This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Maybe a bug in separate zone networks in 17.06MR6?

We have a XG210 deployed at a customer 2 months ago, firmware version is 17.06 MR6.

We have configured 3 wireless networks, internal (bridge to ap), guest (separate zone), sonos (separate zone). The reason for creating 2 separate networks was that the web filter and client isolation is enabled for guest devices and in sonos there are only several SONOS audio, no web filtering and no client isolation active.

All wireless networks and AP(15)s are part of the same Access Point Group, in the networks only 2.4GHz is selected. Internal is WPA2 Enterprise, the other two WPA2 personal. Fast transition is only active on internal, client isolation only on guest.

 

The customer reported a strange behaviour. As said he has several SONOS audio devices which he controls via iPhone or Android pad. It seems that the controlling device only sees the SONOS devices that are connected to the same accesspoint, but not all SONOS devices in the wireless network. Unfortunately I wasn't able to troubleshoot it onsite, only remote until now.

Has anyone discovered similar problems with a separate zone network?
My original plan was enabling Fast transition for the sonos network, that was first disabled but made no difference.



This thread was automatically locked due to age.
Parents Reply Children
  • I was able to solve this problem. LAN-to-LAN was no problem, but WLAN-to-WLAN.

    The access points in LAN broadcasting the separate zone SSIDs needed a firewall rule, that covered the traffic from the separate zone WiFi to the same separate Zone WiFi. After setting that rule for testing I realized, that it got hits and afterwards the SONOS app was able to reach the devices on other APs.

    For me a subnet-internal rule only makes sense, when bridging is active but OK, never stop learning... ;-)
    I furthermore think of the accesspoints beeing a big bridged interface of n accesspoints ending on one wlanxyz interface on the XG and so the firewall rule makes sense again.