I would like to have the vWLC management and "APmanager" functionality on separate VLANs. For security reasons I don't like exposing the manager IP to all places where I place APs. But when I disable DYNAMIC-AP-MGMT on the management if and enable it on another IF the VWLC complains that the JOIN message comes in on a wrong VLAN and rejects the AP join.
Is it possible to separate the mgmt and APManager to different VLANs? Maybe to use the out of band service port for mgmt and put an CPU access list on the data port to block exposed mgmt protocols like https?
Or did I misunderstand how this is supposed to work?