Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

The NETGEAR Engage Controller and audio video (AV) user interface (UI) provide preconfigured AV profile templates that you can configure and assign to switch ports and VLANs at a site, thereby creating network profiles.

An AV profile template integrates NETGEAR proprietary settings, allowing you to optimize specific audio and video environments. You can use an AV profile template to create one or multiple network profiles. For example, you might use the same AV profile template to set up three network profiles for different areas at the same physical location: one network profile for the lobby, one for the theater, and one for the patio.

These are the essential differences between an AV profile template and a network profile:

  • AV profile template: A preconfigured or custom template with multicast, frame size, QoS, and PTP settings that you can apply to multiple network profiles.
  • Network profile: An AV profile template that you configured and assigned to one or more switch ports, to a VLAN, and as an option, you can create a layer 3 VLAN, if required.

You can use an AV profile template to create one or multiple network profiles. For example, you might use the same AV profile template to set up three network profiles for different areas at the same physical location: one network profile for the lobby, one for the theater, and one for the patio.

When you configure a network profile, you must give the profile a name and assign it to a VLAN. Optionally, you can also add an IP interface to the VLAN, creating a layer 3 VLAN. By default, this is enabled. The network profile applies an AV profile template to that VLAN and specifies how selected ports participate in it.

For example:

  • Untagged (access): The port carries the VLAN untagged. The switch sets the port’s PVID to this VLAN and treats all untagged ingress traffic as part of it.

  • Tagged (trunk): The port carries the VLAN with 802.1Q tags so multiple VLANs can traverse the link.

  • Excluded: The port does not participate in that VLAN.

During the device onboarding process on the Engage Controller, the controller does the following:

  • Pulls all network profiles that are configured on the onboarded fully managed switches at the site.
  • Pushes the collected network profiles to all onboarded devices at the site

When you configure a network profile, you must select an AV profile template on which you base the network profile, give the profile a name, and assign it to a VLAN. You can also assign a color for visual representation. When you add a network profile, you are defining the PTP residency time stamping setting (depending on whether the profile supports this feature), the global site SSID or WiFi settings (depending on whether APs are present in your network), and the ports that participate in the profile. You can also configure routing and related features.

To use the controller to configure and assign a network profile based on an AV profile template:

  1. On your computer, double-click the Engage application icon, or double-click the Engage shortcut. Alternatively, search for Engage, and double-click the Engage application icon.
    The controller application opens and displays a login window. 
  2. In the Login Name field, enter admin as the user name, in the Password field, enter the controller password that you set up the first time that you logged in, and click the Login button.
    The Managed Devices window displays.
  3. If you set up more than one site, from the Site menu, select the site.
    The Edit Network Setup pop-up window displays.
    Do one of the following:
    1. Make no changes to the network setup for the site: Click the Apply button, this applies if the selected network adapter is the correct adapter.
    2. Change the network setup for the site: Click the Apply button, this applies if the network adapter is not correctly set.
  4. Select Site Settings.
    The Network Profiles window displays.
  5. Click the Create New Profile link.
    The Create New Profile window displays the Profile Template section. 
  6. From the Profile Templates menu, select an AV profile template.
  7. To use the network profile as the default VLAN profile for the site, select the Use As Default VLAN Profile toggle so that it displays blue or green and is positioned to the right.
  8. Click the Next button.
    The Create New Profile page displays the Profile Settings section.
  9. In the Profile Name field, enter a name for identification purposes.
    NOTE: You cannot change the selection from the Profile Template menu.
  10. In the VLAN ID field, enter the VLAN ID to which the traffic of the profile must be assigned.
  11. To add a color to the network profile for visual representation, click the box in the Color field, select a color, and click the OK button.
    This unique color indicates what network profile a port supports when you select a port to a network profile in Step 18.
  12. Depending on the AV profile template that you selected in Step 6, you can enable or disable PTP residency time stamping (PTP-TC) for the profile. 
    1. Enable PTP TC: Turn on the PTP residency time stamping toggle so that it displays blue or green and is positioned to the right.
    2. Disable PTP TC: Turn off the PTP residency time stamping toggle so that it displays gray and is positioned to the left.
  13. Click the Next button.
    The following occurs, depending on whether your network includes onboarded access points (APs): 
    1. APs in the network: The Edit SSID pop-up window displays. All WiFi networks that use the same VLAN as the network profile display. Do the following:
      1. In the SSID Name column, select a radio button for an existing SSID.
      2. Click the Apply button.The Wireless Settings page displays.
    2. No APs in the network: The Port Assignment section displays. Go to Step 17.
  14. (The following is a step is for a network with APs.) To keep WiFi disabled for the network profile, leave the WiFi toggle disabled so that it displays gray and is positioned to the left, and then go to Step 16.
    Otherwise, go to the next step.
  15. (The following is a step is for a network with APs.) To enable WiFi for the network profile, do the following:
    1. Click the WiFi toggle so that it displays blue or green and is positioned to the right.
    2. Click one of the following mutually exclusive toggles so that the toggle displays blue or green and is positioned to the right: 
      1. ​​​GLOBAL SITE SSID: Use the global site SSID for the network profile.
        This is the default selection if you enable WiFi. With this selection, the Dedicated SSID for this VLAN toggle displays gray and is positioned to the left.
        NOTE: You can also click the Add MPSK link and add a new WiFi network. 
      2. Dedicated SSID forthis VLAN: Use a dedicated custom WiFi network for the network profile and associated VLAN. You must select the WiFi network from the SSID menu.
        With this selection, the GLOBAL SITE SSID toggle displays gray and is positioned to the left. 
        NOTE: You can also click the Add New SSID link and add a new WiFi network. 
  16. Click the Next button.
    The Create New Profile window displays the Port Assignment section.
  17. Click the graphical display of the switch on which you want to add ports to the network profile.
    The window adjusts to display the switch ports of the selected switch.
    If a switch is already tagged to a network profile, the port displays the unique color you set in Step 11.
  18. To select all ports do the following:
    1. Add all ports as untagged ports: Click the Untag all button.
      All ports are flagged.
    2. Add all ports as tagged all ports: Click the Tag all button.
      All ports are marked with a T (for tagged).
    3. Remove all ports: Click the Remove all button.
      All ports are unflagged.
  19. To select or change individual ports, do the following:
    1. Add a port as an untagged port: Click the port so that it is checked with a checkmark icon.
    2. Add a port as a tagged port: Click the port so that it is marked with a T (for tagged).
    3. Remove a port: Click the port so that it is unchecked.
  20. To add ports on another switch to the network profile, repeat the previous three steps.
  21. When you are done adding ports to the network profile, click the Apply button.
    The Create New Profile pop-up window displays.
  22. Click the Yes button.
    The VLAN Routing Planner pop-up window displays.
  23. Do one of the following:
    1. Do not add routing to the network profile: Click the No button.
      Your settings are saved but routing is not added to the network profile. (You can add routing later.) The profile is added to the table on the Network Profiles window.
      You completed this procedure.
    2. Add routing to the network profile: Click the Yes button.
      Your settings are saved and the profile is added to the table on the Network Profiles window. The VLAN Routing Planner window displays. Continue with the following steps to add routing to the network profile.
  24. To enable routing on all switches that use the network profile, select the Enable Routing on all Switches check box.
  25. To configure the routing, DHCP server, and IGMP options for an individual switch that uses the network profile, click the graphical display of the switch.
    A pop-up window displays.
  26. Select one or more of the following radio buttons:
    1. Enable Routing: Select the radio button to enable routing on the switch. If you already selected routing on all switches in a previous step, the radio button is already selected.
    2. DHCP Server: Select the radio button to configure the switch as the DHCP server in the routing VLAN. Routing must be enabled for the switch to function as a DHCP server. Selecting the DHCP server function also enables routing.
    3. Core Switch: Select the radio button to configure the switch as the core switch in the routing VLAN, which means that the routing, DHCP server, and IGMP querier options are automatically enabled.
    4. IGMP Querier: Select the radio button to configure the switch as the IGMP querier for the network profile. Routing does not need to be enabled for a switch to function as the IGMP querier for a network profile (VLAN).
  27. Click the Apply button.
    The pop-up window closes.
  28. To configure the routing, DHCP server, and IGMP options for another switch, repeat the previous three steps.
  29. When you have configured all switches, click the Apply button.
    A pop-up window displays.
  30. Click the Go to VLAN Routing button.
    The Basic Configuration window displays. Your routing settings, DHCP server setting, IGMP setting, or all of these settings are saved.
  31. You can change the DHCP server or IGMP querier settings.
  32. To save the settings to the running configuration, at the top right of the page, click the Save button.

With the audo video (UI), you can configure a fully managed switch, either as a standalone device or as a managed device in a ProAV network. (The AV UI is also accessible through the controller.)

When you configure a network profile, you can enable or disable PTP residency time stamping (depending on whether the profile supports this feature), give the profile a name and assign it to a VLAN, and add a unique color for visual representation. As an option, you can assign a specific VLAN IP address to the profile and configure a DHCP server on the profile.

NOTE: On an M4500 fully managed switch, you cannot configure a profile with a DHCP server.

To use the AV UI to configure and assign a network profile based on an AV profile template:

  1. Visit the NETGEAR Download Center and download the latest firmware file to the computer that you use to access the AV UI.
  2. Launch a web browser, and in the address field, enter the IP address of the switch.
    For information about finding the IP address of your fully managed switch, see How do I find the IP address of my NETGEAR fully managed switch?.
    The login page displays.
  3. In the Login Name field, enter admin as the user name, in the Password field, enter your local device password, and click the AV UI Login button.

    NOTE: The first time that you log in, no password is required. However, you then must specify a local device password to use each subsequent time that you log in. The password must be 8 to 64 characters in length and must contain at least one uppercase letter, one lowercase letter, and one number. The following special characters are allowed: ! @ # $ % ^ & * ( ).
    You cannot use the word admin in the password.
    To display the password, click the eye icon.

    If you are also managing the switch through the Insight Cloud Portal or Insight app, enter the Insight network password for the Insight network to which the switch is added. The AV UI is not available, as the Insight Cloud Platform and the AV UI are mutually exclusive.

    The Overview window displays.
  4. If you use a switch stack, a menu is present at the top of the page, allowing you to select the Stack Unit. Select the switch to configure.
  5. Select Configure > Network Profiles.
    The Network Profiles page displays.
  6. In the Profile Templates table, to the right of the AV profile template that you want to use, do one of the following:
    1. Preconfigured AV profile template: Click the gear icon.
    2. If you configured a custom AV profile template: Click the 3 dots icon and select Configure.
      The Profile Configure window displays.
  7. Select the ports to add them to or exclude them from the VLAN to which the network profile must apply:
    1. Untagged port: Click the port once. The port is added as an untagged port and is checked with a checkmark icon. To untag all ports, click the Untag all button.
    2. Tagged port: Click the port twice. The port is added as a tagged port and is marked with a T icon (for tagged). To tag all ports, click the Tag all button.
    3. Excluded port: Do not click the port. The port is excluded and is not marked with a green icon or T icon. To exclude all ports, click the Remove all button
  8. Depending on the AV profile template that you select in the previous step, below the graphical display of the switch, you can enable or disable PTP residency time stamping (TC) for the profile:
    1. Enable PTP residency time stamping: Turn on the toggle so that it displays green and is positioned to the right.
    2. Disable PTP residency time stamping: Turn off the toggle so that it displays gray and is positioned to the left.
  9. In the Profile Name field, enter a name for the profile.
    NOTE: You cannot change the selection from the Profile Template menu.
  10. In the VLAN ID field, type the VLAN ID to which traffic of the profile must be assigned.
  11. To add a color to the network profile for visual representation, click the box in the Color field, and select a color.
  12. To assign a specific IP address to the network profile, and as an option, use the network profile as a DHCP server, do the following:
    1. Turn on the Edit VLAN Routing / DHCP Server toggle so that it displays green and is positioned to the right.
      The IP address menu and fields become available.
    2. From the VLAN IP Settings menu, select Static or DHCP client.
      By default, None is selected. If you select Static, you must specify the IP address settings manually and you can also configure the network profile as a DHCP server. (See the following step.)
      If you select DHCP client, the network profile functions as a DHCP client and a DHCP server in your network assigns an IP address to the network profile.
    3. If you select Static from the VLAN IP Settings menu, specify the IP address and subnet mask in the VLAN IP Address and Subnet Mask fields.
    4. To set up the network profile as a DHCP server, from the DHCP Server menu, select DHCP Server, and specify the following settings:
      1. Default Router: The IP address of the router for the DHCP pool. By default, this IP address is the same address as the VLAN IP address, but you can change it.
      2. DHCP Server Pool Start: The start IP address of the DHCP server pool. By default, this IP address is derived from the VLAN IP address and subnet mask, but you can change it.
      3. DHCP Server Pool End: The end IP address of the DHCP server pool. By default, this IP address is derived from the VLAN IP address and subnet mask, but you can change it.
      4. DNS Server 1: The IP address of the primary DNS server.
      5. DNS Server 2: As an option, the IP address of the secondary DNS server.
      6. Search Domain: The domain name for the DHCP server. This name is a fully qualified domain name (FQDN).
      7. Lease Time: The lease time of the IP addresses that the DHCP server assigns. The default is 240 minutes.
  13. Click the Apply button.
    Your settings are saved. The window closes. The Network Profiles page displays again.
  14. To save the settings to the running configuration, at the top of the page, click the Save icon or text.

