Configure VLANS on XR500 using new GUI under Networking Tab

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
DWCruiser
DD-WRT User


Joined: 15 Aug 2016
Posts: 290
Location: Melbourne, Australia

PostPosted: Mon Jun 23, 2025 4:52    Post subject: Configure VLANS on XR500 using new GUI under Networking Tab Reply with quote
Subsequent reinstating of Switch Config tab from r61848 (06/24/25) renders the following steps dormant. Cool
________________________________________________________________________________________________

The following steps detail how to set up VLANs in later DDWRT versions where [Switch Config] Tab is no longer available. (Tested under version r61745).

Examples: setting up Two VLANs. 1 wired, 2 vAPs (wlan0.2 and wlan1.2). The two VLANs will subsequently be placed on bridge.

Note: Reference to 'wait 1 min' or '2 mins' is an approximation. The surest way is VISUALLY checking that i) some light indicators will go off first; ii) then all corresponding light indicators are lit up again. It's indicative that the router is back into a READY state, after the change.

In steps:

1. First, ensure XR500 works in DDWRT with wifi (wlan0 & wlan1 for fallback connection, if necessary). Note: No CLI at all for VLAN in [Startup].
2. Create 2 vAPs: wlan0.2 and wlan1.2 (wlan0.1 & wlan1.1 are already utilized for other purposes).
-Options chosen: AP Isolation (enable), Web UI Access (disable), Network configuration (Unbridged) & Net Isolation (disable) - Leave IP address blank. Not needed. Save&Apply (S&A)
3. Set up security and password for each vAP created @2. S&A. Wait 1 min.
4. Under [Setup|Networking], at VLAN Tagging:
4.a - Set VLAN ID 10 for etherport, say, 4
Set Tagging VLAN20 for each wlan0.2 and wlan1.2. S&A. Wait 1 min.
4.b - Create bridges for VLAN10 & VLAN 20. S&A. Wait 2 mins. (Not sure about options under the 'Settings' column here for now).
5. Assign to corresponding bridge created above VLAN10, wlan02 & wlan1.2. S&A - Wait 2 mins - Do ANOTHER s/w reboot via [Administration|Reboot Router]
6. Verification: Check to see each VLAN component appears under the [Current Bridge Table] as you would expect. This step indicates that all steps above are completely captured by XR500!
7. Roll down the page to enter relevant details for br10 & br20, including subnets. S&A. Wait 2 mins.
8. Finally, enter details at the bottom page for DHCP for each bridge. S&A. Wait 2 mins.
9. Then do another s/w reboot [Administration|Reboot Router]

Both VLANs should now be working on XR500 as expected.

(P.S. This write-up is my appreciation of the excellent features of DDWRT by BS and devs). Cheers.

_________________
Life is a journey; travel alone makes it less enjoyable and lonely.
___________________________________________________
2x Netgear R9000 & 2x XR700
Features:
- Gateway
- Overclocked -2000MHz
- SmartDNS, DDNS
- Both 5GHz & 2.4GHz using DDWRT
(not Vanilla component)
- Private Home network on default br0 bridge together with vlan1 + wlan0 & 1
- Isolated port-based VLANS, placed on bridges + vAPs (wlan0.1 & 1.1) for guests & IoT devs)
- WireGuard Server for secure on-the-road access & remote control of devices @home
- OpenVPN Client for incognito & o/seas based programs
- 10G SFP+ connected to RB5009 (via optical fiber)
- QoS - HFSC/FQ_CODEL deployed on ISP's 500/50mbps connection


Last edited by DWCruiser on Tue Jul 08, 2025 22:33; edited 1 time in total
Sponsor
zdsf
DD-WRT Novice


Joined: 09 Nov 2022
Posts: 31

PostPosted: Tue Jul 08, 2025 18:23    Post subject: Reply with quote
I am struggling to make it work for 2 vlans setup on R7800

VLAN1: lan 1, lan2, lan3, lan4, 5ghz AP
VLAN2: lan 4, 2.4ghz AP

LAN4 is tagged (VLAN1 and VLAN3), There was CPU port (eth1 maybe?) was also tagged VLAN1 + VLAN3.


Can you post a screenshot of how you'd do it? Mine create lan1.1,.... lan4.1, and lan 4.3 instead of creating VLAN1 and VLAN3 that I can then assign to bridges.



Screenshot_6.png
 Description:
Old configuration that works
 Filesize:  25.84 KB
 Viewed:  20826 Time(s)

Screenshot_6.png




Last edited by zdsf on Tue Jul 08, 2025 20:57; edited 1 time in total
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16756
Location: Texas, USA

PostPosted: Tue Jul 08, 2025 18:46    Post subject: Reply with quote
That's not the new GUI settings. That is pre-DSA. See Sticky: Basic VLAN configuration via GUI, specifically swconfig - VLAN configuration via GUI - 2 CPU ports and ensure you are on a fairly recent pre-DSA build. Otherwise, upgrade and do it the new way.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
zdsf
DD-WRT Novice


Joined: 09 Nov 2022
Posts: 31

PostPosted: Tue Jul 08, 2025 20:57    Post subject: Reply with quote
Yes this is the old. Any advice on how to translate it to the new GUI (post-DSA)? That's my question. Thanks
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 16756
Location: Texas, USA

