ProCurve / ProVision-Based
Showing results for 
Search instead for 
Did you mean: 

Multiple VLANs over 1 switch port


Multiple VLANs over 1 switch port

Hi all,


see VLAN overview below:

This is an example of a setup today, which works.

However we are planning to remove all of the wifi devices and replace them by Netgear Access Points, which support multiple SSIDs and can handle 2 or more VLANs. (internal wifi devices aren't listed on the overview)


Current setup: 6 interal wifi access points and 2 guest wifi access point.

We're going to place 4 powerfull netgear access point, which will broadcoast both the internal wifi and the guest wifi.


The Netgear access points however, only have 1 LAN port.

This means that we have to put 2 VLANs on 1 port.


I've read multiple articles about this, but I can't figure it out.



The problem is that the VLANs need to be separated.

VLAN12 is the vlan used for the public guest wifi. (

VLAN 1 is the internal LAN and internal wifi. (


Is it this simple that I only have to change the switch from:


port 6 to outlet 5.22 untagged vlan12 - access




port 6 to outlet 5.22 tagged 12, untagged 1 - trunk?


These are the settings between switches and (2 VLANs over 1 port)


If you need any more info, let me know.

I hope the problem is clearified.


Thanks in advance

Occasional Advisor

Re: Multiple VLANs over 1 switch port


Each port on the switch can have exactly one untagged VLAN and multiple

tagged VLANs.  On Procurve switches, the ports *must* have one untagged VLAN.


Yes it is about as simple as you describe: figure out whether the AP needs to send

one of the VLANs untagged.  If it does, do a "vlan <vid>" then "untagged <port>"

for that VLAN.  For the rest of the VLANs do a "vlan <vid>" then "tagged <port>"


If the AP has no untagged VLAN, it is probably best to go into VLAN 1, the default

vlan, and put the port in there as untagged.  However, it looks like you are planning to use

VLAN1 for production traffic.  First, consider possibly not doing that.  The only thing it really

should be used for in multi-vlan networks is CST spanning tree or if you are feeling lazy,

switch management traffic.  If you need to use VLAN1 and the AP wants all its vlans

tagged, you will have to pick another, different, vlan to work as the untagged VLAN for

that port.


Remember to also do a "tagged <port>" for all the uplinks to other switches

that must carry this VLAN, but not if the VLAN in question is the untagged VLAN

for the uplink.  Make sure all your inter-switch links have matching untagged

and tagged VLAN settings on ports that are connected to each other.


Richard Brodie_1
Honored Contributor

Re: Multiple VLANs over 1 switch port

I would only add that when you want to run tagged LANs to an edge port, you have to figure out how to get the device at the other end to accept them. So you need to assign the guest Wifi to tagged on VLAN 12 on the APs at some point; once you have that part figured, setting up the Procurves should be relatively easy.


Re: Multiple VLANs over 1 switch port



I've did the setup and guess what: It's working.

However, the guest wifi is only working on the first (of 4) router I've configured.

When I connect to the guest wifi on an other router, i get an ip adress, but no internet connection.

Also can't ping the gateway.


When I connect to the first router I've configured, I can ping the gateway and have internet access.


All settings on the switches and ports are the same... :s


Can this be caused by settings I used on the router/ap?

We used netgear WNDAP360, but I don't think those devices support DHCP forwarding.
So I've set up the guest wifi per router, and gave them all their own DHCP ranges:

AP 1: -> (this is the one where everything is working)

AP 2 -> 10.10.10. 69

AP 3 ->

AP 4 ->


Normally you sdhould use DHCP forwarding, but since the netgear does not support this, I've set it up like this.
Quick & dirty, but should work, no?


BTW: the netgear supports multiple SSID's, and each SSID/wifi network can be separated using VLANID's, so that's cool!


Re: Multiple VLANs over 1 switch port



I've called with Netgear, they confirmed that the above configuration should work, since the netgear ap doenst support DHCP forwarding.


So the problem has to be in the VLAN config.

AP 1 is working, I can ping the gateway:

When I connect to AP 2, 3 or 4, I get an IP, but have no internet access.

I also can't ping the gateway...


I've spent hours looking at the configs but can't find a defference...


This is the full overview of the current config:




URL for full pic:


The working access point is the 'NGReceptie' -

So the interal wifi network is fine, it's the Public which is only working on the


All switches and access points have the same config...

I can't see the issue...


Thanks in advance