Link to home
Start Free TrialLog in
Avatar of amigan_99
amigan_99Flag for United States of America

asked on

Trunking to the Access Point No working

I was able to add the subinterface to the AP with the native VLAN.  I was able to keep connectivity throughout.  BUT when I tried to add the second guest VLAN something is not working.  

Relevant Config on the Cisco AP 1242..

interface FastEthernet0.1
 encapsulation dot1Q 1 native
 no ip route-cache
 bridge-group 1
 no bridge-group 1 source-learning
 bridge-group 1 spanning-disabled
interface FastEthernet0.2
 encapsulation dot1Q 99
 no ip route-cache
 bridge-group 2
 no bridge-group 2 source-learning
 bridge-group 2 spanning-disabled
interface BVI1
 ip address
 no ip route-cache
interface BVI2
 ip address
 no ip route-cache

On the Cisco 3560 switch:

spanning-tree vlan 32,99 priority 24576

interface GigabitEthernet0/9
 description link to port 51B
 switchport access vlan 32
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 32
 switchport mode trunk
 srr-queue bandwidth share 10 10 60 20
 queue-set 2
 priority-queue out
 mls qos trust cos
 auto qos voip trust

interface Vlan99
 ip address

c3560-1#sho int vlan 99
Vlan99 is up, line protocol is up
  Hardware is EtherSVI, address is 5475.d041.b9c5 (bia 5475.d041.b9c5)
  Internet address is

c3560-1#sho int gi 0/9 trunk
Port        Mode             Encapsulation  Status        Native vlan
Gi0/9       on               802.1q         trunking      32

Port        Vlans allowed on trunk
Gi0/9       1-4094

Port        Vlans allowed and active in management domain
Gi0/9       1,32,99
Port        Vlans in spanning tree forwarding state and not pruned
Gi0/9       1,32,99


Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:
At this stage I just want to ping between the virtual interface 99 on the directly connected 3560 switch and the BVI interface on the access point.  But no luck in either direction.  Thoughts most appreciated!
Avatar of ArneLovius
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Please post the entire config from the WAP via code or attachment.
Here are a couple things that you didn't post but you should have.

dot11 ssid Guest
   vlan 99
   authentication open
   authentication key-management wpa  <-- obviously whatever you are using  
   mbssid guest-mode
   wpa-psk ascii whateverhexyouhavehere

and you should have a similar one for ssid office on vlan 32

interface Dot11Radio0.99
 encapsulation dot1Q 99
 no ip route-cache
 bridge-group 99
Avatar of amigan_99


I just put an IP address on BVI 2 in order to test things before starting in on the WiFi part.  But ok I will try to add the guest VLAN and see if wifi hosts can ping the once they attach.  Thanks!