PostPosted: Tue Jul 08, 2025 22:19    Post subject: Reply with quote
From the same sticky:

DSA bridge filtering - VLAN configuration via GUI

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
RSS feed for DD-WRT releases (2025)
RSS feed for DD-WRT releases (2024)
RSS feed for DD-WRT releases (2023)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
lexridge
DD-WRT Guru


Joined: 07 Jun 2006
Posts: 2152
Location: WV, USA

PostPosted: Wed Jul 09, 2025 3:17    Post subject: Reply with quote
zdsf wrote:
I am struggling to make it work for 2 vlans setup on R7800

VLAN1: lan 1, lan2, lan3, lan4, 5ghz AP
VLAN2: lan 4, 2.4ghz AP

LAN4 is tagged (VLAN1 and VLAN3), There was CPU port (eth1 maybe?) was also tagged VLAN1 + VLAN3.


Can you post a screenshot of how you'd do it? Mine create lan1.1,.... lan4.1, and lan 4.3 instead of creating VLAN1 and VLAN3 that I can then assign to bridges.


Can you post a screenshot of your setup with the DSA build. Unless you have a specific use for tagged vlan1 on the trunk, you can probably do away with that, but that is a hot topic in itself (usually completely safe for home use but maybe risky in corporate networks). Note you do not need to use VLAN Filtering to use VLANs on DD-WRT. It can 100% completely be done with VLAN Tagging along with a bridge for each vlan.

The old Switch Config tab REQUIRED you to have a tagged VLAN1 on the Trunk port just to have access to the router. The DSA method does not require it.

_________________
- Linksys EA8500: I-Gateway, WAP/VAP 5ghz only. Features: VLANs, Samba, WG, Entware - r60xxx
- Linksys EA8500: 802.11s Secondary w/VLAN Trunk over 5ghz - r60xxx
- Linksys MX4300: 802.11s Primary w/VLAN Trunk over 5ghz. 2.4ghz WAP/VAP only - r60xxx
- Linksys MX4300: (WAP/VAP (7)) Multiple VLANs over single trunk port. Entware/Samba r60xxx
- Linksys MR7350: WDS Station for extended Ethernet r60xxx
- Linksys MR7500, MX8500: None in production. Just testing. r60xxx
- OSes: Fedora 40, 10 RPis (2,3,4,5), 23 ESP8266s: Straight from Amiga to Linux in '95, never having owned a Windows PC.
- Forum member #248
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3776
Location: Germany

PostPosted: Wed Jul 09, 2025 6:54    Post subject: Reply with quote
Quote:
It can 100% completely be done with VLAN Tagging along with a bridge for each vlan.


But it has been proven that this does not work properly for me.

For example, a device connected to my R7800 on port 4 cannot access the trunk on port 2.

The DSA implementation on the R7800 simply seems to be faulty.

Bridge filtering works correctly, this is also the openwrt way.

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 24.10.4 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 13880
Location: Netherlands

PostPosted: Wed Jul 09, 2025 7:45    Post subject: Reply with quote
ho1Aetoo wrote:
Quote:
It can 100% completely be done with VLAN Tagging along with a bridge for each vlan.


But it has been proven that this does not work properly for me.

For example, a device connected to my R7800 on port 4 cannot access the trunk on port 2.

The DSA implementation on the R7800 simply seems to be faulty.

Bridge filtering works correctly, this is also the openwrt way.


I have an R7800 running OpenWRT and there are problems reported with the qca8k DSA driver

See:https://github.com/openwrt/openwrt/issues/17891

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3776
Location: Germany

PostPosted: Wed Jul 09, 2025 8:12    Post subject: Reply with quote
https://forum.dd-wrt.com/phpBB2/files/7975267527558_158.jpg

This is how I had configured it.
It worked so far, but there was no cable connected to the WAN

Anyway, never touch a running system.
swconfig worked everywhere without any problems

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 24.10.4 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
zdsf
DD-WRT Novice


Joined: 09 Nov 2022
Posts: 31

PostPosted: Thu Jul 10, 2025 17:47    Post subject: Reply with quote
Thanks guys for shedding more light on this. So what's the consensus, should I replicate the openwrt config with vlan filtering or do we try to do tagging as well?

I am inclined to stay on this build (r60586 std (04/04/25)) till the DSA is sorted out since this is the main router in my home and cant change anything till the kids are away. Fixing a typo i made in the original post:

VLAN1: lan1, lan2, lan3, lan4, wlan1
VLAN3: lan4, wlan0

Port 4 goes to a smart switch that sorts out the vlans. If it can be done with swconfig, then I don't mind waiting on ho1Aetoo's great how to posts for the DSA. Thank you everyone.
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3776
Location: Germany

PostPosted: Thu Jul 10, 2025 18:04    Post subject: Reply with quote
I have posted an example of bridge filtering with a trunk there.

https://forum.dd-wrt.com/phpBB2/viewtopic.php?p=1315642#1315642

(is not so easy to configure, many settings have to be made and you can quickly lock yourself out completely)

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 24.10.4 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum