What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

VLAN Switch Control settings for the Default IoT network are not being applied to the RT-BE88U AiMesh router

arewhy

Occasional Visitor
Hello folks,

The VLAN Switch Control settings for the Default IoT network are not being applied to the RT-BE88U AiMesh router with Merlin or ASUS 3006.102_37xxx firmware. The issue was not present on the GT-AX 6000 with ASUS 3006.102_34810. I don’t know if the issue was introduced when ASUS created the new “Network” page to consolidate main network and Guest Network Pro or if the issue is only present on the RT-BE88U. Below are the gory details. In every case, I performed a factory reset using the WPS method and the results are fully reproducible.



An IoT network was configured under Guest Network Pro for the Default IoT network, with the default VLAN assigned (52), LAN IP 192.168.52.1, and DHCP enabled. Wireless clients connected to the IoT VLAN's SSID on both the AiMesh router and AiMesh nodes and function as expected.

However, configuring any LAN port on the AiMesh router to Mode=Access and VLAN profile for the IoT network does not yield the expected results. The port behaves like any LAN port set to All(Default) mode, receiving an IP address from the main LAN IP pool. In contrast, VLAN Switch Control settings work correctly on AiMesh nodes. Setting Mode=Access and the VLAN profile for the IoT network on a node port ensures that any device connected to that port receives an IP from the Default IoT network and can communicate with other devices assigned to the VLAN.

A VPN VLAN was also created under Guest Network Pro without encountering the previously mentioned issue. Additionally, for the VPN VLAN, there is an AiMesh configuration option available to select which nodes the VPN VLAN applies to. However, there is no AiMesh configuration option for the Default IoT VPN. Despite this, the IoT VLAN is accessible on all nodes except for the AiMesh router switch ports.

Below is the BE88U’s switch and bridge configuration after setting eth8 to mode=Access and assigning it to the Default IoT profile. The expected outcome is that eth8 and eth8.52 should not be present in br0 and br55 respectively, and eth8 should be present in br55.

Picture1.png



bridge name bridge id STP enabled interfaces

br0 8000.cc28aa2xxxx no eth1
eth2
eth3
eth4
eth5
eth6
eth7
eth8
eth9
wds0.0.1.0
wds0.0.2.0
wds1.0.1.0
wl0.0
wl0.1
wl0.4
wl1.0
wl1.1
br55 8000.d228aa2axxxx no eth1.52
eth2.52
eth3.52
eth4.52
eth5.52
eth6.52
eth7.52
eth8.52
eth9.52
wds0.0.1.52
wds0.0.2.52
wds1.0.1.52
wl0.2
wl0.52
wl1.2
wl1.52
br56 8000.d228aa2axxxx no eth1.53
eth2.53
eth3.53
eth4.53
eth5.53
eth6.53
eth7.53
eth8.53
eth9.53
wds0.0.1.53
wds0.0.2.53
wds1.0.1.53
wl0.3
wl0.53
wl1.3
wl1.53

Network Configuration

RT-BE88U with Merlin 3006.102.3 or ASUS ASUS 3006.102_37102

Two GT-AX6000 AiMesh nodes with ASUS 3.0.0.6.102_34810. One node is connected via a 2.5 Gbps link, and the other is connected via Wi-Fi.

Workaround

I have found that, using the brctl command, I can manually assign the BE88U's ethernet ports to the desired VLAN profile.
 
The VLAN implementation on these devices is an absolute nightmare. I don't know what kind of testing they did on the soft- and hardware before releasing this, but it's been slim to none if you ask me. I bought two of these devices because they support VLANs natively to replace my older setup where it had to be hacked together. After troubleshooting for two weeks I still haven't got the devices to work properly. Among many of the problems I encountered, the one you encounter I hadn't ran in to yet, but maybe that is because I am running mine in AP mode. I'm strongly considering to do the whole setup with scripting it myself like I did here instead of using the Asus provided options.

Also don't buy into the STP being enabled, I've also encountered broadcaststorms in my test setups where their STP implementation is clearly failing.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top