This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Create VLAN for WiFi Access Points

Hi everyone, 

I'm trying to create a VLAN for some Ubiquiti UniFi access points and I just can't seem to get it working correctly. 

In my interface for the access points I assigned them a VLAN ID of 2, as shown here: http://screencast.com/t/s8VuPEud7

In my Cisco SG-500 switch I created a VLAN as shown here: http://screencast.com/t/wcAMNUwJ 

I set all the ports to Trunk and accept all frames as shown here: http://screencast.com/t/TO0EcTH6iY 

Since the AP that is plugged into the port of the switch will be passing frames with the default VLAN of 1, and also a VLAN of 2. I left the port untagged for the VLAN 1 as shown here http://screencast.com/t/fjVBw9gcal and then the VLAN ID 2 is tagged on the port the AP is connected to as well as the port to the machine running Sophos XG is connected to, as shown here: http://screencast.com/t/MdJhozsoI 

Here you can see those ports and the VLAN memberships: http://screencast.com/t/b9P8sWJ1m 

In Sophos I then created a new Zone for the guests as shown here: http://screencast.com/t/IRTPRWYrsG 

I then created a new VLAN interface and assigned it an ID of 2, then assigned it to the zone I created in the previous step, as shown here: http://screencast.com/t/tA77JnCRdFDt

Finally, I created a DHCP service and selected the VLAN interface that I created from the previous step, as shown here: http://screencast.com/t/IA5yZnYtwP 

I thought that's all I needed, but it doesn't appear to be working. My devices are unable to obtain an IP address when the connect to the AP. I'm sure I've missed a step or did something incorrectly. Any assistance would be greatly appreciated. 

Thanks,
Christopher



This thread was automatically locked due to age.
Parents
  • Hi guys

    I'm interested in hearing if any of you got this working, as i have planned to do exactly the same thing at work.
    Ubiquiti AP, with SSIDs on different VLANS for corporate/guest access seperation. (Going through HP Procurve switches though).

    Anything to look out for?

    I am hoping to be able to tag frames with VLAN ID from the UBT AP's, and be able to identify them and apply proper rules on the XG firewall based on VLAN ID.

    Hope you have some good advice...


    - Martin

Reply
  • Hi guys

    I'm interested in hearing if any of you got this working, as i have planned to do exactly the same thing at work.
    Ubiquiti AP, with SSIDs on different VLANS for corporate/guest access seperation. (Going through HP Procurve switches though).

    Anything to look out for?

    I am hoping to be able to tag frames with VLAN ID from the UBT AP's, and be able to identify them and apply proper rules on the XG firewall based on VLAN ID.

    Hope you have some good advice...


    - Martin

Children
  • I haven't had time in the last while to play with it after the latest firmware update, but earlier when did play around with it, this is my experience:

    Port DHCP = 10.100.x.x

    XG Gateway = 10.100.0.1

    VLAN10 = 10.10.x.x (XG DHCP)

    VLAN20 = 10.20.x.x (XG DHCP)

    Issue encountered was when I checked my switches they all registered the VLAN tags being properly applied, but the XG would not assign an IP in the proper range (or at all).

    I tried a simple setup of AP-->Unmanaged Switch --> XG
    No Luck, still no IP assigned.

    I changed my AP to not assign a VLAN tag then everything flowed through fine with a 10.100.x.x ip assigned. As soon as I add a VLAN tag, then no ip gets assigned and therefore no connection to internet or other network resources.

    Somehow the XG was just not playing nice with VLAN tagging. I tried Sophos Tech support but as I am not using Sophos APs they kept saying it must be the switch (unmanaged) or my APs.

    I am hoping to give it another go when I have some time again.