VLN Limit: Max of 8

MikeForshock
MikeForshock Posts: 40  Freshman Member
Third Anniversary 10 Comments Friend Collector

Have run into a situation where we are limited on VLAN count. By default the USG FLEX 100 will only allow 8 VLAN networks to be created.

We have now maxed that out and need to create more. Using in a router-on-a-stick type situation to segregate network segments/zones on a managed switch.

Is there a reason it is hardcoded to stop at 8?
Is there a fix or another path we can go to avoid this?

Accepted Solution

  • PeterUK
    PeterUK Posts: 3,152  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    Answer ✓

    Limited so you have to buy a bigger Zywall page 1202

    https://download.zyxel.com/USG_FLEX_100/user_guide/USG%20FLEX%20100_V5.36_Ed1.pdf

All Replies

  • PeterUK
    PeterUK Posts: 3,152  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    Answer ✓

    Limited so you have to buy a bigger Zywall page 1202

    https://download.zyxel.com/USG_FLEX_100/user_guide/USG%20FLEX%20100_V5.36_Ed1.pdf

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,370  Zyxel Employee
    Sixth Anniversary 1000 Comments 100 Answers Zyxel Certified Sales Associate

    Hi @MikeForshock,

    If you need to create more VLAN interfaces, USG FLEX 200 and USG FLEX 500 are recommended.
    Max. number of VLAN interface
    USG FLEX 200: 16
    USG FLEX 500: 64

    Best regards,
    Emily

    Don't miss this great chance to upgrade your Nebula org. For free! https://bit.ly/4g2pS9L

  • MikeForshock
    MikeForshock Posts: 40  Freshman Member
    Third Anniversary 10 Comments Friend Collector

    Thanks for the very precise answer.

    Disappointing, will have to go another direction on this. Even the 100 is underutilized in this deployment, so anything larger is more waste.

  • PeterUK
    PeterUK Posts: 3,152  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    Why you need so many VLAN's?

  • MikeForshock
    MikeForshock Posts: 40  Freshman Member
    Third Anniversary 10 Comments Friend Collector

    Critical Infrastructure projects, so is very, very zero trust as the buzzwords go.

    We segment the network heavily and use the firewall to assign allowed inter vlan networking. Was attempting to use the USG as a central firewall/router (router on a stick, non-routed network) versus multiple, separately managed units. We use it for minimal operator/user devices (2-3 terminals, viewing stations) so the USG FLEX is doing very, very little work overall currently. Even a USG20/FLEX 50 was doing just fine, but it does not have the various security functions offered by the 100 or higher.

    Each location/site may have as many zones/vlans/subnets (Controls, Security, Corporate Data, IoT/Data, Guest/BYOD, Backhaul Radio/Network). Some locations have as many as 100 sites (most without Guest type networks).

Security Highlight