Wifi on management vlan

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Wifi on management vlan

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Wifi on management vlan
Wifi on management vlan
2022-12-21 17:59:05

Good evening all

 

today i transferred my home network from several switches, ap's etc from several manufacturers to my test setup tplink omada

oc200, el7206, 4x managed switch and 3 accespoints.

went really smoothly, all working fine, except for 1 minor issue.

 

in my previous setup i had on my managedswitch in my study 1 port for management vlan 1, connected to my pc for management

also on my wifi network i had a management ssid, with 2 whitelisted ip adresses of tablets, so i could manage from my chair in my living room

 

now all my wifi is working on the same ssid's, except for the management ssid in vlan 1. Get no ip. When changing vlan it will work.

 

is this done on purpose, so you could only get in the controler by lan or by tplink cloud, or am i missing something?

i have read some issues about this in another forum, but that gave me no solution.

 

if it is possible i like it, otherwise i will use the tp link cloud. But sometimes there is this urge to get it done how i thought i could do it.

 

 

  0      
  0      
#1
Options
6 Reply
Re:Wifi on management vlan
2022-12-22 09:05:42

  @Pksparks Could you provide more information.  Specifically, is the management VLAN the Native Network (untagged) for the link between switch and AP?  Does the management SSID in WLAN Settings have the VLAN check box marked and a VLAN number placed in? 

  0  
  0  
#2
Options
Re:Wifi on management vlan
2022-12-22 22:04:38

  @JoeSea  to be short, on all your questions it is a yes.

and i am not to annoyed by it, if it is not possible, i even think it is a good security feature.

so i can also manage via tp link cloud.

 

so  i tried all settings, but as soon as i change away from managment vlan 1, my tablet gets good wifi on that ssid,and an ip adres.

  0  
  0  
#3
Options
Re:Wifi on management vlan
2022-12-22 22:31:46

  @Pksparks 

 

It should work as you intended. I've just tried it on my own network. I've switched form my usual SSID to the SSID associated with VLAN1 and it does work. So no, it is not some security feature.

Kris K
  0  
  0  
#4
Options
Re:Wifi on management vlan
2022-12-24 22:27:47

  @KJK  thanks for the reply and testing. When i have time, i will try again. I guess i did something wrong in a setting.

i will try first in changing working vlan ssid into management ssid.

i let you know, but can take some time as of the time of year.

  0  
  0  
#5
Options
Re:Wifi on management vlan
2022-12-25 08:19:40 - last edited 2022-12-25 08:20:21

  @Pksparks Hi, I had to be away a couple of days.

What I've learned under Omada is, the SSID that is associated with the wired native network cannot have the VLAN option active.  To elaborate, in Omada the data on the native network on a switch port (regardless of VLAN number) has no VLAN information when sent out of the port.  When the AP receives the untagged packet, the AP does not know to assign a VLAN to the packet.  So the SSID that is intended for the untagged network cannot have a VLAN option on, since the AP doesn't see a VLAN with that number from the switch.  Going the other way, the AP will apply the VLAN tag, send it to the switch, and the switch will understand it belongs to the correct VLAN, since Omada does incorporate protection for double tagged packets.

 

Two solutions I would suggest.  Disable the VLAN option for the SSID that is to be connected to the native network.  Or have all SSIDs on a VLAN that is not the native untagged network.

 

I have had a change request in for a couple of months to add tagging for the switch port native network, since TPLink switches in standalone can tag outgoing packets for the native network.

  1  
  1  
#6
Options
Re:Wifi on management vlan
2022-12-25 10:35:13

  @Pksparks 

 

I don't think associating the management VLAN with another SSID will make any difference. I think the key is to mark the port the AP is connected to as TAGGED in the management VLAN, just like any other VLAN. Just to clarify, my switch is not under Omada, but the AP is.

Kris K
  0  
  0  
#7
Options