# How to monitor VLANs on Linux (Debian with Network Manager)

This document provides a step-by-step guide on configuring VLANs on a Debian Linux (running Domotz Pro Agent) system using Network Manager and monitor them using the Domotz Pro Agent.

## Prerequisites

- A Debian Linux system with root or sudo privileges.
- Domotz Pro Agent from Snap is installed and activated on the system.
- Network Manager installed and running on the system.
- **Important:**Ensure that the PC (running Debian) or VM is connected to a properly configured trunk port on the switch, with the VLANs you plan to define on the OS allowed on that trunk. If the trunk port is not correctly configured, the Domotz agent will be unable to discover devices on those VLANs. If the system is a VM hosted on Hyper-V, please refer to this guide to configure VLANs: [**Configuring VLANs on Hyper-V**](https://help.domotz.com/tips-tricks/configure-vlans-on-hyper-v/)

## Step 1: Install Necessary Packages

Before configuring VLANs, please run the below commands to ensure that the required packages are installed:
`sudo apt-get update
sudo apt-get install network-manager vlan`
The VLAN package is required for VLAN tagging, and _network-manager_ provides the interface for managing network connections.

## Step 2: Ensure the Main Interface is Managed by Network Manager

Before proceeding with VLAN configuration, it is important to ensure that the main network interface (e.g., `eth0`) is managed by the _network-manager_. If the interface is unmanaged, Network Manager will not be able to configure VLANs on it.

### Check the Interface Management

To list managed interfaces please run:

`nmcli device status`

The output should list the main interface (e.g., eth0) with the status connected, disconnected, or unavailable, indicating that Network Manager is managing it. If the status shows as unmanaged, you need to configure Network Manager to manage the interface.

### Enable Management (if needed)

If the interface is unmanaged, follow these steps:

1. Edit the Network Manager configuration by modifying the below file:

`sudo nano /etc/NetworkManager/NetworkManager.conf`

1. Modify or add the following lines to ensure that all interfaces are managed:

`[main]`

`plugins=ifupdown,keyfile`

`[ifupdown]`

`managed=true`

1. Run the below command to restart Network Manager to apply the changes:

`sudo systemctl restart NetworkManager`

1. To verify the interface is now managed, run:

`nmcli device status`

Ensure that the main interface (e.g., eth0) no longer appears unmanaged.

## Step 3: Create a VLAN Interface Using Network Manager

You can create a VLAN interface using the command line utility (`nmcli`).

### Using nmcli (Command Line)

1. **Identify the parent interface**: Determine the name of the physical network interface that will be the parent of the VLAN interface. This is typically `eth0`, `ens33`, or similar.   Run the below command and Identify the interface you want to use for VLAN tagging:   `ip link show`
2. **Create the VLAN interface**: Use the following command to create a VLAN interface. Replace `eth0` with your interface name, `100` with the VLAN ID, and `VLAN100` with a descriptive name for the VLAN interface.   `sudo nmcli connection add type vlan con-name VLAN100 dev eth0 id 100`
3. **Assign an IP address**: If you want to assign a static IP address to the VLAN interface, please run the below commands and don’t forget to change the IP address with your desired IP address of the VLAN. You can skip `ipv4.gateway `if you don’t want to allow inter-VLAN communication:   `sudo nmcli connection modify VLAN100 ipv4.addresses 192.168.100.10/24   sudo nmcli connection modify VLAN100 ipv4.gateway 192.168.100.1   sudo nmcli connection modify VLAN100 ipv4.method manual   `   - **For a DHCP configuration:**   `   sudo nmcli connection modify VLAN100 ipv4.method auto   `
4. **Bring up the VLAN interface**:   `sudo nmcli connection up VLAN100   `

## Step 4: Verify the VLAN Configuration

After creating the VLAN interface, you should verify that it has been configured correctly. Follow the below steps to verify the settings:

1. **Restart Network Manager Service**:   `   sudo systemctl restart Network Manager`
2. **Check the interface status**:   `ip link show   `Look for a new interface named similarly to `eth0.100` (if your parent interface was `eth0` and VLAN ID was `100`).
3. **Check the IP address**:   `ip addr show eth0.100   `   Ensure the correct IP address is assigned to the VLAN interface.
4. **Ping to test connectivity**:   `ping -c 4 <VLAN_Gateway_IP>   `   Replace `<VLAN_Gateway_IP>` with the gateway address of your VLAN network.

## Step 5: Persistent Configuration

Network Manager automatically makes VLAN configurations persistent across reboots. No further action is needed.

## Step 6: Restart The Domotz Pro Agent Service

Restart the Domotz Pro Agent Service by running the following command:
`
sudo snap restart domotzpro-agent-publicstore`

## Step 7: Verify The Network Settings on the Domotz Portal

Now please log in to your Domotz portal (**portal.domotz.com**), select your agent, navigate to the **Inventory** menu, and click on the **Sites** tab. Then, select **Network Setup** for the chosen agent. You should see the VLAN interfaces detected by the Agent. The image below is for reference only; in your case, you should see the VLAN interfaces configured in Step 3.

Viewing and managing site inventory in the dashboard.

1. Navigate to the Inventory section in the sidebar menu to access site inventory options.

2. Ensure the "Sites" tab is selected at the top to display site-specific data.

3. The top bar shows totals and status indicators, such as the number of offline sites and those with security issues.

4. In the main table, observe columns for Site Name, Status, Online Devices, Important Offline Devices, Persistent Devices, Monitoring Mode, Network Setup, and Site Integrations.

5. Use the "Network Setup" column to see and manage attached networks for each site by clicking on the corresponding links.

6. Filters and search options are available to sort and locate specific sites or statuses.

Network Setup and Attached Networks Overview

1. The "Network Setup" section is displayed with an "Online" status indicator.
2. Under "Attached Networks," a description explains that Layer-2 networks detected by the Domotz Agent are listed based on their connection to the host NIC. Device discovery on these networks is carried out via MAC addresses.
3. Specific networks are labeled, including "eth0.103," "eth0.252," and "eth0.253," indicating their respective network segments. Use these identifiers to recognize network interfaces and manage network resources effectively.

## Step 8: Troubleshooting

- **Interface not showing**: Ensure the VLAN module is loaded.   `sudo modprobe 8021q`
- **Check logs for errors**:   `journalctl -xe | grep NetworkManager`
- **Verify network connectivity** by checking routing tables and pinging other devices within the VLANs configured.
- **If the Domotz Agent is not discovering devices on new VLANS:**  - Please make sure the system is connected to the **Trunk** **Port**on the switch and the configured VLANS are allowed in the trunk port configuration. - Please check the configuration files of VLAN interfaces at: `/etc/NetworkManager/system-connections`  - In the `system-connections` directory, you will find configuration files for the VLAN interfaces of the configured VLANs, as shown below:   Listing Network Manager system connections on Linux. 1. Open a terminal and execute the command: `ls` in the `/etc/NetworkManager/system-connections` directory. 2. Review the listed connection files. Examples include `ens3.nmconnection`, `vlan-ens3.20.nmconnection`, `vlan-ens3.30.nmconnection`, and `Wired connection 1`. 3. Each file corresponds to a network connection configuration. Select the appropriate file to view or edit the configuration settings. - Please open these configuration files with a text editor:` `   `sudo nano vlan-ens3.20.nmconnection   ` - Verify under the `[vlan]`, flag value is set to `1`, if it is `0,`please set it to` 1,` and save the file. Similarly, check other VLAN configuration files and modify the flag value if needed.    Viewing a VLAN configuration file in a Linux terminal. 1. The terminal shows the file path: `/etc/NetworkManager/system-connections/vlan-ens3.30.nmconnection`. 2. Under `[connection]`, key-value pairs are listed, including:    - `id=vlan-ens3.30`    - `uuid=...`, followed by a long UUID.    - `interface-name=ens3.30` 3. Under `[ethernet]`, a `mac-address-blacklist=` entry is present but empty. 4. Under `[vlan]`, several settings are visible:    - `egress-priority-map=` and `ingress-priority-map=` are present but empty.    - `flags=0`    - `id=30`    - `parent=ens3` 5. The `[ipv4]` section lists:    - `address1=192.168.30.7/24`    - `dns-search=` followed by a space.    - `method=manual` 6. The `[ipv6]` section has:    - `addr-gen-mode=stable-privacy`    - `dns-search=` followed by a space.    - `method=auto` - Restart the Network Manager service to apply the changes:`   sudo systemctl restart network-manager` - Restart the Domotz Pro agent service:`   sudo snap restart domotzpro-agent-publicstore` - (Optional) reboot the system`:   sudo reboot` - If the issue persists after following the above steps, please contact Domotz support at **support@domotz.com** and include screenshots of the steps you completed.
