cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1032
Views
0
Helpful
2
Replies

Business 240AC Access Point - VLAN 1 Tagging

seb-edv
Level 1
Level 1

Hello Cisco community,

We have deployed two Cisco Business 240AC access points at a clients office and are facing issues with VLAN tagging.

The switchport on which the access point is plugged in is in a hybrid configuration and has our management VLAN set as untagged, and the internal network (VLAN1) and guest network set as tagged. Since it's not possible to set a dedicated management VLAN on these aps (at least I couldn't find a way) like on the older WAP371's, I had to set the management network as an untagged vlan and enabled VLAN tagging on both WLANs in the ap configuration. While the guest network works as desired I noticed that all clients connected to the internal WLAN on VLAN1 are just simply joined into the untagged vlan. This causes them to not be able to access any ressources on VLAN1 and also exposes all configuration interfaces in the management network to them. The access point seems to ignore VLAN tagging when it's set to VLAN1. Is there any workaround or fix for this? Or maybe another configuration option for having the management interfaces not accessible from the internal network?

Thanks in advance for your suggestions.

2 Replies 2

Rich R
VIP
VIP

Without having checked the product documentation or release notes I doubt there is anything you can do about it.

If you haven't already - then make sure the AP firmware is up to date just in case there's a fix or enhancement for that.

But this is an object lesson in why vlan 1 should not be used on a network - suggest you have a word with the network admin/designer.

Hi

 Not only this device but all devices will ignore tag on vlan 1.  What you can do is create the WLAN and associate it to a VLAN and select Vlan tag yes under Firewall & VLAN .   Keep the Vlan1 for management.

Review Cisco Networking for a $25 gift card