You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

TL-SG108E交换机与Proxmox服务器VLAN配置异常排查及优化建议咨询

TL-SG108E交换机与Proxmox服务器VLAN配置异常排查及优化建议咨询

Hey there! Let's break down the VLAN leakage issues you're seeing (VMs on VLAN40/50 accessing VLAN10 and VLAN1 switch IPs) and walk through step-by-step fixes to get your setup aligned with your original goals.

First, let's recap your core requirements to keep us focused:

  • VLAN10 (Users): Only allow internal communication between devices on this VLAN
  • VLAN20 (Admins): Full access to all other VLANs
  • VLAN30 (Server Config): Restricted access for Proxmox GUI/SSH (ideally only accessible to VLAN20)
  • VLAN40 (Home VMs): Internal-only, no access to other VLANs except maybe necessary services (like DNS if hosted elsewhere)
  • VLAN50 (Shared VMs): Only accessible via VPN, no access to internal VLANs like 10/40

Likely Root Causes of Your Current Issues

From your description, the problems are almost certainly coming from one (or a mix) of these three areas:

  1. Default VLAN1 misconfiguration on your TL-SG108E switches
  2. Incorrect trunk port settings between switches or to your Proxmox server
  3. Missing VLAN isolation rules on your router or Proxmox firewall

Step 1: Fix TL-SG108E Switch Configuration

TL-SG108E uses 802.1Q VLANs, and the default VLAN1 is often the culprit for unintended cross-VLAN access. Here's what to adjust:

Port Mode & VLAN Allowed Lists

  • Proxmox Server Port (Switch2): Set this to Trunk Mode, then explicitly allow only the VLANs you need (10,20,30,40,50). Remove VLAN1 from the allowed list—this stops unmarked VLAN1 traffic from leaking through to Proxmox.
  • Switch-to-Switch Link (Switch1 ↔ Switch2): Also set this to Trunk Mode, allow only your target VLANs (10,20,30,40,50), and block VLAN1.
  • Access Ports (PC1, TV-PC, AP, etc.): Set each to Access Mode and assign their correct PVID (e.g., PC1 gets PVID 10 for user VLAN). Ensure these ports don't allow any other VLANs.
  • Switch Management IP: Move both Switch1 and Switch2's management IP from VLAN1 to VLAN30 (your server config VLAN). This eliminates VLAN1 as a reachable management network for your VMs.

Verify VLAN Isolation on Switches

After making changes, test with two devices:

  • Plug a PC into VLAN10 and another into VLAN40
  • If they can ping each other, double-check your port VLAN assignments—you likely have a port incorrectly allowing multiple VLANs.

Step 2: Hardening Proxmox Network Configuration

Proxmox's bridge setup needs proper VLAN filtering to prevent leakage. Here's what to tweak:

Enable VLAN-Aware Bridging

If you're using Linux Bridges (the default), edit your /etc/network/interfaces file to enable VLAN filtering for your main bridge:

auto vmbr0
iface vmbr0 inet static
    address 192.168.30.10/24  # Assign Proxmox to VLAN30
    gateway 192.168.30.1      # Your router's VLAN30 gateway
    bridge-ports eno1
    bridge-stp off
    bridge-fd 0
    bridge-vlan-aware yes      # Enable VLAN filtering
    bridge-vids 10 20 30 40 50 # Allow only your target VLANs

Reboot Proxmox or restart networking with systemctl restart networking after saving.

VM Network Configuration

  • For each VM, edit its network adapter settings: set the VLAN Tag to the correct value (e.g., 40 for home VMs, 50 for shared VMs).
  • Ensure no VM is using an untagged adapter (which would default to VLAN1)—this is probably how your VMs ended up accessing VLAN1 switch IPs.

Proxmox Firewall Rules

Add rules to block cross-VLAN access at the VM or bridge level:

  • For VLAN40/50 VMs: Create a rule that allows outgoing traffic only to their own VLAN subnet, plus any necessary services (like your VPN server for VLAN50, or DNS if hosted on VLAN30).
  • Block all outgoing traffic from VLAN40/50 to VLAN10's subnet (e.g., 192.168.10.0/24).

Step 3: Router-Level VLAN Isolation

Your router is handling inter-VLAN routing, so you need to add firewall/ACL rules here to enforce your access policies:

  • Block VLAN40 ↔ VLAN10, VLAN50 ↔ VLAN10: Create rules that drop any traffic between these subnets.
  • Block VLAN40 ↔ VLAN50: Prevent home VMs from accessing shared VMs and vice versa.
  • Allow VLAN20 ↔ All VLANs: Let admin devices access every subnet as needed.
  • Restrict VLAN30 Access: Only allow VLAN20 to reach Proxmox's GUI/SSH (VLAN30 subnet)—block all other VLANs from accessing VLAN30 unless necessary.
  • Drop VLAN1 Traffic: Disable routing for VLAN1 entirely, since you moved switch management to VLAN30.

Final Testing Checklist

  1. Ping from a VLAN40 VM to a VLAN10 device—this should fail.
  2. Ping from a VLAN40 VM to Switch1's old VLAN1 IP—this should fail (since you moved management to VLAN30 and blocked VLAN1 routing).
  3. Ping from a VLAN20 device to all VLANs—this should work.
  4. Verify shared VMs on VLAN50 are only accessible via VPN, not from internal VLANs.

If you still run into issues, double-check each device's VLAN tag assignments and rule sets—small misconfigurations (like a typo in a subnet mask) are often the culprit!

备注:内容来源于stack exchange,提问作者meszolym

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 12:03:14