Jeffrey Young
Very Senior Member
So a fun thing I just found in researching (and testing) those TP Link switches is that you can't define a management VLAN and the management IP is available from every port on the switch, no matter what settings you change. So my "untrusted" VLAN can still access the management IP if you set a static IP in the correct range, and can still see traffic to/from the management IP. Going to replace them with two D-Link DGS-1100-08V2 that should do the same thing for $10 more each but allow setting a separate management VLAN that's not accessible from all ports.
I have the TPLink 108 managed switch. I have read other warnings from other websites about this issue. I read into it that TP-Link is aware of it, but it is designed this way. You need the commercial version for better.