You can use the Engage Controller to configure multiple VLANS for different types of AV over IP traffic, for example, audio, video, or lightening VLANS.

This scenario shows you how to use the Engage Controller to configure and audio VLAN and a video VLAN.

To use the Engage Controller to configure two VLANS for audio and video:

  1. On your computer, double-click the Engage application icon, or double-click the Engage shortcut. Alternatively search for Engage, and double-click the Engage application icon.
    The controller application opens and displays a login window. 
  2. In the Login Name field, enter admin as the user name, in the Password field, enter the controller password that you set up the first time that you logged in, and click the Login button.
    The Managed Devices window displays.
  3. If you set up more than one site, from the Site menu, select the site.
    The Edit Network Setup pop-up window displays.
    Do one of the following:
    1. Make no changes to the network setup for the site: Click the Apply button.
    2. Change the network setup for the site: Click the Apply button.
  4. Select Site Settings.
    The Network Profiles window displays.
  5. Click the Create New Profile link.
    The Create New Profile page displays the Profile Template section. 
  6. Click the Profile Template menu and select Audio Q-Sys.
  7. Click the Next button.
    The Create New Profile window displays the Profile Settings section.
  8. In the Profile Name field, enter a name for identification purposes, for example: Audio.
    NOTE: You cannot change the selection from the Profile Template menu.
  9. In the VLAN ID field, enter the VLAN ID to which the traffic of the profile must be assigned.
  10. To add a color to the network profile for visual representation, click the box in the Color field, select a color, and click the OK button.
  11. Click the Next button.
    The Create New Profile window displays the Port Assignment section.
  12. Click the graphical display of the switch on which you want to add ports to the network profile.
    The window adjusts to display the switch ports of the selected switch.
    If a switch is already tagged to a network profile, the port displays the unique color you set in Step 10.
  13. To select or change individual ports and assign the port to the audio VLAN, do the following:
    1. Add a port as an untagged port: Click the port so that it is flagged.
    2. Add a port as a tagged port: Click the port so that it is marked with a T (for tagged).
    3. Remove a port: Click the port so that it is unflagged.
  14. To add ports on another switch to the network profile, repeat the previous three steps.
  15. When you are done adding ports to the network profile, click the Apply button.
    The Create New Profile pop-up window displays.
  16. Click the Confirm button.

    You have successfully configured the audio VLAN. Stay on the Network Profiles window to create the video VLAN:
     
