EAP sending traffic both tagged and untagged
I have a new EAP670v1 running 1.0.3. This is my first Omada configuration.
I have a very simple setup, 2 SSIDs, one on 2.4 and the other on 5 Ghz. Both SSIDs are assigned VLAN100. The mgmt vlan is 600, but is sent as a native, so untagged.
After the AP starts taking on clients, it starts sending data on both VLAN100 and 600 intermittently, so nothing is able to communicate with the network correctly. Output from Cisco switch (I've highlighted a duplicate as an example):
switch1#show mac address-table interface gigabitEthernet 1/0/8
Mac Address Table
Vlan Mac Address Type Ports
---- ----------- -------- -----
100 14c1.4e65.ff86 DYNAMIC Gi1/0/8
100 14c8.8b24.ec39 DYNAMIC Gi1/0/8
100 201f.3bd8.4930 DYNAMIC Gi1/0/8
100 582f.407e.4b59 DYNAMIC Gi1/0/8
100 9c76.13d8.3131 DYNAMIC Gi1/0/8
100 a45e.60be.5231 DYNAMIC Gi1/0/8
100 a477.3375.c856 DYNAMIC Gi1/0/8
100 d436.398f.7944 DYNAMIC Gi1/0/8
600 14c8.8b24.ec39 DYNAMIC Gi1/0/8
600 1c61.b4cc.6764 DYNAMIC Gi1/0/8
600 5231.8100.0064 DYNAMIC Gi1/0/8
600 5231.8100.c064 DYNAMIC Gi1/0/8
600 a45e.60be.5231 DYNAMIC Gi1/0/8
600 ec39.8100.0064 DYNAMIC Gi1/0/8
I have tried moving the management VLAN to a tagged VLAN, but the packed still arrive as duplicates, on VLAN1 instead.
The data is being sent in a load balanced method, oddly. If I block every other VLAN, traffic is dropped from the client perspective, but I suspect the EAP is still trying and the switch is just dropping the traffic.
Anyone have any troublehsooting ideas? I am out of ideas.
switchport trunk native vlan 600
switchport mode trunk
spanning-tree portfast edge trunk
spanning-tree bpdufilter enable
spanning-tree guard root