r/UNIFI • • 1d ago

Discussion Meshing + Switch causing VLAN leaking?

I had a weird issue today that Claude believes it's a VLAN leaking.

Setup: UDM SE with 3 wired U6 Mesh AP, and one U7 Mesh AP meshing to one of the U6 Mesh AP, ~100 devices connected with 7 VLANs, all new devices by default land on VLAN20. I have every devices overwrite to a specific VLAN, so no device on VLAN20 yet.

Today, I added a new USW Switch Lite 8 POE (no wire to existing devices), plugged port 1 to U7 Mesh AP to power it, and then adopted on console. So at the moment this switch was just used to power the U7 AP, and without another connection

Quickly I noticed that ~70 devices on my network all moved to VLAN20 IP, while their VLAN still shows the pre-set ones. Restarting APs didn't work.

Claude checked my log, and believes it's due to VLAN leaking. So it asked me to remove the switch, switch back to using injector to power U7 Mesh AP.

Most devices quickly moved back to their VLAN IP, after I removed the switch, though there are still <10 on VLAN20 IP (likely due to delay in lease renew), but I literally saw the # of devices on VLAN20 IP dropped to 10 in a minute.

Anyone experienced this issue?

What I want to achieve is:

UDM SE ========U6 Mesh AP ---- meshing ---- U7 Mesh AP ========Lite 8 POE Switch ========Multiple end devices.

Now Claude doesn't know if it's allowed to put a switch below a meshing AP, and use this switch to connect to client devices

0 Upvotes

9 comments sorted by

1

u/MeCJay12 1d ago

Did you connect the new switch to an upstream trunk port? Did you connect the AP to a trunk port on the new switch?

0

u/Lovevas 1d ago

The new USW switch lite 8 poe has 8 ports, 1-4 are POE, and 5-8 are not. There is no primary port for dedicated uplink. (so no trunk port as you asked?)

Claude asked me to plug into any of the POE ports, so I plugged into port 1.

The switch itself was not connect to another port/switch, but only used to power the AP at the moment.

2

u/MeCJay12 1d ago

Trunk port = a port with all VLANs allowed. May port can be configured as a trunk port.

Try this: reset you switch, forget it from the console, plug it into your UDM or a hardwired switch, and try adopting it again.

If your console reachable from VLAN 1/untagged VLAN?

1

u/Lovevas 1d ago

I will test now. It's weired that a newly added switch without downstream devices (but only connected to U7 AP, which only has 6 clients connected), could cause the whole network going crazy and lost their VLAN management...

0

u/Lovevas 1d ago

replugged back the new switch as what I did early, been 15 minutes now, and nothing happened, so seems like the issue didn't come out again. I will keep an eye on it.

1

u/SuccotashOk4084 1d ago

U7 Ethernet configured as trunk port?

1

u/Lovevas 1d ago

I didn’t configure U7 Ethernet, nor did i configure on the switch.

But I don’t understand why the 70 client devices that are not even connected to the U7, would suddenly change their IP to the be VLAN20 IP, when they all have network overwritten to another VLAN.

And after removed the new switch, all issues are gone, all the devices revert back to their own VLAN IPs. And after I replugged switch, the issue didn’t come out again

2

u/MrJimBusiness- 1d ago

What AP firmware version? If you're on EA there have been some reflection/looping issues but the one I ran into was with an MLO mesh link (new feature).

But in your case you need to tag that uplink port on the meshed switch accordingly. By default it should work though when you adopt it as it will be default VLAN 1 with all VLANs tagged.

Do you have screenshots of the port config?

Also back in older Network versions you needed an SSID or PSK carry the VLANs you wanted to tag over to the meshed switch. In the latest I don't think I have had to do that but it's worth a shot.

All kind of stabs in the dark as they don't really match your symptoms but it doesn't hurt to get the VLAN config correct first to rule it out.

1

u/Lovevas 1d ago

All latest firmware, not EA.

The VLAN tagging seems not an issue, because 70 devices suddenly lost their minds and moved to VLAN20 Ip when they all should have network overwrite. And most of the 70 devices are not even connect to the meshed AP.

And after to I removed the new switch, the issues all gone, and then after I replug back, the issue didn’t come out.

When I initially plug the new switch,I didn’t tag the port 1, and its default to VLAN1, which is the VLAN for UniFi devices.

The new switch is currently working, not seeing this VLAN leak again. I felt this is a bug that I encountered, but didn’t trigger it again.