Best way to configure Netgear RAXE290 behind Firewalla Gold

Comments

8 comments

  • Avatar
    Michael Bierman

    I think you probably want the Netgear in AP mode behind FWG in Router mode, something like this. 

     

    See https://help.firewalla.com/hc/en-us/articles/4411167832851-Firewalla-Router-Mode-Configuration-Guide-

    0
    Comment actions Permalink
  • Avatar
    rj834

    I have it that way now, but I lose all the advanced settings, so I can't define separate VLANs.  I guess If I could have visibility into how Netgear is identifying the guest VLAN internally, I could at least define that in the Fireewalla and be good to go.  I don't recall how we identified the VLAN ID of the Apple Airport.  It's been so long, but I'm thinking it was command line or a separate tool!

     

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    Most gear is not like the airport. Airport, like a lot of Apple stuff, hides complexity and detail (like the fact it uses VLANs) from users. N

    This article covers the basic setup for VLAN with Firewalla.  https://help.firewalla.com/hc/en-us/articles/4408644783123-Building-Network-Segments

    Looking at the manual for that Netgear, it is a little odd. It talks about VLANs but only in a particular context of VLANs for things like streaming TV from your ISP and doesn't say if they work in AP mode. It does not say it supports 802.1Q which is the standard VLAN spec. You may need to confirm with them that you have VLAN capability when in AP mode. I think it should work, but I have not tried VLANs on that netgear. etgear may not be using VLANs for guest networks. Often that isn't how Guest networks are created. 

    0
    Comment actions Permalink
  • Avatar
    rj834

    Yeah, that’s where I’m stuck. Most of the Netgear capabilities are disabled in AP mode, so I’m not sure where to go with it. Apple did hide the VLAN, but it worked like a charm with the Firewalla rule created. Seems odd a powerful unit like the Netgear is I can’t get it to hand off the guests to an alternate VLAN in AP mode.  It will isolate the two in router mode, but then it won’t work with the Firewalla. 

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    I would check with NETGEAR experts (maybe on Reddit or NETGEAR directly It is possible that this NETGEAR can’t do the job, but I’m not yet convinced it is impossible.

    0
    Comment actions Permalink
  • Avatar
    rj834

    I have a ticket open with them, but with Apple, it was Firewalla who helped figure it out.

    0
    Comment actions Permalink
  • Avatar
    rj834

    Was on the phone wit Netgear for over two hours. No such capability with the $400 router/AP. They did try to sell me an extended warranty and premium support though! Needless to say, it’s going back.

    0
    Comment actions Permalink
  • Avatar
    Michael Bierman

    Yikes! Sorry it didn't work out. I'll add to my list of devices not to recommend. Curious what are you going to replace with?

    0
    Comment actions Permalink

Please sign in to leave a comment.