<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSIDs and VLAN Problem in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484890#M296247</link>
    <description>&lt;P&gt;Are you sure that there is an issue? If you are testing with the same laptop or device make sure that you are looking at the SSID  specific Clients for the past two hours or else you may be fooled into thinking that the wrong subnet is in use... The first time I ran across this with Meraki in 2016, I nearly had a heart attack thinking my guest segment was leaking into my corp VLAN... Why does this happen? The same client accessing multiple segments. If you don't narrow the search it will give you the first record it finds in the client table... So host name searches and MAC searches requires very specific filtering. Also, patience with allowing the cloud to update with the data also helps. i would also move your store segment of off VLAN 1 and onto a differing VLAN as the use of VLAN 1 could cause all sorts of unintended behavior.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TBHPTL_0-1692031062341.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271937iA68869F0F80C799B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Aug 2023 16:41:35 GMT</pubDate>
    <dc:creator>DainBrammage</dc:creator>
    <dc:date>2023-08-14T16:41:35Z</dc:date>
    <item>
      <title>SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484883#M296240</link>
      <description>&lt;P&gt;I tried typing out the entire setup and it turned into a convoluted mess, so this is the essence of what the problem is:&lt;/P&gt;&lt;P&gt;MX67&lt;/P&gt;&lt;P&gt;Port 3 = Store Network - VLAN 1 - Trunk Port - 192.168.101.0/24 - Store SSID&lt;/P&gt;&lt;P&gt;Port 5 = Office Network - VLAN 149 - Access Port - 192.168.0.0/24 - Office SSID&lt;/P&gt;&lt;P&gt;x6 MR33 APs&lt;/P&gt;&lt;P&gt;6 SSIDs - 1 Store / 1 Office / 1 Employee / 3 Guest (varying restrictions) - Employee and Guests are in isolated networks.&lt;/P&gt;&lt;P&gt;I want all SSIDs to broadcast on all APs, however, when a device connects to the Store SSID on an AP connected to/through port 5, it gets an IP in the Office range. &lt;/P&gt;&lt;P&gt;The 2 networks should be completely independent as I segregated them by VLANs, however, sharing the APs shouldn't be a problem as far as I know, but maybe I'm wrong.&lt;/P&gt;&lt;P&gt;I thought the solution was to set Port 5 to a trunk port with the Native VLAN as 149, but that didn't work. The IPs were still from the wrong range, it's like the IPs are sticky to whatever they get, even after refreshing them. This seems like it should be really simple, but I'm clearly missing something.&lt;/P&gt;&lt;P&gt;Thanks in advance for any guidance and help.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 04:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484883#M296240</guid>
      <dc:creator>WhoIsThis</dc:creator>
      <dc:date>2023-08-12T04:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484884#M296241</link>
      <description>&lt;P&gt;It's difficult to get an idea of your exact configuration from above but typically you would want to do a trunk port between MX and MR, allowing all of the vlans of your ssid's. The native vlan should be either an unused vlan or the MR management vlan (depending on if you've manually tagged the management vlan on the MR's or not).&lt;/P&gt;&lt;P&gt;Finally, your ssid configuration should do the actual vlan tagging.&lt;/P&gt;&lt;P&gt;Can you give us some screenshots of the port config on the MX and the ssid config on the MR?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 04:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484884#M296241</guid>
      <dc:creator>Brash</dc:creator>
      <dc:date>2023-08-12T04:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484885#M296242</link>
      <description>&lt;P&gt;I think this is what you're asking for. If not, I can take some more.&lt;/P&gt;&lt;P&gt;The config for both SSIDs are the same, less the WPA key.&lt;/P&gt;&lt;P&gt;The trunk port makes sense, and I did try that, but like I said originally, it's like the IPs are too sticky, they stay with the device regardless of which network they are connected to.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MX Port Config" style="width: 844px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271930i63449574ADFC542E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;MX Port Config&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSID Config 1" style="width: 992px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271931i7B8F16DBCE241E95/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;SSID Config 1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SSID Config 2" style="width: 999px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271934i8E0B31177B21F848/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;SSID Config 2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 05:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484885#M296242</guid>
      <dc:creator>WhoIsThis</dc:creator>
      <dc:date>2023-08-12T05:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484886#M296243</link>
      <description>&lt;P&gt;You need to be vlan tagging on the SSID.&lt;/P&gt;&lt;P&gt;In the 2nd screenshot, you have "don't use vlan tagging", which means that clients aren't being assigned a vlan based on the SSID. They will instead just get out onto the native vlan.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 05:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484886#M296243</guid>
      <dc:creator>Brash</dc:creator>
      <dc:date>2023-08-12T05:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484887#M296244</link>
      <description>&lt;P&gt;I think we're on the same page as that's something else I tried, however, and this may be what threw me off, is the "All other APs" fields, what should that be set as?&lt;/P&gt;&lt;P&gt;I haven't implemented the changes, I just want to confirm with the images your recommendations.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VLAN Tagging Office" style="width: 557px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271935i3A3BCB3E6642F30C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;VLAN Tagging Office&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VLAN Tagging Store" style="width: 536px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271933iD86870572E745FF3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;VLAN Tagging Store&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Trunk Port" style="width: 818px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271936iFCC059DB5DA637FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Trunk Port&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 05:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484887#M296244</guid>
      <dc:creator>WhoIsThis</dc:creator>
      <dc:date>2023-08-12T05:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484888#M296245</link>
      <description>&lt;P&gt;So with the config there, you're applying configuration based on AP tags. Are you using tags on your access points?&lt;/P&gt;&lt;P&gt;If not, the "Default" tag applies to all AP's.&lt;/P&gt;&lt;P&gt;Otherwise if you are, you can assign the vlan to the ssid based on AP tag as you have there. &lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 07:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484888#M296245</guid>
      <dc:creator>Brash</dc:creator>
      <dc:date>2023-08-12T07:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484889#M296246</link>
      <description>&lt;P&gt;I created tags and implemented them as a workaround to restore the previous physical setup. I used the SSID Availability feature to limit which was broadcast by which AP.&lt;/P&gt;&lt;P&gt;What is the alternative to using tags? What is your recommended configuration?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Aug 2023 15:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484889#M296246</guid>
      <dc:creator>WhoIsThis</dc:creator>
      <dc:date>2023-08-12T15:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSIDs and VLAN Problem</title>
      <link>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484890#M296247</link>
      <description>&lt;P&gt;Are you sure that there is an issue? If you are testing with the same laptop or device make sure that you are looking at the SSID  specific Clients for the past two hours or else you may be fooled into thinking that the wrong subnet is in use... The first time I ran across this with Meraki in 2016, I nearly had a heart attack thinking my guest segment was leaking into my corp VLAN... Why does this happen? The same client accessing multiple segments. If you don't narrow the search it will give you the first record it finds in the client table... So host name searches and MAC searches requires very specific filtering. Also, patience with allowing the cloud to update with the data also helps. i would also move your store segment of off VLAN 1 and onto a differing VLAN as the use of VLAN 1 could cause all sorts of unintended behavior.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TBHPTL_0-1692031062341.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/271937iA68869F0F80C799B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 16:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/ssids-and-vlan-problem/m-p/5484890#M296247</guid>
      <dc:creator>DainBrammage</dc:creator>
      <dc:date>2023-08-14T16:41:35Z</dc:date>
    </item>
  </channel>
</rss>

