Access Points failing to tag traffic for VLAN 43 - VLAN 33 and 113 work correctly

Access Points failing to tag traffic for VLAN 43 - VLAN 33 and 113 work correctly

Access Points failing to tag traffic for VLAN 43 - VLAN 33 and 113 work correctly
Access Points failing to tag traffic for VLAN 43 - VLAN 33 and 113 work correctly
14 hours ago
Model: OC200  
Hardware Version: V1
Firmware Version: 1.40.18 Build 20260506 Rel.74003 (Stable)

Product: Omada Controller + EAP Access Points + TL-SG1218MPE switch

 

Issue Description:

I have a pfSense firewall/router with multiple VLANs configured. The following VLANs are working correctly:

  • VLAN 33 (Staff network) - Works via SSID "KAOWiFi"

  • VLAN 113 (Guest network) - Works via SSID "KAO-Guest" (Guest mode enabled)

However, VLAN 43 (OfficeIoT) does NOT work on ANY SSID I create.

 

What I have verified:

  1. pfSense configuration is correct - VLAN 43 interface is up (192.168.43.1/24), DHCP server is running with pool 192.168.43.150-199, and static reservations exist

  2. Switch configuration is correct (TL-SG1218MPE):

    • Ports 3 & 4 (connected to APs): VLAN 43 = Tagged, PVID = 1

    • Port 10 (wired device): VLAN 43 = Untagged, PVID = 43

    • Port 1 (connected to pfSense): VLAN 43 = Tagged, PVID = 1

  3. Wired device on VLAN 43 works - A fingerprint device (TA500) on port 10 gets IP 192.168.43.3 successfully

  4. Packet capture on pfSense shows VLAN 43 traffic from the wired device, but NO DHCP discover packets from WiFi clients trying to connect to VLAN 43 SSIDs

  5. I have tried:

    • Creating a brand new SSID (TEST-VLAN43) with VLAN 43

    • Enabling Guest mode on the test SSID

    • Adding an "Allow All" firewall rule on pfSense for VLAN 43

    • Rebooting the Access Points

 

Result: When any device (phone, Smart TV) tries to connect to a VLAN 43 SSID, it fails to obtain an IP address. The device connects to the SSID but never receives a DHCP lease. The same devices connect successfully to VLAN 33 and VLAN 113 SSIDs.

 

Question: Why are my Access Points failing to tag client traffic with VLAN 43 when they correctly tag VLAN 33 and VLAN 113? Is there a known limitation or bug with certain VLAN IDs on Omada APs?

 

Environment

  • Omada Controller version: OC200 1.0 1.40.18 Build 20260506 Rel.74003 (Stable)

  • EAP firmware version: EAP670(EU) v2.0 v1.3.7

  • Switch: TL-SG1218MPE 5.0 1.0.0 Build 20230616 Rel.57668

0
0
#1
1 Reply
Re:Access Points failing to tag traffic for VLAN 43 - VLAN 33 and 113 work correctly
7 hours ago

Hi  @tmeita 

 

Thanks for posting here.

We don't have a known issue of this type. To find out the reason, please give us the following info:

1. Screenshots of the pfSense firewall VLAN settings;

2. Screenshots of the switch VLAN settings;

3. Screenshots of the EAP VLAN43 SSID config pages;

 

In the meantime, please test the following and let us know the result:

1. Create a new SSID in VLAN43, without a password and any other advanced settings;

2. Change the VLAN43 ID to another number, such as 100, and let us know the result. This change should be done on the firewall, switch, and EAP.

3. If you don't mind, please forget the EAP and re-adopt it, see if the same situation persists.

 

0
0
#2

Information

Helpful: 0

Views: 42

Replies: 1