Fresh Install OPNsense 26.7, unable to implement vlans with Netgear MS308E

Started by Schwermzilla, October 01, 2026, 10:35:24 PM

Previous topic - Next topic
Hello OPNsense forum, I apologize if this is a novice problem, but it has stumped me for days at this point and I have been searching here and at netgear's forum and not found anyone sharing the same problem, I have seen some related posts which I have tried to replicate the solutions of, to no success.

Scenario: I have OPNsense 26.7.4_1 running on a 5 port miniPC (Intel N150, 128gb ssd & 8GB ram), the pc has 3 2.5Gb ports and 2 10Gb SFP ports. Currently, I am just using the 2.5Gb ports, as I want to verify vlans work before I add more complexity. To keep things simple, I am working on a reduced complexity as things weren't working in a previous, more complex state either. So, I recently did a fresh install and full update because I was at wits end.
I am only able to upload one photo here because of image size, full folder is available here: https://drive.google.com/drive/folders/1YmCybrYoM4dVkMVTz_UjtMY8Dn6Zi6km

Currently: LAN and WAN access work great, stable internet, DHCP leases working, Static IP config for the managed switch, wireless AP, and NAS.
Port 1 is WAN (igc0/Wide_Network in photos).
Port 2 is the LAN (igc1/Local_Network in photos).

Problem: I am trying to setup Port 3/igc2 as a truncated vlan port with only two tagged vlans on it;
tag 11 is the Guest_Network, tag 22 is the Surveillance_Network. I have setup the vlans, enabled them as interfaces, added static ipv4 addresses, allowed firewall access and allocated DHCP address pools (verifiable in the photos).
I have split out the Local_Network and vlans on separate ports, as I have seen others have issues with mixing tagged and untagged traffic on the same port with netgear/Opnsense.
The photo (netgear_ports) shares the mapping on the Netgear managed switch; ports 4/5 are connected to OPNSense, port 4 is paired with igc1 (Local), port 5 with igc2 (vlan Trunk).  Port 8 will go to an NVR which has POE ports for the cameras (haven't turned this on yet). Last relevant connection on the switch, port 1 goes to my wireless AP (Netgear Orbi Pro 6, SRX80) setup in AP mode, which works on local network access when tested. On the Orbi, it has been setup in Trunk mode since being in AP, I have two id's broadcasting there, one for 192.168.1.x (local) and the other for 192.168.11.x. (guest). I have tried running port 1 on the switch in trunk/uplink mode as well, but then I lose connection to the orbi in either Trunk or Access vlan 11 only (pictured). The only way it works is when it is set to access only local vlan 1; Then devices on the local wifi work fine, devices on the guest wifi connect to the Orbi but have an IP configuration error and aren't assigned DHCP leases, as expected.

My understanding of the problem, when in Trunk/Uplink mode, the Netgear switch is not seeing the incoming tagged traffic on igc2/port 5. Running in diagnostic mode shows zero "bytes received" on that port, the screenshot was captured after 30 mins or so. I am not confident OPNsense is sending anything, but I don't see any issues with my configuration from the OPNsense side.

Any help would be wonderful, I had spoken with my friend who is an SRE, and he gave me a bit of sanity check that I didn't have anything obviously setup wrong, but who knows, so I come to you all in hopes of finding a solution. THANK YOU!

Quote from: Schwermzilla on October 01, 2026, 10:35:24 PMLast relevant connection on the switch, port 1 goes to my wireless AP (Netgear Orbi Pro 6, SXR80) setup in AP mode, which works on local network access when tested.

On the Orbi, it has been setup in Trunk mode since being in AP, I have two id's broadcasting there, one for 192.168.1.x (local) and the other for 192.168.11.x. (guest).
I have tried running port 1 on the switch in trunk/uplink mode as well, but then I lose connection to the orbi in either Trunk or Access vlan 11 only (pictured).

The only way it works is when it is set to access only local vlan 1 : Then devices on the local wifi work fine, devices on the guest wifi connect to the Orbi but have an IP configuration error and aren't assigned DHCP leases, as expected.
So the problem is your WiFi Orbi Unit and not OPNsense then ?!

