Omada SSIDS + VLAN Tagging issue

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Omada SSIDS + VLAN Tagging issue

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Omada SSIDS + VLAN Tagging issue
Omada SSIDS + VLAN Tagging issue
2022-12-27 05:44:37 - last edited 2022-12-27 05:46:23

Hello, (Hardware below)

 

I am attempting to set up 2 WLANs on my AP, and both of them are assigned to 2 different VLAN's via the VLAN ID, butclients are able to communicate across VLANs. 

Looking online, it seems pretty simple to assign a VLANs to ports on the switch, and then that will deter any communication across VLANs. The problem here is that the AP only uses one port, and I assumed that assigning a VLAN ID while creating the WLAN will stop traffic between two separate VLANs. In the documentation, it clearly states:

 

"VLAN: To set a wireless VLAN for the wireless network, enable this option and set a VLAN ID from 1 to 4094.

When enabled, traffic in different wireless networks is marked with different VLAN tags according to the configured VLAN IDs. Then the EAPs work together with the switches, which also support 802.1Q VLAN, to distribute the traffic to different VLANs according to the VLAN tags. As a result, wireless clients in different VLANs cannot directly communicate with each other."


Im not sure if it's a problem with the "profiles" tab under LAN, because I have created new profiles and tagged the network, also enabled the VLAN interface on the switch and still it cross communicated. 

Setting up a firewall rule in my opinion to block the traffic makes absolutely no sense, because then the wireless clients in separate VLANs on the same AP is an absolutely useless concept in the OMADA ecosystem. 

 

Is anybody out there able to block communication across VLANs between two different SSIDS on the same AP that only uses ONE port? Please let me know how you did it. 

Thanks. 

Hardware: 

ER7206 v1.0

TL-SG2008P v3.0

EAP653(US) v1.0[Custom]

  0      
  0      
#1
Options
1 Reply
Re:Omada SSIDS + VLAN Tagging issue
2022-12-27 08:48:41

  @Domada 

I'm pretty new to this but I had to use ACL to deny communication between 2 SSID.

 

1x ER-7206 1x C200 2x EAP245 1x SG2008P
  1  
  1  
#2
Options