DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

VLAN Tagging & Multiple AP's

  • hopkins35
  • User
  • User
More
03 Sep 2018 12:42 #7 by hopkins35
Replied by hopkins35 on topic Re: VLAN Tagging & Multiple AP's

Sidewinder wrote:

hopkins35 wrote: Would be easier for us if you could show your network setup as a diagram in something like Visio or even Powerpoint to help us pinpoint your problem(s). VLANs can be quite complicated to setup and as previously mentioned there will be config needed on your switches as well with the physical ports being added to VLAN groups and the setup of trunk ports which transport all data packets (useful when linking 2 switches or the link between a switch and an access point - possibly relevant to your problem).



I can do that, I didn't realise that you can upload diagrams, give me a couple of hours, I've a job to finish, then I'll draw something up in Visio.

Thanks all.



You'll have to upload it to a filehost and post the link

Please Log in or Create an account to join the conversation.

  • sidewinder
  • Topic Author
  • User
  • User
More
03 Sep 2018 12:49 #8 by sidewinder
Replied by sidewinder on topic Re: VLAN Tagging & Multiple AP's
Thanks

Please Log in or Create an account to join the conversation.

  • sidewinder
  • Topic Author
  • User
  • User
More
03 Sep 2018 15:33 #9 by sidewinder
Replied by sidewinder on topic Re: VLAN Tagging & Multiple AP's
OK, I have done a diagram in Visio, it's not a perfect diagram, but, I think it should be understandable.
It's a pdf, so I hope this is ok?
https://www.dropbox.com/s/lxps77fbhddjgmd/Visio-Network%20v01.00.pdf?dl=0

If anyone can help then it will be really appreciated.

Please Log in or Create an account to join the conversation.

  • sidewinder
  • Topic Author
  • User
  • User
More
03 Sep 2018 15:34 #10 by sidewinder
Replied by sidewinder on topic Re: VLAN Tagging & Multiple AP's
Everything works as I expect, until I add V-Lan tagging to be able to utilise the two AP-900's to transmit 2 SSID's.

Please Log in or Create an account to join the conversation.

  • hopkins35
  • User
  • User
More
03 Sep 2018 19:28 #11 by hopkins35
Replied by hopkins35 on topic Re: VLAN Tagging & Multiple AP's
Would be interested to see a screenshot of your VLAN port setup on the 2860.

A key principle of a port based VLAN setup is that there must be an ingress and egress port, a way in and a way out. So, for example, if you have a PC connected to port 5 and a PC connected to port 4 both on VLAN1, for them to be able to communicate with one another you would need to make sure that both port 4 and port 5 are allocated to that VLAN group. I believe from your diagram that you have another router (2860) plugged into port 6 of your 2860vn+ so port 6 on the 2860vn+ should be allocated to VLANx with a tag of xx (I read somewhere that this should be in the 10s ie. 10, 20, 30, 40 etc), on the 2860 you need to allocate the inbound port to the same VLANx group with the same tag as on the 2860vn+ and do the same for any/all of the ethernet ports on the 2860 that will be connecting to client devices.

Another rule of thumb is that when connecting VLAN aware devices, so I'm thinking of your links between your D-Link switches and your APs here, you should set these as 'trunk' links whereby the switch doesn't add or remove the VLAN tags but sends them unadulterated, obviously you would then setup the SSIDs on the APs to mirror your VLAN setup as mentioned above. Dumb wired devices, like PCs, that don't natively understand VLANS should be plugged into a port of your switch that is part of a VLAN group, don't forget to think about ingress and egress, which port is the data coming in and which port is it going out through and make sure that they're both in the right group and so get tagged appropriately.

I'm no expert but I have a fairly complex VLAN setup myself, think about ingress and egress ports and trunk links and try to make your tags as double figures and see how you get on.

Good luck

Please Log in or Create an account to join the conversation.

  • sidewinder
  • Topic Author
  • User
  • User
More
03 Sep 2018 19:42 #12 by sidewinder
Replied by sidewinder on topic Re: VLAN Tagging & Multiple AP's

hopkins35 wrote: Would be interested to see a screenshot of your VLAN port setup on the 2860.

A key principle of a port based VLAN setup is that there must be an ingress and egress port, a way in and a way out. So, for example, if you have a PC connected to port 5 and a PC connected to port 4 both on VLAN1, for them to be able to communicate with one another you would need to make sure that both port 4 and port 5 are allocated to that VLAN group. I believe from your diagram that you have another router (2860) plugged into port 6 of your 2860vn+ so port 6 on the 2860vn+ should be allocated to VLANx with a tag of xx (I read somewhere that this should be in the 10s ie. 10, 20, 30, 40 etc), on the 2860 you need to allocate the inbound port to the same VLANx group with the same tag as on the 2860vn+ and do the same for any/all of the ethernet ports on the 2860 that will be connecting to client devices.

Another rule of thumb is that when connecting VLAN aware devices, so I'm thinking of your links between your D-Link switches and your APs here, you should set these as 'trunk' links whereby the switch doesn't add or remove the VLAN tags but sends them unadulterated, obviously you would then setup the SSIDs on the APs to mirror your VLAN setup as mentioned above. Dumb wired devices, like PCs, that don't natively understand VLANS should be plugged into a port of your switch that is part of a VLAN group, don't forget to think about ingress and egress, which port is the data coming in and which port is it going out through and make sure that they're both in the right group and so get tagged appropriately.

I'm no expert but I have a fairly complex VLAN setup myself, think about ingress and egress ports and trunk links and try to make your tags as double figures and see how you get on.

Good luck



The wired physical VLan system is all working fine.
There is only one 2860, the PC with the label "guest 2860 port 6" is to indicate that there is a wired guest connection to port 6, that is why I used a picture of a PC rather than another router/modem.
All this works fine until I introduce VLan tagging, which I need to run 2 SSID's from the AP900's according to the Synology documents.
The AP900's will run the internal wifi fine and devices can see the network when connected to them etc. they just become part of the internal network OK and work fine.

I've not got as far as configuring the D-Link switches yet, I'm just confused why when I tag the guest Vlan it kills the guest connection on port 6 from connecting to the internet, and the wifi ssid which carries the same vlan tag.
According to the Synology documents, this should work!

Please Log in or Create an account to join the conversation.