11-17-2009 09:20 AM - edited 07-03-2021 06:16 PM
Hello,
in cisco documents I find that is'd be better not to use untagged vlans but in all cisco examples management vlan and ap manager vlan are always untagged.
What do you think is the best way use tagging?
Also shuld be possible to use to different vlans for AP manager and management? If it should, which would be best to tag the ap manager vlan or the management one?
Thanks
11-20-2009 07:19 AM
Which controller are you talking about?
If I look at the config on my 4402, they are tagged, but if I look at the wism configs, they are not.
11-25-2009 08:17 AM
I'm talking about 5500 WLCs.
Thanks
11-25-2009 10:03 AM
Security best-practice is to never use the untagged (native) VLAN. The number of organizations that follow this best-practice is probably under .5%. Since it's something that's rarely practiced, it's no surprise that Cisco has examples with the manager interfaces being untagged.
I have used untagged VLANs on the management interfaces for all of my installations. There is nothing wrong with this deployment - it will work just fine. Your other VLANs will require tagging. I'd recommend keeping your Manager and AP Manager interfaces on the same VLAN, though this isn't required.
Does that help to answer your question?
Jeff
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: