Jump to content

Recommended Posts

Posted

I am wanting to setup a VLAN on one network switch as per diagram attached. VLAN 999 has a dedicated DHCP server. I have setup the wireless network so all traffic from the BYOD SSID is tagged 999.

 

If I connect using a cable into VLAN 999 I can ping all devices in that VLAN. If I connect using a wireless device I can’t ping.

 

Can anyone help?

Vlan.jpg

Posted

Does the wireless controller have diagnostic tools from within it's interface such as Ping? If so can you ping from the wireless controller to something on VLAN 999?

 

My assumption would be that the wireless system is not correctly tagging traffic onto VLAN 999 when connected to the Guest network. The switch configuration looks correct.

 

Dave

  • Thanks 1
Posted
Might want to TAG both the VLANs on the port that AP is plugged into rather than UNTAG? Had a similar issue when I was setting up VLANs for our BYOD.

 

Good point - will depend on how the wireless controller is configured with the SSID-VLAN associations.

 

Dave

Posted
Thank you for your reply. When I tag port 9 the AP does not provision or connect to the controller. I can also ping from the controller to an IP on Vlan 999.
Posted
Some wireless system you need to make the port that the AP is connected to a trunk port as this is where traffic originates. Really you should see AP's as another switch so you trunk to these it also mean that you can protect the AP's web interface from access by clients.
Posted
I think that the missing factor is what wireless system you are using. They all do their provisioning differently and this is probably where it is falling down.
Posted
Agree with @Ric_, I think this is going to be something specific to the wireless system. Your ProCurve setup looks fine and is the same as I have setup up our ProCurve for VLANs; all my Ruckus APs and the controller are on access ports, I have not had to make them a trunk port.
Posted
From that diagram it suggest that you are not keeping traffic form different SSID on different vlan's is this the case? If I was setting it up I would have each SSID on it own vlan only taking to others at the routing device on the network.
Posted
Let us know what Wireless system you are having issues with. For example I setup Ruckus at last place as well. I tagged multiple SSID's for different vLANS. I did not however tag the ports that the Access points plugged into for vLAN1 the management/default vLAN which I left due to other issues. I had no issues connetcing to the Guest/BYOD networks unless the Access point was plugged into the wrong switch port.
Posted (edited)

I used a wireless system that consisted of the MSM760 and MSM422. The controller need to be in the same vlan as the AP's and that vlan needs DHCP (not the controller). I would configure the port with the AP's to be in untagged ports in the management vlan the same with the controller. You then need to decide which vlan you want to put traffic in form the different ssid's you go to the ssid in the MSM760 to do this. Also beware MSM422 had a tendency to end up in the wrong vlan's. You can tunnel guest traffic back to the controller if you which and then off load it on to the network from there this is where you may need to used a trunked port.

 

In Summary I would expect the MSM AP to port to be

 

Untagged managment

Tagged SSID 1

Tagged SSID 2

 

Also to be clear I mean by trunking I mean 802.1Q Vlan Tagging.

Edited by nicholab
  • Thanks 1
Posted (edited)

Thank you for this. I have setup as suggested. Everything works until i tunnel guest traffic to the controller.

 

Any suggestions?

Edited by rjones
Posted (edited)

You should only use this for the guest traffic or traffic will bottle neck at the controller. To make this work the second controller port has to be configured as the internet port we had issue with the proxy settings so did not use. If it was me I would just create a guest vlan and deliver that to the Layer 3 device and put in place some access list so that only DHCP is allowed form the main network and internet access.

 

If you could give some more details of you gateway it would help.

 

If I remember correctly it is a pain to do access list on the HP kit we had HP third line support onsite helping us with the set up.

Edited by nicholab
Posted (edited)
Thank you for this. If I setup the Internet Port should that be connected to a port on the Guest VLAN? Edited by rjones
Posted (edited)
The internet port needs to be able to talk to the gateway so it should be in the same vlan as the gateway. This may get fun if your have a proxy for web traffic but other protocols talk direct to the gateway. Edited by nicholab
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...