Enabling VLAN with the EAP225 locks me out

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Enabling VLAN with the EAP225 locks me out

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Enabling VLAN with the EAP225 locks me out
Enabling VLAN with the EAP225 locks me out
2021-08-27 16:10:36 - last edited 2021-09-10 16:25:44
Model: Adapter  
Hardware Version: V3
Firmware Version: 5.0.5 Build 20210604 Rel. 51118(5553)

I just picked up the EAP225 (not Adapter as noted in my selection above), which I am enjoying playing around with.  There is one feature I'd really like to use but for the life of me, can figure it out.  When I enable the VLAN in the EAP225 it locks me out of the admin interface and clients cannot connect to the device.  The only way for me to get back in is to do a factory reset.

 

Setup - Step 1

  • The EAP225 is connected to my Firewalla Gold firewall port 2
  • In the Firewalla Gold I created a physical LAN on port 2, starting with IP 192.168.x.x.
  • In the EAP225 I created 3 SSIDS:
    • IOT Data in the 2.4GHz
    • IOT Media in the 5GHz
    • A hidden guest SSID in the 5GHz (using the wireless portal)
    • None of the SSIDs are using any advanced settings, radio, load balance, etc.

 

VLAN - Step 2

  • In the EAP225 I tested using the following VLAN IDs (based on instructions from Firewalla FW)
    • IOT Data = VLAN ID 33 (only used for my IOT devices that only work on the 2.4GHz channel)
    • IOT Media = VLAN ID 44 (only used for IOT devices that can work on the 5GHz channel)
  • In the Firewalla Gold I configured VLANs also on port 2
    • VLAN 33 named IOT Data
    • VLAN 44 named IOT Media

 

Testing - Step 3

  • When I hit save and try to test everything out I see the EAP225 is online, but refusing connections.

 

Any advice?  Is there some sort of VLAN number convention I should be using instead of 33 or 44? I basically want to keep my IOT devices separated from my main LAN by using VLAN. In my firewalla, I have a rule so that the EAP225 does not communicate with the main LAN, but if I could do it with the EAP as well, then I know this feature is working as intended.

 

Thank you!

  0      
  0      
#1
Options
1 Accepted Solution
Re:Enabling VLAN with the EAP225 locks me out-Solution
2021-09-10 16:24:57 - last edited 2021-09-10 16:25:44

This issue is now resolved.  With help from a member from the Firewalla community, I was able to accomplish what I wanted to do with the EAP225.  The missing link was to create a separate admin SSID and to enable the Management VLAN option, which allowed me access to the AP while being able to create and manage the VLANs that I have created.

 

Thanks for viewing and for the help, much appreciated.

Recommended Solution
  0  
  0  
#9
Options
8 Reply
Re:Enabling VLAN with the EAP225 locks me out
2021-08-27 20:53:13

@RoarinRow 

 

Just a quick read at this and first thing comes to my mind is you don't have a switch.

 

Im not familiar with the Firewalla, but I know it is a router, VLANs trunking requires a switch to handle the vlan encapsulation of the packets, this I believe is your issue.  I have never known any router that could directly connect a VLAN AP, they all require switching in between

 

Just my 2 cents :)

  1  
  1  
#2
Options
Re:Enabling VLAN with the EAP225 locks me out
2021-08-27 21:39:16

@Philbert thanks for your input.  Firewalla is a firewall device that manages router functions so it alleviates CPU on the AP.  They seem to have tested it with the EAP225, not one has acknowledged my response there.

  0  
  0  
#3
Options
Re:Enabling VLAN with the EAP225 locks me out
2021-09-03 08:40:07

@RoarinRow 

 

Hey,

 

Is the port 2 of Firewalla a trunk port? And do different VLAN's have different subnets? I mean, do you configure VLAN interfaces?

  0  
  0  
#4
Options
Re:Enabling VLAN with the EAP225 locks me out
2021-09-03 15:30:11

@Somnus yes based on instructions I've read the Firewalla does VLAN trunking.  I'd post a link, but this forum software won't allow me at the moment.

 

This is how I had one of the VLANs setup in the Firewalla.  

 

  0  
  0  
#5
Options
Re:Enabling VLAN with the EAP225 locks me out
2021-09-06 03:23:52 - last edited 2021-09-06 03:24:45

@RoarinRow 

 

I'm not familiar with firewalla. Is the port selected means a tagged port? I just saw it's in VLAN33, but don't know its egress rule. Tagged port is what really matters.

  0  
  0  
#6
Options
Re:Enabling VLAN with the EAP225 locks me out
2021-09-06 06:17:17

@Somnus Thanks for your feedback.  I'll need to research further on the Firewalla side.

  0  
  0  
#7
Options
Re:Enabling VLAN with the EAP225 locks me out
2021-09-06 07:16:30
No problem! Any update, you can share with us.
  0  
  0  
#8
Options
Re:Enabling VLAN with the EAP225 locks me out-Solution
2021-09-10 16:24:57 - last edited 2021-09-10 16:25:44

This issue is now resolved.  With help from a member from the Firewalla community, I was able to accomplish what I wanted to do with the EAP225.  The missing link was to create a separate admin SSID and to enable the Management VLAN option, which allowed me access to the AP while being able to create and manage the VLANs that I have created.

 

Thanks for viewing and for the help, much appreciated.

Recommended Solution
  0  
  0  
#9
Options