cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1708
Views
5
Helpful
3
Replies

Separate management Vlan

Toscana
Frequent Visitor
Frequent Visitor

Hi,

we're planning to deploy 9120AXI access points in two of our branches. At each site there is one access point with EWC on board. APs are connected to the access switches (2960-XR), together with all other clients (ip phones, computers etc.) We intend to setup two SSIDs on each branch, enclosed in separate Vlans. Looks roughly like this:
Vlan 10 - data
Vlan 20 - voice
Vlan 30 - SSID 1
Vlan 40 - SSID 2

Is it possible/intended by the manufacturer to manage the master AP (EWC) via separate management Vlan (e.g. Vlan 10) and to keep Wifi traffic completely off this vlan? Could be like that:
Master AP: Vlan 10,30,40
Slave AP: Vlan 30,40

Additional: How does master AP provide configuration changes to the satellites?

Thanks for any comment, folks. Regards
Stefano

3 Replies 3

Wes Schochet
Level 7
Level 7

In this scenario, you'd create trunks for all APs and have their management / native VLAN be 10.  The only time traffic would hit 30 or 40 is when the flex policy (or flex group) associated the SSID to that VLAN.

 

Rich R
VIP
VIP

The EWC AP and the subordinate APs must talk to each other over the management VLAN so:

Master AP: Vlan 10 (native),30,40
Slave AP: Vlan 10 (native),30,40

So to answer your question the master will talk to the slaves over vlan 10.

The WiFi user traffic is switched over vlan 30 and 40.

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390

Scott Fella
Hall of Fame
Hall of Fame

Just to add, why not create a vlan just for your ap's, this way the traffic is separate fro all the data traffic?

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card