I am trying to set up my network with a new installation of Sophos UTM, but am having issues with my VLAN. I'm not sure if I am understanding this correctly, so maybe someone can help. I've done a bit of searching on Google, but it hasn't got me where I need to be.
Currently, I have an EdgeRouter Lite on the perimeter, with a Dell PowerConnect 2816 switch and an Engenius WAP. My internal LAN is all untagged packets, and I have a guest/untrusted wifi on a tagged VLAN. The WAP does the VLAN tagging for the devices.
Obviously, the untagged VLAN doesn't work with Sophos. So, I can add another VLAN to my network, and add it to the appropriate ports as tagged traffic. However, on the Dell switch, I cannot disable the untagged VLAN 1. It is on all ports all the time, except a mirror port I have.
So, on each port that I want my local internal devices to connect, those ports have untagged VLAN 1, and tagged VLAN 64. How does the traffic from the port get tagged, since the port accepts both types of traffic? Do I have to set up the VLANs at the end device itself? I don't see a way to make the switch tag the traffic for me--which leaves me wondering about devices like my network printer that I don't think I can set a tag on.
This thread was automatically locked due to age.