Showing results for 
Search instead for 
Did you mean: 

AP 2802 vlan tagging (wlc based) not working

Hi all,

I'm trying to use vlan tagging for the AP-2602 access port to join the WLC.

VLAN-Tagging is enabled for the AP (WLC setting) and the switchport as tunk.


AP won't access the right VLAN.

Work when I change the switchport to access-mode, access vlan xx.


VLAN-tagging Works for the AP 2700 version.


Can it be that AP's 2800/1800 do not support the vlan tagging?





Everyone's tags (1)
VIP Mentor

Re: AP 2802 vlan tagging (wlc based) not working

AP are in local or flexconnect mode ?


If the AP is in local mode, the switch's port is in access mode no matter how many ssid are managed by the AP. All the trafic go in the CAPWAP tunnel


If the LAP is in HREAP/Flexconnect mode, the switch's port is in trunk mode.

H-REAP allows to swtich some wlans locally, that's why a trunk port is necessary on the switch.



Dont forget to rate helpful posts



Re: AP 2802 vlan tagging (wlc based) not working

The AP is in local mode.

I know that the AP need's only one vlan to connect with the wlc.

As the AP's area are not secure, I want to tagging the "access-vlan" from AP view.

E.g. somebody diconnect the AP network cable an put the laptop on it, it will connect to an "empty" vlan (the native one). When the AP is connected, it tagges the "right" vlan to get connected with the wlc.


This setup worked for AP 2700.




Hall of Fame Master

Re: AP 2802 vlan tagging (wlc based) not working

I don’t know how it worked with the 2700’s. Where are you setting the management vlan when the AP is in local mode? For the longest time, all Cisco access points require that the AP management is not tagged. Basically either access vlan or if trunked, native vlan. This is in their deployment guide(s).
What you are trying to do is typically done with 802.1x auth on the switchport. The switch would send auth to radius and then radius would assign the vlan.
*** Please rate helpful posts ***
VIP Advocate

Re: AP 2802 vlan tagging (wlc based) not working

Or the cheaper, easier, less secure way of mac-address-learning (sticky mac address). This will only work with APs in Local mode and not protect from clients copying the mac address of the AP.

Re: AP 2802 vlan tagging (wlc based) not working

It’s on the WLC / Wireless / Detail for AP / Advanced / VLAN Tagging

VLAN Tagging Settings

VLAN Tagging

VLAN tagging of the CAPWAP packets that you can enable or disable.


ID of the trunk VLAN.
If the access point is unable to route traffic through the specified trunk VLAN, it untags the packets and reassociates with the controller. The controller sends a trap to a trap server such as the Cisco PI, which indicates the failure of the trunk VLAN.
If the trunk VLAN ID is zero, the access point untags the CAPWAP packets.

VLAN Tag Status

Whether the access point tags or untags the CAPWAP packets.

CreatePlease to create content
Content for Community-Ad

August's Community Spotlight Awards