Do those things even understand VLANs on their Switch/LAN side ??
AFAIK they do not : Only on the WAN Port.

Also currently your Netgear Switch shows Port 3 as Access Port and those do not transport VLANs ofcourse...
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

So the problem is your WiFi Orbi Unit and not OPNsense then ?!

It may be a part of the current config problem, to test that, I have just plugged my laptop into port 1 and 8 to test vlan 11 and 22 and it also doesn't connect to the internet on either port in access mode for their respective vlans.
So, I am primarily trying to diagnose the managed switch and it's connection to OPNsense, so far, when I change any connection on the switch that connects to OPNsense to Trunk, I lose communication on that port (showing 0 bytes received over 30 mintues).
Not expanded above, but I have previously attempted to have the lan port assigned the non-vlan 192.168.1.x in addition to the tagged vlans of 11 and 22 (with lan/igc1 as parent), but I assumed it was sending the LAN as untagged traffic, and read elsewhere that the switch was expecting three vlans. When I was testing this I kept losing access to the OPNsense over the network when switching to Trunk mode on the switch, so I set one port, igc1, to be untagged LAN access and am attempting to diagnose the pathway of just vlans 11 and 22 from igc2 on the router, to port 5 on the switch in Trunk/Uplink mode, and then handing over vlan exclusive Access to 11 or to port 8 as exclusive access to 22, neither have worked. Essentially ignoring the AP for now.

The current connection of ports 2,3,4,6,7 are running on untagged Lan so I can continue to interface with network devices and troubleshoot the vlan path, do you think that is causing problems?

Do those things even understand VLANs on their Switch/LAN side ??
AFAIK they do not : Only on the WAN Port.


Those things being the wireless AP? and the NVR?
AP, yes I have its incoming port from the switch set to Trunk, and have the wireless network setup expecting tag 11 for the guest network wifi.
NVR, no, which is why I have it's port setup as Access - 22, expecting the netgear to provide untagged access exclusively to vlan 22. 

Also currently your Netgear Switch shows Port 3 as Access Port and those do not transport VLANs ofcourse...
Yeah, hope that is not what is causing the problem. as expanded above, other devices are runninng on LAN without tags. Hoping this would isolate the switch's Port 5 trunk port to the OPNSense igc2 connection, assigned just the two vlans and testing with the AP and a laptop for connection on either port 1 for vlan 11 or port 8 for vlan 22

Quote from: Schwermzilla on Today at 01:01:56 AMYeah, hope that is not what is causing the problem.
Well... if you want to transport Multiple VLANs to another Switch or Accesspoint then you need to use TAGGED VLANs and not ACCESS Mode :)

Just to be sure :

Are you aware of the following =>

OPNsense Interface (whole NIC basically) => Switch Port in ACCESS Mode
OPNsense VLAN Interface (VLAN Interface assigned to a NIC that's not used for anything else) => Switch Port in TAGGED Mode

Switch Port in ACCESS Mode => End user devices like PCs/TVs/Consoles/etc.
Switch Port in TAGGED Mode => Port of another Switch or Accesspoint that understands TAGGED VLAN traffic.

ACCESS MODE = Only 1 VLAN allowed.
TAGGED MODE = Multiple VLANs allowed.

Does your current setup look like this ??
Weird guy who likes everything Linux and *BSD on PC/Laptop/Tablet/Mobile and funny little ARM based boards :)

it reminds me of the first time i enabled vlans on my switches.
if i understand correctly
igc1 (LAN) is linked to port4 of the switch
igc2 (VLAN11+VLAN22) is linked to port 5 of the switch.

port 4 needs to be set to access mode with PVID 1
port 5 needs to be set to trunk with vlan tag 11&22
but for this to work port5 can't have PVID 1.
I fixed things by creating a dummy vlan 99 (or whatever you want but not used ) and setting PVID 99 to port5.
and of course the port for the orbi needs pvid 1 and tagged vlan11 and vlan22 (if you have wifi cams)