I have a situation with Cisco WLC 4402. I have 2 WLAN networks. Corporate network is in vlan188 and guest network is in vlan192. Management interface is on untagged vlan. I would want the controller to be accessible via corporate network but not the guest network. Disabling management via wifi would mean the controller will not be accessible via the corporate network. The controller is connected to a core switch. The interface is a trunk with native vlan defined (vlan 189). Allowed vlans contain both vlans188 and 189 and 192.
Question:
1. Does untagged vlan mean both 188 and 192 networks can access the management IP?
2. How do I only allow 188 segment to access the management IP?