<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest wireless with VLAN Tagging in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524768#M309551</link>
    <description>&lt;P&gt;VLAN 1 is for my wired devices.  My AP's are pulling their IP from the wired DHCP pool. &lt;/P&gt;&lt;P&gt;0/1                         10.236.68.1/22                   Data&lt;/P&gt;&lt;P&gt;0/3                         10.236.236.1/22                Internal Wireless               VLAN 35 Tagged&lt;/P&gt;&lt;P&gt;0/3.1007               10.236.94.0/23                   Guest Wireless                  VLAN 1007 Tagged&lt;/P&gt;&lt;P&gt;0/4                         10.236.5.1/24                     VOIP&lt;/P&gt;&lt;P&gt;0/5                         10.236.81.1/24                   DMZ                                      (Not being used yet)&lt;/P&gt;&lt;P&gt;0/6                         10.236.32.1/24                   Bell &amp;amp; Intercom&lt;/P&gt;&lt;P&gt;0/7                         Uplink&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 15:58:21 GMT</pubDate>
    <dc:creator>CMorinski</dc:creator>
    <dc:date>2022-03-29T15:58:21Z</dc:date>
    <item>
      <title>Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524758#M309541</link>
      <description>&lt;P&gt;Trying to setup a guest ssid in my elementary school. Below is how the ISP has our firewall configured. &lt;/P&gt;&lt;P&gt;0/3                         1x.2xx.2xx.1/22                Internal Wireless             VLAN 35 Tagged&lt;/P&gt;&lt;P&gt;0/3.1007                1x.2xx.9x.0/23                   Guest Wireless                  VLAN 1007 Tagged&lt;/P&gt;&lt;P&gt;I am new to this process and would like to figure it out instead of contacting my vendor to set it up.  &lt;/P&gt;&lt;P&gt;I assumed I would use NAT Mode but how do I configure firewall settings to pull from my IP pool setup by the ISP instead of this one? (10.0.0.0/8)&lt;/P&gt;&lt;P&gt;NAT mode: Use Meraki DHCP&lt;/P&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Clients receive IP addresses in an isolated 10.0.0.0/8 network. Clients cannot communicate with each other, but they may communicate with devices on the wired LAN if the &lt;A href="https://n93.meraki.com/Four-Winds-Schoo/n/o4x3VaDb/manage/configure/traffic_shaping" target="_blank" rel="noopener nofollow noreferrer"&gt;SSID firewall settings&lt;/A&gt; permit.&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524758#M309541</guid>
      <dc:creator>CMorinski</dc:creator>
      <dc:date>2022-03-29T14:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524759#M309542</link>
      <description>&lt;P&gt;In nat mode its always using meraki dhcp.&lt;/P&gt;&lt;P&gt;I would recommend reading this&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/SSID_Modes_for_Client_IP_Assignment#Bridge_Mode" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/SSID_Modes_for_Client_IP_Assignment#Bridge_Mode&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Use bridge mode and tag it with vlan 1007.&lt;/P&gt;&lt;P&gt;Configure the firewall to deny  local lan and enable l2 lan isolation&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:24:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524759#M309542</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2022-03-29T14:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524760#M309543</link>
      <description>&lt;P&gt;Thanks!  I did try doing it that way yesterday.  When i try connecting to the guest it will eventually time out just give me a 169.254.x.x IP.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524760#M309543</guid>
      <dc:creator>CMorinski</dc:creator>
      <dc:date>2022-03-29T14:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524761#M309544</link>
      <description>&lt;P&gt;Do you have trunk ports between the firewall and the switches and to the AP?&lt;/P&gt;&lt;P&gt;Are you sure there is a dhcp scope for this subnet?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:46:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524761#M309544</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2022-03-29T14:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524762#M309545</link>
      <description>&lt;P&gt;My AP's to the switch are set as trunk ports.  My port from switch to firewall is Access.  I did submit a ticket to my ISP to double check the firewall is correct.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524762#M309545</guid>
      <dc:creator>CMorinski</dc:creator>
      <dc:date>2022-03-29T14:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524763#M309546</link>
      <description>&lt;P&gt;That sounds like the problem. A access port transport only 1 vlan(native).   If you want to use more vlans from the firewall you should have trunk ports transporting those vlans&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524763#M309546</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2022-03-29T15:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524764#M309547</link>
      <description>&lt;P&gt;I really appreciate the help on this!  So would my native vlan need to be 35 and allowed just need to be 1007??&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VLAN35.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/270521iC3C3333D353BA7D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Trunk.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/270522iB0AA06A87EF503C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524764#M309547</guid>
      <dc:creator>CMorinski</dc:creator>
      <dc:date>2022-03-29T15:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524765#M309548</link>
      <description>&lt;P&gt;Yes , but maybe first configure it on a empty switch port and swap the cable to that port.  In case it doesnt work you can easily go back.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524765#M309548</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2022-03-29T15:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524766#M309549</link>
      <description>&lt;P&gt;Almost had it.  I was able to get the correct IP address but I had no internet.  I got no internet on both my secure or guest ssid.  Could the trunk port for the AP cause issues?  They are not set for vlan 35&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APPort.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/270523iAAC3EDDA5F38700B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524766#M309549</guid>
      <dc:creator>CMorinski</dc:creator>
      <dc:date>2022-03-29T15:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524767#M309550</link>
      <description>&lt;P&gt;That looks fine.  Maybe vlan 35 is also tagged and native should be 1 on the uplink?, but your previous config shows access port vlan 35, thats confusing.&lt;/P&gt;&lt;P&gt;What management IP/subnet does you AP have?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524767#M309550</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2022-03-29T15:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524768#M309551</link>
      <description>&lt;P&gt;VLAN 1 is for my wired devices.  My AP's are pulling their IP from the wired DHCP pool. &lt;/P&gt;&lt;P&gt;0/1                         10.236.68.1/22                   Data&lt;/P&gt;&lt;P&gt;0/3                         10.236.236.1/22                Internal Wireless               VLAN 35 Tagged&lt;/P&gt;&lt;P&gt;0/3.1007               10.236.94.0/23                   Guest Wireless                  VLAN 1007 Tagged&lt;/P&gt;&lt;P&gt;0/4                         10.236.5.1/24                     VOIP&lt;/P&gt;&lt;P&gt;0/5                         10.236.81.1/24                   DMZ                                      (Not being used yet)&lt;/P&gt;&lt;P&gt;0/6                         10.236.32.1/24                   Bell &amp;amp; Intercom&lt;/P&gt;&lt;P&gt;0/7                         Uplink&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524768#M309551</guid>
      <dc:creator>CMorinski</dc:creator>
      <dc:date>2022-03-29T15:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Guest wireless with VLAN Tagging</title>
      <link>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524769#M309552</link>
      <description>&lt;P&gt;I think a good test might be to configure a port in access mode on each VLAN and test the connection with a laptop to validate that the connection to each VLAN is working as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 16:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/guest-wireless-with-vlan-tagging/m-p/5524769#M309552</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2022-03-29T16:58:47Z</dc:date>
    </item>
  </channel>
</rss>

