OC200 - VLAN's wireless network and Guest Portal issues

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

OC200 - VLAN's wireless network and Guest Portal issues

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
OC200 - VLAN's wireless network and Guest Portal issues
OC200 - VLAN's wireless network and Guest Portal issues
2022-05-04 13:22:27
Model: OC200  
Hardware Version: V2
Firmware Version: 5.0.30

Hi There, I hope you can help a newbie out.


I have the following setup:
Router - Draytek
Switch - HP Aruba J9773A
Omada Controller OC200
AP - EAP245(EU)V3.0

 

Router IP 192.168.15.254 (setup with 2 network IP Ranges and DHCP enabled on Both)
Controller IP 192.168.15.253


Router connected to Port 1 on switch Tagged on both Vlans 1000 & 1500
OC200 Controller connected to Port 2 on switch Untagged on Vlan 1000 and Tagged on 1500
AP connected to Port 3 on Switch Untagged on on Vlan 1000 and tagged on 1500


Wired VLAN Networks setup on Controller 
   CORP - 1000
   Guest - 1500

 

Adopted an AP and given a static IP 192.168.15.1
Setup a Wireless Network called CORP with VLAN disabled
Setup a Wireless Network called Guest with VLAN enabled on VLAN 1500 (set as a guest Network)

 

I can see both SSID's broadcast from the AP and can connect to them both and I am given a correct IP address from the router depending on which network I connect to:
CORP 192.168.15.x
Guest 10.10.0.x

 

If I enable a Portal and apply it to the CORP SSID, my phone connects to the network, gets a correct IP address, tells me I need to sign in, click sign in, Portal window loads up OK and I click to agree to the T's&C's, and I am authorised onto the network and it works perfectly

 

If I enable a Portal and apply it to the GUEST SSID, my phone connects to the Network, gets a correct IP address, tells me I need to sign in, click sign in, thinks about it for a while then tells me:

 

Web Page not Available
The web page at 
http://192.168.15.253:8088/portal/entry?.....
Could not be loaded because:
net::ERR_CONNECTION_TIMED_OUT

 

I think I may need some help in setting up some Access Control Lists, but as a newbie I have not done this before and need some guidance from you kind people.

 

Regards,
Mark.
 

  0      
  0      
#1
Options
5 Reply
Re:OC200 - VLAN's wireless network and Guest Portal issues
2022-05-04 17:25:50

  @MarkyP 

 

I think if you just untag VLAN 1500 on port 2 which is connected to the OC200 AND in your router create a route or NAT port map from the 10.x.x.x guest subnet so it can see the OC200 IP.

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#2
Options
Re:OC200 - VLAN's wireless network and Guest Portal issues
2022-05-05 09:00:56
Hi There, I can't do this as port 2 on the switch (the port the OC200 is patched into) as the port is already untagged on VLAN 1000 which is needed to be able to see the AP's when they come online and adopt them. Can only be untagged on 1 VLAN. Regards, Mark.
  0  
  0  
#3
Options
Re:OC200 - VLAN's wireless network and Guest Portal issues
2022-05-05 14:36:17

  @MarkyP 

 

Well you have a problem because the OC200 doesn't tag traffic.  My TPLINK 2008 $70 switch will untag multiple VLANs per port...I'm surprised yours doesn't.

 

I went looking for proof, and I found it in post #8 of this thread, paragraphs 3 and 6

 

https://community.tp-link.com/en/business/forum/topic/174738 

 

He's a LV6 contributor...so probably knows what he's going on about :)

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#4
Options
Re:OC200 - VLAN's wireless network and Guest Portal issues
2022-05-05 14:44:14 - last edited 2022-05-05 14:46:05

  @MarkyP 

 

Seems this Arbua 1 untag per port is a thing after all

From the community hpe com site /t5/Aruba-ProVision-based/Possible-on-untag-port-for-multiple-VLANs-and-passing-the/td-p/6475680 

 

I think you either need to fix this somehow in your router via NAT or static routes, or get an Omada switch.

 

for what it's worth I thought I could live without Omada switches too...but their router functionalities are pretty limited without a matching switch attached.

 

<< Paying it forward, one juicy problem at a time... >>
  0  
  0  
#5
Options
Re:OC200 - VLAN's wireless network and Guest Portal issues
2022-05-05 17:43:31

  @d0ugmac1 

 

ok thanks for your help on this matter, i will asses the necessity for a captive portal, it is something we would 'like' but not a deal breaker.

 

time to start looking at this from the router end then I guess. ;)

 

Much Appreciated.

  0  
  0  
#6
Options