We have our ASA and modem on the second floor which is on Vlan 2. Our ASA inside interface is on the default Vlan. We plan to have our ASA act as a dhcp server for the guest network and push out our modem DNS addresses. I want this guest wireless network be able to reach our ASA to get Internet access. The guest wireless will be broadcast on Vlan 18 only.
The general topology is as follows:
Modem---> ASA ---> Vlan 2 Hp switch ---> Core Switch ---> Vlan 18 HP Switch ---> Cisco 1200 WAP (Corporate and guest wireless)
I'm assuming from the Cisco WAP to the HP Switch would need to be tagged. Also, the HP switches will need to have the new vlan created. The the uplink port on the 18 access switch, that connects to the Core switch, will need to be tagged as well. Then the Core Switch port going to the Vlan 2 access HP switch will need to be tagged.
Finally, do to my current ASA license, I have a port on the ASA that is untagged for guest wireless Vlan going to the 2fl HP switch. The port on the 2nd floor HP switch, the ASA is connect to, is untagged for the guest wireless. Please let me know if this will work. Thanks ahead of time!
Modem ---> ASA ---guest Vlan untagged port ---> 2nd fl HP switch ---Tagged Guest wireless--> Core Switch ---> uplink to 18th fl is tagged for guest wireless ---> 18th floor switch ---tagged port for guest wireless ---> Cisco WAP (Corporate and Guest Wireless)