Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

To separate guest and production networks, you can segment a network and create two Layer 3 networks. In this way, you achieve complete separation between both networks, while each network can have full access to the Internet.

When you create VLANs, be sure to use numbers and names that clearly identify each VLAN and its purpose. The scenario described in this example is as follows:

  • Existing default VLAN 1: 192.168.1.0/255.255.255.0
  • Example VLAN 5 as Guest: 192.168.5.1/255.255.255.0
  • LAN 11 port on the Smart Switch: connected to a computer in VLAN 5
  • LAN 1 port on the PR60X Pro Router: connected to the LAN 1 port on the Smart Switch

In this example we are using a NETGEAR PR60X Pro Router and a NETGEAR Smart Switch with a Smart UI. For information about the same procedure for a Smart Switch with a traditional UI, see How do I set up one or more VLANs between a NETGEAR PR60X Pro Router and a Smart Switch with a traditional UI?. However, you can use any router and Layer 2 switch that support VLANs. Consult the documentation for your router and switch.

To set up VLAN 5 with the name Guest on the PR60X Pro Router and Smart Switch with a Smart UI, and assign ports to the VLAN:

Step 1. Log in to the PR60X Pro Router:

  1. Launch a web browser from a computer or mobile device that is connected to the router network.
  2. In the address field of your browser, enter https://www.routerlogin.net.
    The login page displays
  3. Your browser might display a security warning. For more information, see What do I do if I my browser displays a security message?
  4. Type one of the following passwords:
  • Type the router user name and password. The user name is admin.
    The password is the one that you specified when you set up the router. The user name and password are case-sensitive.
  • If you are managing the router through the Insight Cloud Portal or Insight app,
    type the Insight network password for the Insight network location to which the router is added.

The Dashboard displays.

Step 2. On the PR60X Pro Router, create VLAN 5 with the name Guest and assign the VLAN to LAN port 1:

  1. Select LAN > VLAN Settings.
    The VLAN Settings page displays.
  2. Click the Add VLAN Profile button.
    The Add New VLAN Profile pop-up window displays.
  3. In the VLAN ID field, type 5.
  4. In the VLAN Name field, type Guest.
  5. Keep the Inter VLAN Routing toggle gray and position to the left.
    Traffic between this VLAN and other VLANs on the router is restricted.
  6. In the IP Address field, type 192.168.5.1.
  7. In the Subnet Mask field, type 255.255.255.0.
  8. In the DHCP Server section, click the Status toggle so that it is blue and positioned to the right.
    The DHCP server is enabled and assigns an IP address to the devices on this VLAN.
  9. In the Start Address field, type 192.168.5.20 as the start address for the DHCP server.
  10. In the End Address field, type 192.168.5.100 as the end address for the DHCP server.
  11. Click the Apply button.
    Your settings are saved. The new VLAN profile is added to the VLAN Settings page.
  12. Remain on the same page but scroll down to the Assign VLANs to Wired Ports section at the bottom of the page.
  13. For VLAN 5, select Tagged in the LAN 1 column.
    The LAN 1 port is already an untagged member of VLAN 1, so for VLAN 5, the LAN 1 port must be a tagged member.
  14. Click the Apply button.
    Your settings are saved.

Step 3: Log in to the Smart Switch:

  1. Connect your computer to the same network as the switch.
    You can use a WiFi or wired connection to connect your computer to the network, or
    connect directly to a switch that is off-network using an Ethernet cable.
  2. Launch a web browser.
  3. In the address field of your web browser, enter the IP address of the switch.
    If you do not know the IP address, see How do I discover a NETGEAR Smart Switch.
    The Device Admin Password page displays.
  4. Enter one of the following passwords:
  • Enter your device admin password.
  • If you previously managed the switch through the Insight app or Cloud portal,
    enter the Insight network password for the last Insight network location.
  1. Click the Login button.
    The Dashboard page displays.

Step 4. On the Smart Switch, create VLAN 5 with the name Guest:

  1. Select Switching > VLAN > VLAN Management.
    The VLAN Management page displays.
  2. Click the Add New button (or the + button).
    The Add VLAN Configuration pop-up window displays.
  3. In the VLAN ID field, type 5.
  4. In the VLAN Name field, type Guest.
  5. Click the Save button.
    Your settings are saved.

Step 5. On the Smart Switch, add port 11 to VLAN 5 and remove port 11 from VLAN 1:

  1. Select Switching > VLAN > VLAN Configuration (Basic).
    The VLAN Configuration (Basic) page displays.
  2. From the VLAN ID menu, select 5.
  3. Select port 11 by clicking the port until it displays blue.
  4. Mark port 11 as untagged by clicking the Untag Port button. The port displays a "U."
  5. Click the Apply button.
    Your settings are saved.
  6. From the VLAN ID menu, select 1.
  7. Select port 11 by clicking the port until it displays blue.
  8. Remove the port from VLAN 1 by clicking the Clear button.
    Your settings are saved.

Step 6. On the Smart Switch, change the PVID for port 11 to 5 (for VLAN 5):

  1. Select Switching > VLAN > VLAN Configuration (Advanced).
    The VLAN Configuration (Advanced) page displays.
  2. Select the check box for port 11.
  3. Click the Edit button.
    The Edit PVID Configuration pop-up window displays.
  4. In the PVID field, type 5, which is the ID of the VLAN to which untagged or priority-tagged frames
    received on interface 11 must be assigned.
  5. Click the Save button.
    Your settings are saved.

Step 7. Test that both VLANS are online and segregated:

  1. Connect a cable from a switch port in VLAN 1 to a computer that must manage the switch in VLAN 1.
  2. Connect a cable from switch port 11 to a computer that must be connected in Guest VLAN 5.
  3. Confirm that the computers are connected to the Internet by navigating to any website or pinging the two remote computers.
    If a computer cannot connect, double-check that you followed each step correctly and that the cables are in the correct ports.
  4. Confirm that the VLANS are segregated by using a command prompt or terminal to send a ping packet from the computer that is
    connected to a port in default VLAN 1 to the computer that is connected to port 11 in the guest VLAN. The ping should time out because the VLANs are segregated.
Last Updated:07/11/2025 | Article ID: 8898

Our team is here to help!

Phone
Chat
Email