- Joined
- Sep 16, 2018
- Messages
- 32,574
- Reaction score
- 10,121
Some nice tutorial about pfSense VLAN
1) with cheap TP-Link TL-SG108E
2) with Unifi switch
1) with cheap TP-Link TL-SG108E
2) with Unifi switch

Just followed the following two videos to configure my MikroTik hAP ac² router to have VLAN based guest wifi and Port based VLAN. It is a bit tedious but still not that complicated.
Final results:
default 2.4GHz and 5GHz wifi, eth2, eth3 -- LAN, 192.168.88.1
guest_wifi_2G4 and eth4 -- VLAN60, 192.168.60.1
guest_wifi_5G and eth5 -- VLAN80, 192.168.80.1
Learned a bit more with the following article, to set up vlan trunk port (eth2) to pass the VLAN info the the previously configured TP-Link TL-SG108E.
http://wiki.tuturutu.eu/doku.php/networking/mikrotik/wireless_vlan
Final results:
default 2.4GHz and 5GHz wifi, eth3 -- LAN, 192.168.88.x (MikroTik default configuration)
guest_wifi_2G4 and eth4 -- VLAN60, 192.168.60.x (using the first video as the guide)
guest_wifi_5G and eth5 -- VLAN80, 192.168.80.x (using the second video as the guide)
eth2 -- trunk port to pass VLAN 60, 80 and 99 to the TP-Link TL-SG108E.
dumb access point connected to VLAN 60 access port of TL-SG108E -- VLAN60, 192.168.60.x
dumb access point connected to VLAN 80 access port of TL-SG108E -- VLAN80, 192.168.80.x
dumb access point connected to VLAN 99 access port of TL-SG108E -- VLAN99, 192.168.99.x
It is said that bridge VLAN filtering is a better method. I will take a look at that one later
https://help.mikrotik.com/docs/display/ROS/Bridge+VLAN+Table
Hope to benefit the public . I dont understand the HDB Kuku planning of having SINGLE LAN Port at the living hall design .
This was my tested setup that does not sacrifice a good router to put inside a DB Closet.
Vlan setup with single trunk
https://ibb.co/f0mC1Mq
This design is only using Single Lan Cable to route traffics from ONT to Router and back to the DB Panel to the rest of LAN points at DB.. Via Vlan group control , one can share a single LAN Trunk to route internal traffics as well as external traffics to share a Single LAN Cable.
Doing so , one can enjoy to use the good router at living hall to control more devices near TV console with multiple media devices with flexible choices of LAN/Wireless without sacrificing the distance path loss issue facing by wireless devices.
Connection
SW2. Managed Switch's Ports connection at DB. with the following connection .
P1. Trucking to Living hall lan point
P2.ONT
P4-7 -Vlan_internal , to link to LAN points to all the rooms .
SW1 - > Managed Network Switch -2(SW2) at living Hall.
Legend P1=> Port 1
P1: Linked to the SW1 Port 1
P2: Router with Vlan Profile , Vlan ID should follow Telco settng .
P3: -> Generic router without Vlan profile SW2-Ports connections
P4 -> Vlan_internal , Router LAN port rerouted back to the same switch to extend the LAN Ports capacity( number of ports increased) .
P5-P8 , Vlan_Internal
SW Configuration with the managed switch SW1 and SW2.
Users need to buy 2 Managed switch and configure a vlan grouping .
Vlan ID :10
SW2:
P1-2, tagged, Port-3 untagged
SW1
P1 & P2 tagged, P3-untag
VlanID:20
SW2 Port 1 tagged, Port8 -untagged
P1-2, tagged, P8:untag
SW1 (living hall )
P1, tagged, P8:untag
Vlan100
SW2
P1 tagged , P4-7 untagged
SW1
P1 tagged. P4-7 untagged
SW1
PVID Setting(VID)
Port1: 1
Port2: 10
Port4-7: 100
Port 8: Optional IPTV
SW2 PVID Setting
Port 1:1 //Single Lan trunk
Port 2: 10 // For singtel router
Port 3:
Port 4-7: 100
Port 8: 20 // for Singtel IPTV
actually now that i think about it, can this method can work for those on singtel ont with singtel tv going for those mesh system with 2 ports as main router?
actually now that i think about it, can this method can work for those on singtel ont with singtel tv going for those mesh system with 2 ports as main router?
yes, as long the 3rd party router (in AP mode)/ unmanaged switch supports igmp snooping, can work for singtel tv.Sometimes you do not need VLAN to sort out issues though.
For example, if there is only one LAN port in the living room, it can be a big issue for Singtel ONR users if the ONR is located in the DB box and the 3rd party AP (non Netgear and not Linksys E9450) and the Singtel TV box are in the living room, since the TV box can not be connected to the 3rd party AP.
Singtel ONR -- 3rd party router/AP -- Singtel TV Box (not working).
The initial thought is to use managed switch to sort out the issue (not proven), but there is a creative solution from hairymonster here -- to use the AP as a IGMP enabled dumb switch/AP.
Ref: https://forums.hardwarezone.com.sg/...tel-tv-onr-ac86u-ax23-singtel-tv-box.6681949/
wait guys.... are we saying that there is a separate solution (3rd solution) to the hdb issue?
usually we will either do 2 routers or 1 router and pull another lan cable method.
but with the above diagram, we are saying that all we need is 1 router, 2 switches, and the router can be placed in the middle of the room and without the need to pull extra lan cable?