Managed Switch Recommendation

There's quite a bit of difference between consumer and business gear however their older DSL gear is pretty solid for what it is.l

Half expected to used business equipment recommended for this. Not an option? Not a good option?

I've been contemplating running a single cable from the router to our loft and then connecting various wall sockets and wireless access points to a switch in the loft. Hence my interest in the original post.

It's usually not worth it since you wont have any warranty and "enterprise" features aren't usually needed at home not to mention that most generate quite a bit of heat which results in noisy fans and ventilation requirements.

1 Like

Be aware that most business switches are meant for rack usage, which means they come with loud fans - they are rarely home compatible.

3 Likes

Might not have mattered if it was in the loft. :slight_smile:

And presumably draw a lot of power.

I have other heat worries about the whole idea since my loft gets very warm in sunny weather.

Had look on ebay earlier - I can also see there really isn't much of a price differential, so given your advice I can see it's better to go with consumer switches.

Thanks to you both.

1 Like

Having worked on porting OpenWRT on managed switches using RTL8380 SoCs (Support for RTL838x based managed switches), my experience is that all vendors including premium vendors like Cisco use the same switch designs made by always the same Taiwanese companies for these SoCs. Whether the electronic components are of higher quality in some cases I don't know. For a list of vendors for this SoC type see e.g this interesting list:
https://packetstormsecurity.com/files/154201/Realtek-Managed-Switch-Controller-RTL83xx-Stack-Overflow.html
With regards to heat: There are web-managed switches with up to 52 GE ports that do not need fans, for example the DLink DGS‑1210‑52. Fans come into play when either PoE of more than about 100Watts is made available by the switch or there are Multi-Gigabit ports in the switch, as the power consumption seems to increase roughly linearly with the speed of a port. There is experimental support for OpenWRT for switches with up to 28 ports, including 4 SFP ports for fibres with the RTL8382M SoC, all fan-less and some with 100Watts PoE.
Kobi

2 Likes

Still educating myself on managed switches, but I did notice that some (all) cheap ones only support VLAN's from 1 to the number of ports. So they are not suitable for some use cases (i.e. WAN tagging with ISP's specific VLAN id). I will read up on Zyxel and HP switches now.

That isn't necessarily a problem, if they at least allow defining VIDs (VLAN IDs).

That is the thing: they do not. Some I checked only support VLAN ids from 1 to 5 (or 8). I think they call it Basic VLAN Support.

I too was looking for a managed switch. I ended up ordering a Netgear GS108Ev3. I already have a GS105Ev2 and yes the interface is horrible but it doesn't really matter, configure it once and done.

I went with Netgear because it supposedly uses a better Broadcom chip, though who knows what they really ship these days or if it really matters vs Realtek that TP-Link, Zyxel and others use.

One weird thing about these Netgear switches:

That's from the firmware release notes, well known issue. But I have no plans to enable flow control, so it should be OK. And it's just for port 80 which is less common these days. But still, surprised by such a crappy decision, you would think they could have picked a less common port for their web interface or let you set it.

They all have 802.1q advanced settings where you can customize about 4000 VLAN IDs (might be easy to miss it though in the crappy web interface). If you do basic port based VLANs then you get VLANs from 1 to the number of ports.

1 Like

Updating the above ... I gave up on the Netgear GS108Ev3 because you can't set the management VLAN, it's stuck on PVID 1 untagged only. You also cannot set ports to allow tagged traffic only. And other things like a port can be untagged in multiple VLANs which makes no sense to me.

I instead picked up a GS108Tv2 (Broadcom BCM53312) on the cheap. It's better in terms of the above limitations, but the web interface is also terrible and it's not getting firmware updates anymore. It does the job, set it and forget it, I hope to not look at the UI often.

Consumer grade managed switches are disappointing. They can get the job done in a home environment, but if you want to do things the proper way and learn from it, look for something else :frowning:

3 Likes

I think the TP-Link small-business grade switches look reasonable: T1600G-28TS for example (about $125 on Amazon)

Also the Zyxel GS1900-24E used to be about $99 it's an excellent deal at that price.

For low-end home use the TP-Link sg108e is workable, it supports full VLANs and very basic QoS, as well as static LAGs

I wish they came in smaller form factors for 8 ports. They are pretty big to hang on the wall, next to a tiny EdgeRouter X :slight_smile:

I don't think it lets you set the management VLAN or to set ports to allow only tagged traffic. But it does work for a home network, keep the main VLAN untagged, PVID 1 and add other VLANs for guest, IoT, work, etc.
A secure connection https or ssh access would be nice too.

I like the Cisco SG250-08. It has ssh cli management, and can be powered by PoE. Has all the mentioned features, is small and stable. And runs some OpenWrt based SDK...

2 Likes

Perhaps older versions had these limitations but current versions with up to date firmware do not have these issues. (I suppose the way you allow "only tagged traffic" is to set the port VID to a nonexistent VLAN. I use 4094)

This post is of some interest regarding consumer orientated device setup.

1 Like

Interesting device, I did look at it but couldn't find one on the used market. New it's $90+ vs. the GS108Tv2 that I got for $30 on CL.

Yeah that's the (ugly) workaround for tagged traffic only. Better switches let you control ingress, they can filter out non-tagged traffic and also traffic with tags that have no business being on that port -- though neither is big deal in a home environment, just saying.

Does it allow you to change the management VLAN though or is it always PVID 1 untagged traffic? I looked through some UI screenshots and didn't see any option to do so.

My understanding is it's always VLAN1 but you can PVID whatever you want. So if you want to put PVID=4094 on all ports, then you'll only be able to admin the switch by tagged packets.

I have not tested this, but I did read about how earlier firmwares would prevent you from modifying vlan1. The firmware released 2018-01-05 for the version 3 hardware fixed this bug, and I believe it's fixed in later versions etc as well. So you can make it so that there are ports that can't be used for management in any way.

You can make certain ports not a member of VLAN1, so then it will exclude packets on vlan1 arriving at that port, I think this also means if the PVID = 1 it will exclude those packets too (should be tested).

1 Like

Interesting. This budget TP-Link might be a good alternative to the more expensive Netgear that now forces you to register to enable most features (at least on some models).

I'm curious whether anyone has any first hand experience with the Zyxel GS1200-8 vs TP-Link TL-SG108E