  17. Click the Create New Profile link.
    The Create New Profile window displays the Profile Template section. 
  18. Click the Profile Template menu and select Video.
  19. Click the Next button.
    The Create New Profile window displays the Profile Settings section.
  20. In the Profile Name field, enter a name for identification purposes, for example: Video.
    NOTE: You cannot change the selection from the Profile Template menu.
  21. In the VLAN ID field, enter the VLAN ID to which the traffic of the profile must be assigned.
  22. To add a color to the network profile for visual representation, click the box in the Color field, select a color, and click the OK button.
    NOTE: Choose a different color to the audio VLAN.
  23. Click the Next button.
    The Create New Profile window displays the Port Assignment section.
  24. Click the graphical display of the switch on which you want to add ports to the network profile.
    This is the same switch as the one you chose for the audio VLAN.
    The window adjusts to display the switch ports of the selected switch.
    If a switch is already tagged to a network profile, the port displays the unique color you set in Step 10.
  25. To select or change individual ports and assign the port to the video VLAN, do the following:
    1. Add a port as an untagged port: Click the port so that it is flagged.
    2. Add a port as a tagged port: Click the port so that it is marked with a T (for tagged).
    3. Remove a port: Click the port so that it is unflagged.
  26. To add ports on another switch to the network profile, repeat the previous three steps.
  27. When you are done adding ports to the network profile, click the Apply button.
    The Create New Profile pop-up window displays.
  28. Click the Confirm button.

    You have successfully configured the audio and video VLANs.

Audio Video Bridging (AVB) supported on the following switches:

  • M4250 series switches
  • M4350 series switches

802.1AS timing and synchronization is an AVB feature. The IEEE 802.1AS standard specifies the protocol and procedures used to ensure that the QoS requirements are guaranteed for time-sensitive applications, such as audio and video. The IEEE 1588 Precision Time Protocol (PTP) forms the basis of the IEEE 802.1AS standard. PTP specifies a precise clock synchronization protocol that relies on time-stamped packets.
As of firmware version 13.0.4.17 for the M4250 series switches, a license is no longer required for the AVB feature. The M4350 series switches support AVB and do not require a license either.

For more information, see the Engage Controller User Manual at NETGEAR Support.

Precision Time Protocol (PTP, IEEE 1588) is a protocol that enables precise synchronization of clocks with a sub-microsecond accuracy across a packet-based network. PTP version 2 (PTPv2) lets network devices of different precision and resolution synchronize to a grandmaster clock through an exchange of packets across the network.
The switch supports a PTP end-to-end transparent clock that is used in the PTP residency time stamping feature. Most network profiles support PTP residency time stamping. Whether the feature is available, enabled by default, or disabled by default, depends on the network profile. You can enable or disable PTP residency time stamping per network profile. The following network profiles cannot not support PTP residency time stamping and you cannot configure the feature in the controller UI: 

  • Audio-Video AVB 802.1AS (audio video bridging, or AVB) is supported on the M4250 series and M4350 series switches but is incompatible with PTP residency time stamping. AVB is not supported on M4300 series and M4500 series switches.
  • Data
  • Lighting
  • NUCLEUS Converged AV Network
  • Sonos
  • Video
  • Video NDI4
  • Visionary AV Network
     

NOTE: PTP residency time stamping is not supported in a stacking configuration. PTP residency time stamping is not supported on M4300 series models M4300-24X24F, M4300-48X, and M4300-48XF.

For more information, see the Engage Controller User Manual at NETGEAR Support.

If you let the controller onboard one or more access points (APs), you must set up a global site SSID, which is the default WiFi network that is associated with the Default network profile with VLAN ID 1.

You can either add the global site SSID when you set up the controller or add it when you onboard the first AP at a site.

After setup, you cannot delete the global site SSID or change the type of WiFi security, but you can add other SSIDs (WiFi networks) and apply them to the Default network profile and other profiles. Although you cannot make another WiFi network the global site SSID, you do not need to use the global site SSID if its settings do not suit your needs at the site (that is, you can disable WiFi for the global site SSID).

The global site SSID has the following default settings:

  • VLAN: The default VLAN is VLAN 1 with the name Default. You cannot change the VLAN ID.
  • Radio band: The 2.4 GHz radio and 5 GHz radio are enabled, but you can disable one of the radios. 
    If applicable to your AP, you cannot enable the 6 GHz radio for the global site SSID, but you can add another SSID with security settings that can be supported by the 6 GHz radio.
  • Security: The WiFi security is WPA2 - MPSK. You cannot change this type of security, but you can do the following:
    • Change the WiFi password for the global key name.
    • Enable or disable client isolation within an MPSK group and isolation from other groups.
    • Add, change, or remove additional MPSK groups, each consisting of a VLAN ID, key name, password, and isolation definition.
Last Updated:12/18/2025 | Article ID: 000068417

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email