Joined: 08 Jun 2010 Posts: 109 Location: New Zealand
Posted: Thu Nov 22, 2018 8:46 Post subject: RT-AC3200 setting VLAN tagging on WAN port?
I've spent the last 4 hours trying to get this to work and reading lots of wikis and posts and I'm still stuck.
I have an RT-AC3200 and I have just gotten fibre installed and I can connect to my ISP using a windows laptop with windows pppoe dialer and manually setting the NIC to VLAN 10 (which is the required VLAN tag for my ISP in New Zealand - and many ISPs here use VLAN 10 tagging for fiber).
However, I am on Kong's latest build and I've tried going to Setup>Networking and under tagging I've clicked Add and then tried applying Tag Number 10 to vlan2 and then setting the wan to port assignment to the newly generated vlan2.10.
This seems like it should work, but I have had no luck whatsoever. I also tried tagging eth0 to eth0.10 and that didn't work either.
I'm completely stumped. Given that the Setup>VLANs tab shows the wan on vlan2 and the lan ports on vlan1 it seems that tagging vlan2 (wan port) with Tag Number 10 is right approach...but...yeah....no love.
I also tried using the 'Tagged' swith in the VLANs tab for the WAN port, but that had no effect either.
You don't want to "tag vlan2 to be 10". If you do that, you are double tagging. Double tagging has its uses, but isn't what you need here. You want to use vlan10 and tag it, so what you need is:
vlan10hwname=et0
port0vlans=10 16 (you can add 18 19 21 but they don't matter)
vlan10ports=0t 5
You will also need to set the various WAN variables to vlan10, so that WAN firewall rules come up with vlan10. I'm not sure why there are so many, but better safe than sorry so set these all to vlan10 (and after rebooting check iptables to make sure vlan10 is being used for WAN related firewall rules and vlan2 does not show up anywhere)
Joined: 11 Apr 2010 Posts: 318 Location: San Francisco Bay Area
Posted: Thu Nov 22, 2018 22:54 Post subject:
Tagging is different from the specific VLAN number. Tagging allows the multiplexing of multiple VLANs over a single media channel like Ethernet. The top of the Setup, Networking page has a way to set tags on specific VLANs. I use this feature to multiplex two VLANs over Ethernet to another access point where they are then de-muxed.
Still seeing some weirdness in the web gui with the VLANs and bride assignment though. I've raised that issue in the other post, but if you have any thoughts that would certainly be appreciated.
I'm not sure how to properly check iptables though for the WAN and vlan? My connection is up and running and seems ok, but I'd like to make sure everything is 'proper'