Multi-SSID VLAN with TL-WA1201 and TL-SG1016DE
I've got a TP Link TL-WA1201 access point which has support for multiple SSIDs and VLANs, and a TL-SG1016DE switch. I'm trying to get separate VLANs for WiFi devices so I can keep IoT devices, Smart TV and anything which only needs an internet connection separate from the rest of my home network, which has both wired and wireless devices.
I've read this https://www.tp-link.com/uk/support/faq/418/ which I thought meant that what I am trying to do should be possible. Although it doesn't mention what capabilities are required on the router, the port used from the AP on the Switch is marked as tagged, and the port for the router is untagged, which I thought meant that the egress traffic would be untagged (even if tagged traffic was received for that VLAN). Untagged traffic would reach my Sky router and all would be well, or so I thought.
I have setup three SSIDs on the Access Point which have VLAN IDs of 1 (not shown), 2 and 3. The SSID with VLAN 1 I'm planning on removing, but I can connect via WiFi and I get an internet connection. On the switch I have the default VLAN 1 with all ports as untagged members, including port 13 which is the Access Point.
I'm testing VLAN 3 but I haven't yet been able to get an internet connection using it. On the switch I have VLAN 3 with the Access Point port 13 a tagged member, and port 16 as an untagged member. I don't know why I can't get an internet connection on this VLAN. I've read other threads about asynchronous VLANs but that was with UniFi APs which were sending untagged traffic to the switch. I presume I could later on add ports 5 and 8 as shown below as either untagged members, or as tagged members and add a PVID of 3 to those ports and all devices on VLAN 3 would be able to see each other?
That's secondary though until I can get out to the internet using VLAN 3. Am I doing anything fundamentally wrong?