG-1100 <----OPT ethernet----> nonTag (laptop) 192.168.2.100

      Procedure:

      1. Enable OPT port and set IP address to 192.168.2.1/24
      2. Enable OPT DHCP server. (Start: 192.168.2.100 to: 192.168.2.200)
      3. Set OPT port to VLAN 200.
      4. Add firewall pass IPv4+IPv6 TCP/UDP source OPT net.

      ethernet setting:
      VLAN_setting.png

      wireshark capture packets:
      packets for nontag_to_VLAN_200.pcapng

      1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by

        You have to configure the laptop to use that VLAN. If it can't be configured for a VLAN then you'll either have to not use a VLAN for that or get a cheap managed switch (avoid TP-Link) to convert between tagged and untagged.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        J 1 Reply Last reply Reply Quote 0
        • J
          jacy @JKnott
          last edited by

          @jknott Thanks for your reply, May I know SG-1100 filter rule can drop nonTag packets ?

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @jacy
            last edited by

            @jacy

            There is no such rule. VLANs are at L2 and the filters work at L3. What you do is configure the interfaces with VLANs when you need them. For example I have VLAN3 enabled on my LAN interface to support my guest WiFi. Also, my understanding is the Netgate gear does something different with VLANs. I haven't worked with Netgate equipment, so I can't help with that.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.