Thank You Eric. I already had the two VLANs so I changed the management VLAN to 20 and left my untagged to 1. 20 is my Guest Only. After I tried to connect externally by pinging the gateway and it still failed. BUT when I went to check the configuration, I forgot to change the static IP on the WAP. So I cannot access it. It still works because internal users work fine. I work remotely, so I will have to drive in this weekend and reconfigure. I will try the above again to let you know if it works. Thanks!
... View more
I have a WAP321 with 2 SSID's. One is for local access and another for guest. The WAP connects to a 3550 and it's port is set to description Cisco Wireless switchport trunk encapsulation dot1q switchport trunk allowed vlan 1,20 switchport mode trunk no ip address spanning-tree portfast My ASA 5505 is set with both VLANs and I'm using DHCP to dishout the guest IP. MyWAP has both networks setup. VAP 0 is setup for VLAN 1 and VAP 1 is for VLAN 20. Both are enabled. When connecting to my local wireless, I have no problem getting local access and Internet connection. When I connect to Guest I get an IP from my ASA's DHCP, but I cannot ping my gateway, which is my ASA. I know my guest VLAN is ok, because if I put a port on that VLAN, I can connect to the Internet. When I do packet captures from the WAP (Administration-Packet Capture), I can't see any ICMP attempts either from the eth0 or VAP 1. When I capture my machines wireless interface I see ICMP attempts with no reposnds. It makes me think I missed something in the WAP321 setup. Any ideas where to check?
... View more