01-23-2022 10:21 AM
Hi is there anyway that using mobility express on AP’s it would be able to route traffic to two different networks.
At the moment the AP’s have a (corp) SSID and are on a 10.1.1.0/24 subnet with a default gateway of 10.1.1.1 which is the core router. Dhcp for this network is passed on and handled by the core network.
Now I’m looking to add another SSID (Regional) On the same AP’s but this time using the DHCP built in the MOBILITY EXPRESS with an ip address range of 192.168.1.0/24 with a default gateway of 192.168.1.1 which will be handed out to the devices on this SSID.
This new SSID can’t be routed to the core network, but to a DMZ Firewall which will have the ip address for the default gateway.
Can this be done, is there a way to have 2 networks on the same AP using mobility express, as at the moment the AP’s only have 1 subnet and default gateway.
Is there a way to get the AP to route traffic with the (Regional) SSID to a different network so it would route to the DMZ. As at the moment any traffic that is outside of the 10.1.1.0 subnet will go to the CORE.
Thanking you in advance.
01-23-2022 02:57 PM
Hi
As you have only one interface, you are going to need to work with trunk on the uplink between AP and Core and allow 2 VLANs. One for the current SSID and one to the new SSID.
Then, you can choose one port on your core to connect do the Firewall and put this port on the VLAN you created on the AP.
01-23-2022 03:02 PM
DHCP in ME is not recommended, but yes you can have a new DHCP scope defined for the WLAN. Make sure that you run a supprted firmware.
By design Mobility Express is similar to Cisco FlexConnect, but client data is only bridged locally at the access point. Therefor it is perfectly possible that you can create a new WLAN, tag that with a VLAN where the gateway is in the DMZ of the Firewall. DMZ to Core router traffic flows can be blocked from the firewall as required, I would suggest not to add routing as well. In the DHCP scope make sure to define the gateway as your DMZ VLAN interface IP.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide