Solved

Trunk port configuration for Wireless VLANs

Posted on 2016-11-14
11
88 Views
Last Modified: 2016-11-15
Objective:      Trying to seperate SSID's into two VLANs.  Currently, two SSID's using VLAN 40, everything working fine.
Configuration:       Setup a port on our Catalyst 3750 as a trunk port for VLANs 40 & 45, added SSID and configured it for VLAN 45 on      Ubiquiti wireless controller.  (VLAN 40 is currently being used for the wireless system, AP's are plugged into Catalyst access ports set for VLAN 40).

Troubleshooting:  Would not communicate so, started tested with a laptop in which I can set VLAN tags.  Configured 40 and 45 on the laptop seperately with no luck.  Reconfigured Catalyst to an access port testing one VLAN at a time and only works when the laptop is configured with no vlans.  

Have only set trunk ports to connect between switches, never to handle multiple VLANs for endpoint devices,  Am I missing something?
Thank you.
0
Comment
Question by:Webcc
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 25

Expert Comment

by:masnrock
ID: 41886479
The controller has to be on the same VLAN as the APs. However, within the controller you can configure the SSIDs to use tagged VLAN IDs.

When you configured the trunk port, did you configure 40 to be the untagged VLAN and 45 to be a tagged one? You might want to configure the ports going to the APs as General ports instead, with the PVID being 40 and untagged, and 45 being tagged

This way, when your laptop are connected to general ports configured as such, they will be on VLAN 40 (if you put in for VLAN 45 on the NIC of the laptop, it will end up there). Also, then you should be able to configure your SSIDs to use VLAN 45.
0
 

Author Comment

by:Webcc
ID: 41886507
Configured the trunk port as follows:
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk allowed vlan 40,45
0
 
LVL 25

Expert Comment

by:masnrock
ID: 41886513
What about the ports going to the laptop and the APs? Those should be configured as general ports (trunk ports do not always play nicely with non-Cisco devices).
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:Webcc
ID: 41886514
Should have asked how do you configure a Catalyst for "general" ports instead, with the PVID being 40 and untagged, and 45 being tagged?
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 250 total points
ID: 41886521
You do NOT need to have the APs on the same VLAN as the controller.  It makes it easier, but it's not mandatory.

The 3750 doesn't do general ports.  It does access or trunk.  It's Cisco-speak.

In your case, the port config needs to be...

switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk native vlan 40
switchport trunk allowed vlan 40,45

Open in new window


The laptop doesn't need to to any VLAN tagging.  That will be handled at the AP.
0
 

Author Comment

by:Webcc
ID: 41886604
But if I want to test proper port configuration I should be able to set the laptop VLAN ID  to 40 or 45 right?
0
 
LVL 25

Assisted Solution

by:masnrock
masnrock earned 250 total points
ID: 41886656
I'm writing this under the assumption you're using a cable for the laptop...

If you want to test VLAN 40, you don't need to set a VLAN on the laptop. However, if you want to to test VLAN 45, then you do need to set it into the NIC.

As far as the APs go, you'll need to make sure that the SSIDs that will utilize VLAN 45 is correctly configured.
0
 

Author Closing Comment

by:Webcc
ID: 41886712
Thanks guys, working great!
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 41886781
You just need to put a switch port on whichever VLAN you want to test. NO VLAN tagging at the laptop is necessary.
0
 

Author Comment

by:Webcc
ID: 41887093
Just using the laptop to test port configuration before I connect the AP's and set the VLAN ID's on them to match.  Thanks
0
 

Expert Comment

by:John Chuma
ID: 41889001
I normally don't do this, but thank you to Craig for the solution. I have the same switch at home and have multiple VLANS for WiFi and this worked.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco ASA 5512 LAN Config 16 79
Remote access problem to camera controller 9 39
VPN Server config in Modem 5 32
cannot view videos at msnbc 12 44
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question