Studied the guides, by anav and others and followed ‘thenetworkberg’ tutorial to make vlan’s on my ros..
Have 1 rb5009, hap ac (backup), and 2 switches.. brocade icx7250/3com baseline 2948 (which will only run on 1g SFP+ Only)
My wan side is 5009 connected with 2 bridged mode modems,
SO VLAN’s are setup and;
-working actually
-DHCP also good
-Unify U6 Pro AP only works on Default SSID and not the ones which have my VLAN’s
Sfp as trunk and connected to brocade and all ports untagged and tagged on it as per guides (i didn’t say properly because i need some more conceptual understanding)
What i wanna diagnose is that where is my config wrong ? Because:
a) I am getting a 1/5th of my speed (as compared to a normal dhcp client and LAN scenarios on my device)
b) can,t do a speed test sometimes and and when i do its as above, at least 5 times lower than my original speed
c) VLAN’s working on brocade switch, also mikroitk, but not on Unifi, and thus this is where i scoured the forum and got more confused and want to learn;
Theoretically if i set an ether port as tagged am i correct to assume it can’t be untagged to all VLAN’s at the same time ?
(Big ISSUE for me) = What in God’s name is this issue with default VLAN’s and them being necessarily untagged or something:
While i was setting my switch ports on Brocade/3com both gave a similar squeak when i tried to change VLAN1 untagged.. Is the defgault VLAN supposed to have no trunk port and must be on ports as untagged ? I need to understand this as maybe this the reason my unifi AP won’t receive VLANs and only the default SSID’S works which is VLAN1
secondly is PVID the same as VLAN id ? do i have to set it in bridge ports for all ports ?
i hadn’t enabled ingress filtering before but did it after, .. also what about frame types, is it necessary to set them and why can’t i use admit all since VLAN filtering is already enabled
I Realize from forums that Unifi has its stupid issues and wants an untagged (access) port to communicate with, but should i not connect it to a trunk as i have 4 VLAN’s that i want it to receive and broadcast as ssid’s, but an access port would limit it to just 1 VLAN or network segment, no ?
many forums said mikroitk doesn’t prefer RSTP.., so STP or infact MSTP is better suited ? Is this correct ?;
Because of this what should i set my brocade switch to ? as it does not have MSTP, should i use STP here then ?
Lastly.., am i in a double NAT Scenario ?
i have 3 buildings with the main one having a load balanced 5009 with 2 Bridged mode ISP’s and a 3rd smaller isp as WAN’s
i have run a dhcp server on it and this building (the one with the VLAN office environment) receives WAN via DHCP client..
Can this be a reason for any speed issues ? because without VLAN’s and just LAN before things were running smooth
in the release notes it state “SSIDs using RADIUS assigned VLANs or on different VLANs from the native VLAN may operate at slower than expected speeds. This is our top priority to resolve.”
All smart devices get IP on vlan11. (trusted or management network)
Why is ethernet 5 UNTAGGED FOR TWO different vlans. ILLEGAL !!! an access port or Hybrid port can only have one untagged vlan. THus I removed vlan12 as untagged on 5.
You have a mismatch between vlans and pools, plus I added a vlan.
What is pool for 30??? pool2 no such address etc… there is no such subnet… hence a mismatch somewhere.
Why is ethernet 5 UNTAGGED FOR TWO different vlans. ILLEGAL !!!
Quite right and an oversight, was fixed asap, regardless it was not in use and thus is not the cause, as i am ‘trunked’ to a brocade at sfp and using access ports there.
All smart devices get ip on Vlan11
?? How ? You have not set it as an access port or a Tag anywhere ??
If so i where am i to connect my unifi u6 to .. Like set a port access and then ? Since Unifi is forwarding my vlan’s should i not be connecting it to a trunk/tag port ?
Lastly my pools are not mismatched somewhere and i have re-named and rechecked them again, pool 30 was actually me waiting to understand and setup a management/native Vlan (AND ASSIGN TO IT AFTER) which im still unclear about:
a 5s delay just for a simple google search must mean some config or pvid or tag error etc..
Well the config was incomplete and thus confusing.
Yes everysmart device gets an IP on the managment vlan.
Unifi devices as a default (backwards), assume the management vlan comes untagged and all the wifi vlans tagged.
Thus you need a hybrid port. X is tagged for data vlans but untagged for the management vlan.
add bridge=bridge interface**=etherX** pvid=YY ( where X is port to unifi AP, where YY is the management vlan ID ) add bridge=bridge tagged=bridge,trunkport1,trunkport2,X vlan-ids=A,B,C
add bridge=bridge tagged=bridge,trunkport1,trunkport2 untagged-=X vlan-ids=YY