ssh code: nvram set vlan12hwname=et0
nvram set vlan13hwname=et0
nvram set vlan14hwname=et0
nvram set vlan1ports="1 2 5*"
nvram set vlan12ports="1t 5*"
nvram set vlan13ports="1t 3 5*"
nvram set vlan14ports="1t 4 5*"
nvram set port1vlans=1 12 13 14 16
nvram set port2vlans=1
nvram set port3vlans=13
nvram set port4vlans=14
nvram set port5vlans="1 2 12 13 14 16"
nvram commit
reboot
ssh code: nvram set vlan12hwname=et0
nvram set vlan13hwname=et0
nvram set vlan14hwname=et0
nvram set vlan1ports="1 2 5*"
nvram set vlan12ports="1t 5*"
nvram set vlan13ports="1t 3 5*"
nvram set vlan14ports="1t 4 5*"
nvram set port1vlans=1 12 13 14 16
nvram set port2vlans=1
nvram set port3vlans=13
nvram set port4vlans=14
nvram set port5vlans="1 2 12 13 14 16"
nvram commit
reboot
Q1) Does anyone see any mistakes in the SSH?
Q2) I'm running pfSense so do i still need DD-WRT IPtables for rules?
I spent the weekend learning all about the process of creating VLANs on my R7000, so I am by no means an expert, but I'm pretty sure I have the gist.
I believe that the egress port must be included in the trunk and all that must be assigned to a bridge. Untagged is for a vlan to be transparent to the occupants.
Try this
Code:
nvram set vlan1ports="1t 2 5*"
Let me know how that works for you.
Also, remember that you have to assign those vlans and vaps to a bridge.
I used four bridges to separate the traffic from each other, then out to an edgerouter via port0 which handles DHCP.
I'm not familiar with pfsense, however in my edgerouter I set firewall rules to prevent the vlans from being able to route to each other without specific configuration.
Posted: Mon Feb 10, 2020 17:31 Post subject: Re: R7000 VLAN help
comdat wrote:
Try this
Code:
nvram set vlan1ports="1t 2 5*"
Let me know how that works for you.
Also, remember that you have to assign those vlans and vaps to a bridge.
I will try this hopefully tonite. Something w/ pfSense blew up last night so I have to go through my setup to fix it or recreate some of it.
Yes, I assigned the VLANs & VAPs to each bridge.
ex: BR1 has Vlan12 + vap0.1, BR2 has Vlan13 + vap0.2. (2.4g is disabled so only the 5g need assigned in my case).