nebula flex50h change native vlan
Hello,
we want to change the native vlan in our network.
Example config:
I have an LAN interface, let say 192.168.5.254/24
further 2 vlans. one 192.168.150.254/24 vlanid 150 and 192.168.100.254/24 vlandid 100
i want to use the 150 as my native vlan.
so i create an access interface on my switch with pvid 150
and set on the trunk interface between my switch and flex 50h the pvid also on 150.
so when i connect my laptop to the access port on the 150 network, i would expect that i get an ip in the 150 range. but that isn't the case, i get an ip in the 5 range.
can someone explane why this is? off course i can set an other pvid on my trunk lines, but then i have to create again an other vlan with the same purpose. (at the moment i have dhcp etc enabled for testing, at the end i want to make it an dead end.). (no ip adres dhcp etc.)
All Replies
-
by the way, i use the lan network, just for initial configuration of new switches etc so they can connect directly with nebula to retrieve the configuration. normaly i want to disable this lan interface.
0 -
You want to set the port on switch to USG as PVID 1 then set as tag for that port on VLAN150 what should happen is your laptop on the switch as untag for VLAN150 will go out the tag port to USG for the subnet 192.168.150.254/24
0 -
I mean this situation. I would expect the pc get's an ip from vlan 150. But (At least yesterday) wasn't the case, i got an ip from the LAN. So how to handle this. What happens is the untagged package from the pc, is tagged in the switchport with an vlan150 label. Then the switch sends it over the trunk line, (which accepts all vlans (in my case), and there is something going wrong.
when i change the pvid on the trunk line, it's working well. So? must i create multiple dead vlans? 1 for the access ports, and 1 for the trunk lines? I would expect i can use 1 native vlan for both isn't it?
0 -
different ip ranges as the first one, but just for the idea
0 -
Maybe your understanding and thinking is different to my understanding and thinking?
Any VLAN you do on the Flex 50H will be tagged only when you do Interface Type as Ethernet is it native or untagged
0 -
to be honest, my understanding of vlans is not good enough. So i'm here to learn.
there is one thing what i'm wondering about, and maybe you have an answer about that.
When i configure an access port on an switch, with for example pvid 10. Next thing i do is attaching an computer to it. This computer sends untagged frames out, and when it enters the interface, the switch is adding an vlan tag to the frames isn't it?
What happens when an tagged frame is entering this access port? (or what should happen do you think?) What i have read is that tagged frames are disgarded. But with zyxel, when i put an vlanid on my network adapter, i just get an ip addres from that vlan. While adding the vlanid to my network adapter causes the situation that my network adapter is sending tagged frames.
(the disgarding of frames was also mentioned in zyxel documentation, but i cannot find the artical so quickly)
0 -
Im not 100% sure what your seeing maybe because VLAN 1 on your switch is set to all untagged on all ports? I use the Forbidden option for VLAN1 on ports its not needed.
Then you add your VLAN 150 so say port 1 uplink and port 8 PC
port 8 Fixed untagged PVID 150
port 1 Fixed tagged PVID 1
then because ports 1 and 8 are for that VLAN 150 you set on VLAN1 ports 1 and 8 as Forbidden0 -
Hi @Dpj
I assume the switch is running Nebula mode.
Please do not use the PVID 150 on the link that connecting the switch and 50H. Nebula will untagged this VLAN for this port. Once you set access port PVID 150, VLAN 150 is created on this switch. The trunk ports will forward VLAN 150 packets with VLAN tagged.
Zyxel Melen0
Categories
- All Categories
- 438 Beta Program
- 2.7K Nebula
- 188 Nebula Ideas
- 121 Nebula Status and Incidents
- 6.2K Security
- 455 USG FLEX H Series
- 303 Security Ideas
- 1.6K Switch
- 81 Switch Ideas
- 1.3K Wireless
- 44 Wireless Ideas
- 6.8K Consumer Product
- 279 Service & License
- 436 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 91 Security Highlight