Wireless Clients List in DHCP Table Using Mgmt Vlan Interface
I have a USG Flex 700, GS1920-24 HPv2, and a Mist AP-41 on my network. I have 5 Vlans with Mgmt Vlan being 1 and 10,20,40,50 as the others. Each Vlan has a corresponding SSID on the Access point.
My problem is when I connect any new wireless clients to the network, they always seem to connect under the Mgmt Interface on the firewall instead of the correct interface on the firewall corresponding to the Vlan on the switch and AP. I show 20-30 IP/MAC bindings on the interface for the mgmt instead of only 2 (switch/ap). I used to have it setup router-on-a-stick method but have enough ports that I set it up on individual ports instead for better throughput and control.
I do not have vlans setup on the firewall and have each port setup as a /24 for each of the 5 vlans. It all works ok, but it seems like it could be better if the non-mgmt clients would connect to the correct interface, it would be smoother.
What have a done wrong? Should I have used Vlans on the firewall and if so how?
Thank you,
Jay
All Replies
-
Hi @jayd691 ,
Please refer to the articles below for instructions on configuring VLANs on the USG Flex 700 and GS1920-24 HPv2.
USG Flex 700:
GS1920-24 HPv2:
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP!
0 -
Thank you for the assistance Zyxel_Judy.
I do know how to create the actual interface on the firewall and switch, but I am unsure of how to setup the firewall for the vlans.
- What do I use for the base port for the vlans?
- Do I create a network just for the firewall itself and then use that for the base port for all the vlans?
- Do I need to combine the multiple ports together LAG style and then use a separate network for each base port?
These are my major issues with adding vlans on the firewall. Right now, I just use a /24 subnet as a port on the firewall which then I have connected to the corresponding vlans on the switch and the AP which is LAG to the switch router-on-a-stick style as there are only 2 ports on the AP.
0 - What do I use for the base port for the vlans?
-
I seem to not get how you have done this without VLANs so its down to your switch setup for the VLAN to then untag to a given port on Flex 700?
So if port 24 was the AP and ports 1-5 to Flex 700 ports
VLAN 1 ports 24 and 1 untag ports 24,1 PVID 1 ports 2-5 forbiddenVLAN10 port 24 tag port 2 untag port 2 PVID 10 ports 1, 3-5 forbidden
VLAN20 port 24 tag port 3 untag port 3 PVID 20 ports 1-2, 4-5 forbidden
and so on?0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight