04-20-2024 12:57 PM
I have some branch locations with a simple set up. A router with an access switch connected to it, then another access switch connected to that one to provide POE to IP phones. Currently all devices are in the same VLAN.
I also have an access point connected to the access switch (non-POE) which provides wireless services to our visitors and personnel. I've been trying to separate the wireless traffic to its own VLAN. The AP provides DHCP services to the users that connect to it, and when it's setup in the same VLAN as the switches everything works fine.
AP config sample:
int bvi1
ip address 192.168.2.10 255.255.255.0
Access switch sample:
int fa0/20
switchport access vlan 2
swithport mode access
int fa0/1
switch port mode trunk
switchport trunk van 1 native
Router sample:
int fa0
int fa0.1
encapsulation dot1q vlan 1 native
ip address 192.168.1.1 255.255.255.0
int fa0.2
encapsulation dot1q vlan 2
ip address 192.168.2.1 255.255.255.0
router bhp 65515
network 192.168.1.1
network 192.168.2.1
Used sample configs because I don't have the original configs on me at the timed. I must admit there are also static routes in place to facilitate use of an SDWAN circuit. A default route sends all unknown unicast traffic to the SDWAN interface, while other static routes send traffic across our MPLS WAN.
Since everything works when all devices are in the same VLAN, I'm sure something is wrong in my configuration.
When I modify the setup to accommodate the new VLAN I can connect to the AP, reach locations across the WLAN, but no internet connectivity. I know I'm missing something simple. Can I get some suggestions on where else to look?
04-21-2024 12:46 AM
How does your network diagram looks like ?
you mentioned SD-WAN, is this spoke site you trying to make changes ?
Wireless Traffic for Guest users - means you going to different SSID for Guest or BYOD setup ?
what WLC and AP model in place ?
04-22-2024 10:13 AM
04-22-2024 10:25 AM
Thanks for the additional information and the partial configs. I see ip nat inside on what appears to be the wireless subinterface. I do not see any ip nat outside command and any other commands to implement nat. Those are still number one on my list of possible problems.
04-22-2024 02:44 PM
as this is an active circuit and I need to get approval for adding them, they are not implemented on the router yet.
04-21-2024 12:53 AM
Hello,
I assume the router is also doing the NAT for Vlan 1 ? Have you added the access list entry for the new Vlan also, so the router knows that it has to translate 192.168.2.0/24 as well ?
04-22-2024 06:43 AM
There is much that we do not know about this environment and that makes it difficult to accurately identify the issue. But based on what we know so far I agree with @Georg Pauwen that most likely the issue is that there is not address translation for the wireless traffic. If we had more information, especially the configuration of the router, we could be more confident in our suggestions.
04-22-2024 02:48 PM
as I just responded above, I need to get permission to apply the remaining configs for NAT. I am aware those configs are not complete.
04-22-2024 03:02 PM
Seeing the incomplete production configs is not helpful to us. What would be helpful is to post what you intend the configs to look like as you make the change.
04-22-2024 02:45 PM
there will only be translation for vlan165 as this is the wireless vlan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide