This is a LAN where VLAN 1 is on the first four ports, VLAN 4 is on the next three, and port 8 is the trunk uplink to the router.
VLAN 1 1 2 3 4 5 6 7 8 U U U U _ _ _ T VLAN 4 _ _ _ _ U U U T PVID 1 1 1 1 4 4 4 16 PVID Ingress Filtering D E E E E E E D Acceptable frame types are Admit All In System:Services:Interface Configuration, enable Trust Mode for 8.
Please excuse the non-screenshot style of listing settings for the ports. I think this makes more sense than the web interface.
The acceptable frame type field causes filtering on the frames going into the switch, dropping untagged frames. Ingress filtering drops frames exiting the switch (it’s ingressing from the switch to the port). I leave it disabled on the trunk, because enabling it wouldn’t work; it’s disabled on port 1 “just in case” we need to see broadcast traffic on the switch.
Interface configuration’s trust mode enables forwarding of DHCP traffic from that port.