Solved

Correct port settings for separate WiFi VLAN

Posted on 2016-09-15
2
90 Views
Last Modified: 2016-09-16
Our school’s network has always had just one subnet for everything. Now, we want to isolate WiFi.  Thanks to help from user SIM50 on a previous Xperts-exchange question, I’ve done this with one WAP, connected to a switch which is in turn connected to our Sonicwall router as follows:

diagram2.jpeg
VLAN1:192.168.1.1 (LAN)
VLAN100:192.168.0.1 (WiFi)

In the above, the first WAP is working, but I haven’t extended VLAN100 beyond that switch.  I now need to replicate these settings to the above “Room 36” switch, but I believe there are VLAN settings I need to assign to the pre-existing trunks (fibre) between those two rooms (and the comms room switch in the middle so, Room 39 switch -> Comms room (fibre) -> Room 36 switch).

Working on what I learned from the previous question, I guessed I needed to create the same VLAN on the other two switches, make the trunk ports “tagged” for that VLAN and then replicate the port settings for the working WAP to the port for the second WAP.  SIM50 also said I needed to make sure VLAN100 was allowed through the trunk, but aside from adding the ports to the VLAN, I wasn’t sure what he meant. So I gave it a shot yesterday and I’m not sure how (possible mistake), but I managed to remove all administrative access to all three switches! (the SG200s don’t have admin ports).  After reconfiguration, I’m back where I started (first WAP still working).

This is what I think should work:

 settings.jpg
So, I’m looking for some pointers as to where to go from here.
0
Comment
Question by:mark_D74
2 Comments
 
LVL 14

Accepted Solution

by:
SIM50 earned 500 total points
ID: 41800262
1. Create VLAN 100 on all switches.
2. Port 49 on 192.168.1.96, port 1 and 2 on 192.168.1.201, port 49 on 192.168.1.31 should be configured as trunks. I think it is the default config on the SG switch series. Verify by going to VLAN Management -> port vlan membership. You should see 100T in Administrative VLANs tab. If not there, click on Join VLAN on the bottom and add VLAN 100.
3. Add port 5 on 192.168.1.31 to VLAN 100 as access.
1
 

Author Closing Comment

by:mark_D74
ID: 41802335
Worked perfectly
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question