VLAN tagging issue

Comments

7 comments

  • Avatar
    Firewalla

    Make sure you configure a default interface on the port you configure the DDWRT, this is just a network with no VLAN ID. Then make sure your DDWRT port is configured to be tagged port.  If anything is broken, use ping and look at DHCP and see if your devices are getting IP addresses

    0
    Comment actions Permalink
  • Avatar
    Travis

    Thank you for the reply. I did purposely leave the untagged network out of my firewalla config because I don't want anything going though the network untagged and I want everything sequestered to a specific vlan easier to control rogue devices.

    But like I said this config had been solid for months and all the sudden firewalla stopped responding to the tags. Since I don't have ddwrt auto updating I have to assume it was on the firewalla side.

    I was not able to get a dhcp lease on any of my tagged networks (the firewalla is responsible for dealing out ips). Even setting static addresses the traffic was not being allowed to flow though the firewalla. I also added an untagged network to see if the tagged networks would fail down to it (I'm happy this did not work because it shouldn't)

    It was a very strange issue that took me a little too long to figure out. I only figured it out by accident after I reset the fjrewalla and was assigned a 10.x ip for about 30 seconds while my networks were being restored. After the networks restored I was unable to get ip addresses again. 

    Unfortunately I did not get time tonight to troubleshoot further to see if the problem still exists but I will update when I have more information. As of right now my primary devices are flowing though an untagged network just so I could get back online. I was just kind of throwing it out there because I know you guys are updating preparing for purple and I didn't know if some code got out in the beta channel that may have been causing this. I know the risks I take being in beta but the new features for me outweigh the risks lol this is only a way over configured home network.

    0
    Comment actions Permalink
  • Avatar
    Yas

    @Firewalla i am having the same issue with very similar setup as Travis. Any idea how this could be resolved?
    My main network is on 192.168.×.×/24
    My vlan is on 10.100.×.×/24
    @Travis, were you able to make it work? If so,how?
    Thank you very much in advance

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    What is your switch? Have you done the relevant configuration on the switch? The most common issue we encounter is not treating the port connecting to firewalla as "tagged" port, and the other problem is more related to some of the configurations on the switch side. (PVID for example)

    0
    Comment actions Permalink
  • Avatar
    Yas

    I have a Tp-link TL-SG108E with vlan support. The connection from firewalla purple comes to port1 on the switch and goes to access point (eap650) on port 4.
    Vlan id:1 , vlan name: Default , member ports:1-8 , tagged ports: , untagged ports: 1-8
    Vlan id:180 , vlan name: vlan180 , member ports:1-6 , tagged ports: 1-4 , untagged ports: 5-6
    Vlan id:190 , vlan name: vlan190 , member ports:1-4,7-8 , tagged ports: 1-4 , untagged ports: 7-8
    PVID:
    Port1, port 2, port3, port4 :1
    Port 5, port6: 180
    Port7, port8: 190

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Can you ping devices when you are on the tagged ports? or the problem is with the untagged ports?

    Since your VLAN is a bit complex, my suggestion is start with just one VLAN and go from there. 

    0
    Comment actions Permalink
  • Avatar
    Yas

    Now, all works fine after allowing dhcp for the vlan dhcp servers through the intermediary bridge firewall, between my firewalla purple and the switch/AP. Thank you very much

    0
    Comment actions Permalink

Please sign in to leave a comment.