Change Management VLAN ID on WAX610D disrupts SSID in VLAN1
For an existing network I'm implementing a bunch of WAX610D(30 pieces) with controller on Flex 500. On the Flex 500 I've configured VLAN88. There are 2 SSID's:
- Internal LAN with VLAN tag 1
- Guestnetwork with VLAN tag 88 with only internet access
So far so good everything works, guestnetwork works fine. But to save IP addresses and to make it a bit cleaner, I want to put the Access Points themselves on a different VLAN. So I created VLAN99 with DHCP enabled.
When I change Management VLAN ID on the access points to 99, they get the IP from VLAN99, so that's fine and I can access them. So security policy on firewall is ok. My Guestnetwork on VLAN88 also keeps working. But the SSID for internal LAN which is on VLAN1 then fails to work. Clients are not able to receive IP adresses and also with static IP address I have no network access anymore.
I thought then, I have to turn off "As Native VLAN", after that the whole party is over and I'm not able to access and the network and the access point.
In my eyes I thought this would be simple, but it turns out I'm out of options and don't know how to resolve the problem.
Keep in mind that I want to keep the default network with VLAN1, I don't want to change the whole network just for just management IP addresses.
Any idea's?
0
Accepted Solution
-
Hi Neil,
The reason why devices fail to get IP when connecting to VLAN1 SSID is about the misconfiguration on the VLAN Tag.
By default, AP(and all other network devices) use VLAN1 as management VLAN, a the traffic in VLAN1 is untagged(general default setting), meanwhile traffic in other VLAN (e.g.: VLAN88) should be tagged with corresponding ID, so that each device is able to process the VLAN traffic correctly.
Back to the issue itself, when you change the management VLAN of AP into VLAN99, In order to let AP correctly process the traffic within the VLAN 1 SSID(wireless network) and the Ethernet, you also need to set the traffic in VLAN1 to be tagged with ID=1, from the switch to AP.
As for the least effort configuration change, please set the port to be tagged out VLAN1 on the switch. On Zyxel Switch, the directory is at [Advanced Application > VLAN > VLAN Configuration > Static VLAN Setup > Select VID=1 > Set ports where AP connects as Tx Tagging]
Best Regards,
Richard0
All Replies
-
Hi Neil,
The reason why devices fail to get IP when connecting to VLAN1 SSID is about the misconfiguration on the VLAN Tag.
By default, AP(and all other network devices) use VLAN1 as management VLAN, a the traffic in VLAN1 is untagged(general default setting), meanwhile traffic in other VLAN (e.g.: VLAN88) should be tagged with corresponding ID, so that each device is able to process the VLAN traffic correctly.
Back to the issue itself, when you change the management VLAN of AP into VLAN99, In order to let AP correctly process the traffic within the VLAN 1 SSID(wireless network) and the Ethernet, you also need to set the traffic in VLAN1 to be tagged with ID=1, from the switch to AP.
As for the least effort configuration change, please set the port to be tagged out VLAN1 on the switch. On Zyxel Switch, the directory is at [Advanced Application > VLAN > VLAN Configuration > Static VLAN Setup > Select VID=1 > Set ports where AP connects as Tx Tagging]
Best Regards,
Richard0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight