Dual SSIDs

MulLa

Golden Member
Jun 20, 2000
1,755
0
0
Hi All,

I'm trying to configure 2 seperate SSIDs on my Aironet 1200 as some clients are unable to support RAIDUS authentication. I'm planning to create 2x SSIDs with 2 seperate VLANs and have the non-RAIDUS VLAN only having access to the internet (since that's all they need).

Not too sure what port I should set on the switch port that the access point is going into? When I sent it as an access port in the native VLAN it seemed to work alright. By that I mean the native VLAN worked fine (haven't tested the second VLAN as yet). When I turn it into a trunk so I can carry both VLANs everything stopped working.

Any idea on how I should setup the switch port?


Thanks in advance!
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
set it up as a dot1q trunk port.

You also need to create the vlans on the AP - this is done with sub interfaces on the dot11radio interface and on the fast ethernet interface. Then you use the vlan command under the ssid defintion to assign the ssid to a wireless vlan. It's pretty straight forward actually.

 

jlazzaro

Golden Member
May 6, 2004
1,743
0
0
your going to need to dot1q the port connected to the ap, define the native vlan (ie untagged) and tagged vlans on both the ap and the switch.

interface FastEthernet0/1
switchport trunk encapsulation dot1q
switchport trunk native vlan 306
switchport trunk allowed vlan 1,305,306,1002-1005
switchport mode trunk
end

post your config...
 

MulLa

Golden Member
Jun 20, 2000
1,755
0
0
Thanks for the quick response!

Looks like it seemed to be working. Seemed that I've forgotten to set the native vlan on the switch port that's connected to the AP. Since the switch itself have a different native vlan I'm guess that's why it didn't work?

Below is my config that I think is relevant to confirm that I've done it correctly. Now it's time to configure that VLAN router!!!

Catalyst 2950 (only supports dot1q)
interface FastEthernet0/22
switchport trunk native vlan 120
switchport mode trunk
spanning-tree portfast
spanning-tree bpduguard enable

Aironet 1200
interface Dot11Radio0.120
encapsulation dot1Q 120 native
no ip route-cache
bridge-group 1
bridge-group 1 block-unknown-source
no bridge-group 1 source-learning
no bridge-group 1 unicast-flooding
bridge-group 1 spanning-disabled
!
interface Dot11Radio0.130
encapsulation dot1Q 130
no ip route-cache
bridge-group 130
bridge-group 130 subscriber-loop-control
bridge-group 130 block-unknown-source
no bridge-group 130 source-learning
no bridge-group 130 unicast-flooding
bridge-group 130 spanning-disabled
!
interface FastEthernet0
no ip address
no ip route-cache
duplex auto
speed auto
hold-queue 160 in
!
interface FastEthernet0.120
encapsulation dot1Q 120 native
no ip route-cache
bridge-group 1
no bridge-group 1 source-learning
bridge-group 1 spanning-disabled
!
interface FastEthernet0.130
encapsulation dot1Q 130
no ip route-cache
bridge-group 130
no bridge-group 130 source-learning
bridge-group 130 spanning-disabled


thanks once again!!
 

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
The config looks good, although I'm not sure why you and jlazzaro want to use native VLAN.
As long as the vlan's are configured on both AP and trunk port, they should be fine.
 

nweaver

Diamond Member
Jan 21, 2001
6,813
1
0
Originally posted by: Cooky
The config looks good, although I'm not sure why you and jlazzaro want to use native VLAN.
As long as the vlan's are configured on both AP and trunk port, they should be fine.

actually, they arn't....those ap's have funky dot1q trunk support, you have to meke sure the native vlan is vlan1, or they freak out (or did, a few months ago)
 

MulLa

Golden Member
Jun 20, 2000
1,755
0
0
Hm... My wireless PCs which are on VLAN120 seemed to loose connection if I don't assign as the native on the AP. I've gone through various Cisco docs which suggest that native VLAN isn't necessary in this situation. Maybe I'll look into this once I get the "less secured" clients up and running first.

Thanks everyone for your help. I'll be back if I'm stuck again
 

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
Thanks for pointing that out...we never use native VLAN so I had no idea...for large rollouts we use 4400 controllers so we don't have to worry about it anyway.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Your BVI interface should be in the native VLAN. That causes people confusion sometimes.
 

MulLa

Golden Member
Jun 20, 2000
1,755
0
0
Originally posted by: spidey07
Your BVI interface should be in the native VLAN. That causes people confusion sometimes.

Hm... That might explain why I must set VLAN120 as the native in the AP as the BVI interface is in VLAN120.

Since I'm still a n00b I have another question. Does the native VLAN for the AP have to match the native VLAN on the switch? If they do what if I don't want my wired native VLAN propergated to the wireless network?

Thanks.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
You lost me.

The BVI has to be in the native VLAN - this is for the control plane traffic. From there your wireless VLANs are just tagged.

I thought something funny was off on your config...your .120 subinterface is in bridge group 1. the native VLAN is for management only - not wireless vlans. This comes into play when you are doing multicasting and other intricate VLAN features.

If you want to see what is going on "show bridge" will help. Remember, the AP is nothing more than a bridge - treat it as such.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |