First Look: DSA VLAN Filtering [EA8500]

Post new topic   Reply to topic    DD-WRT Forum Index -> Qualcomm Atheros based Hardware
Goto page Previous  1, 2
Author Message
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3904
Location: Germany

PostPosted: Thu Jul 31, 2025 8:10    Post subject: Reply with quote
It looks correct at first glance, but you can't see all the settings.

The VAPs must not have an IP address and must be set to “default.”

Otherwise, you can give the WLAN client a manual IP address and see if it connects (to rule out a DHCP problem).

You should also try it without SFE/NSS stuff. (This is known to cause strange problems.)

I've also read about a lot of problems in the current build threads regarding the mr7350 – so who knows?

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 25.12.2 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
Sponsor
foz111
DD-WRT Guru


Joined: 01 Oct 2017
Posts: 830
Location: Earth

PostPosted: Thu Jul 31, 2025 8:36    Post subject: Reply with quote
Thanks for looking and replying ho1Aetoo.
Sorry didn't post images as the config was the same as your pics above apart from the vlan id's.

Correct, the problematic VAP's are default (bridged) in wireless interface
I have a VAP wlan0.4, set up as unbridged with IP in wireless interface and dhcpd to test & that works as expected.

DHCP doesn't seem to be the issue, because if I add the VAPs to vlan id 1 they connect and work as expected, I assume the issue was a DD-WRT firmware issue somewhere, I have the same problem with the same config on my spare Dynalink that I have tried so it's not just on this mr7350 router.

One thing i noticed, may not be related, but maybe, on the mr7350 from a factory reset the wpa3 doesn't seem to work on wlan0 & wlan1 (like its the wrong password) but if I configure them to wpa2 and then use wpa3 on wlan0.1 & 1.1 VAP's they connect fine.

But the problematic vlan's, I've tried/tested WPA2, 3 and even without shared key any and they still don't connect once there added to 15 or 16

Tested all forms of SFE, currently disabled, with QCA NSS enabled, none allow the problematic vaps to connect from my testing.

_________________
Main Router: Dynalink WRX36, PPPoE, Gateway Mode, Network IPV4 - Isolated Vlan's. Unifi AC-Pro x 3 AP's, Router Wi-Fi Disabled. Paid Commercial Wireguard Client's & WG server, DNSMasq, Static Leases with Quad9 SmartDNS, DNSMasq Adblocking thanks to egc script.

No one can build you the bridge on which you, and only you, must cross the river of life!
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3904
Location: Germany

PostPosted: Thu Jul 31, 2025 10:37    Post subject: Reply with quote
Well, br0 is a different VLAN and has a different DHCP server.
To rule out VLAN and DHCP problems, assign the clients a manual IP address and see if they connect...
(this is how you do it)

If the VAPs ever had an IP address, it must be deleted in the settings (the default setting is not sufficient).

If an IP address is stored in the GUI, it must be deleted..

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 25.12.2 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
foz111
DD-WRT Guru


Joined: 01 Oct 2017
Posts: 830
Location: Earth

PostPosted: Thu Jul 31, 2025 13:04    Post subject: Reply with quote
The VLAN's work correctly over Ethernet, giving out the correct IP's so I don't believe that dhcp is the issue, but I will test later giving a wireless client a static IP on the correct subnet just to see if that lets it connect.

Has been reconfigured after nvram erase && reboot a few times as has the Dynalink with the same issue so shouldn't have any stuck nvram settings left over.

Added: Giving a wireless client a fixed IP on the correct subnet, still throws me out prompting me as if the password is incorrect.

_________________
Main Router: Dynalink WRX36, PPPoE, Gateway Mode, Network IPV4 - Isolated Vlan's. Unifi AC-Pro x 3 AP's, Router Wi-Fi Disabled. Paid Commercial Wireguard Client's & WG server, DNSMasq, Static Leases with Quad9 SmartDNS, DNSMasq Adblocking thanks to egc script.

No one can build you the bridge on which you, and only you, must cross the river of life!
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 3904
Location: Germany

PostPosted: Thu Jul 31, 2025 15:07    Post subject: Reply with quote
Then it seems to be something specific to the router.
It seems that something is not working properly with the WLAN and virtual WLAN interfaces in the newer builds for the AX routers.

As I said, I have no idea.
I've only read in the build threads that several people have reported such problems.

_________________
Quickstart guides:

use Pi-Hole as simple DNS-Server with DD-WRT

Routers
Marvell OCTEON TX2 - QHora-322 - OpenWrt 25.12.2 - Gateway
Qualcomm IPQ8065 - R7800 - dd-wrt r53562 - WAP
foz111
DD-WRT Guru


Joined: 01 Oct 2017
Posts: 830
Location: Earth

PostPosted: Fri Aug 01, 2025 14:19    Post subject: Reply with quote
Agreed and confirmed. Same config working correctly on R7800 DD-WRT v3.0-r61981 std (07/29/25)
seems an ax router issue, hopefully BS will find this thread and fix issue that seems to have been an issue for some builds now

_________________
Main Router: Dynalink WRX36, PPPoE, Gateway Mode, Network IPV4 - Isolated Vlan's. Unifi AC-Pro x 3 AP's, Router Wi-Fi Disabled. Paid Commercial Wireguard Client's & WG server, DNSMasq, Static Leases with Quad9 SmartDNS, DNSMasq Adblocking thanks to egc script.

No one can build you the bridge on which you, and only you, must cross the river of life!
mflorezm
DD-WRT Novice


Joined: 19 Feb 2018
Posts: 22

PostPosted: Wed Oct 29, 2025 18:20    Post subject: Reply with quote
Hi Guys,

I have a linksys EA8500 too. So, if not possible to config DSA on AX MX4200, I will try on EA8500.

my ISP needs tagged VLANID 100 (PPPoE) and tagged VLANID 101 for VoIp. Wan.100 is working with PPPoE but I need way to connect VLAN101 on the same WAN and link it LAN1 port as it was working on old R8500.

Attached is my netgear R8500 working VLAN config if anyone can take a look and help me to achieve the same result as the image below on EA8500.

Thanks,

Mauricio F.



vlan_on_r8500_838.jpg
 Description:
 Filesize:  56.73 KB
 Viewed:  6492 Time(s)

vlan_on_r8500_838.jpg


foz111
DD-WRT Guru


Joined: 01 Oct 2017
Posts: 830
Location: Earth

PostPosted: Wed Nov 19, 2025 8:32    Post subject: Reply with quote
4 months on and DSA still broken on ax routers, is this ever going to get fixed? seems odd that it works as it should on r7800 but never fixed on the later ax routers.
_________________
Main Router: Dynalink WRX36, PPPoE, Gateway Mode, Network IPV4 - Isolated Vlan's. Unifi AC-Pro x 3 AP's, Router Wi-Fi Disabled. Paid Commercial Wireguard Client's & WG server, DNSMasq, Static Leases with Quad9 SmartDNS, DNSMasq Adblocking thanks to egc script.

No one can build you the bridge on which you, and only you, must cross the river of life!
Goto page Previous  1, 2 Display posts from previous:    Page 2 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Qualcomm Atheros based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum