EAP245 not assigning vlans
Hi there,
I have a new EAP245 I am trying to deploy on site.
I have an existing AC1200 that works with no issues.
I have 4 SSIDs, each one is associated with a different vlan (10,20,30,40).
The DHCP server for each VLAN is sitting on the Fortigate firewall.
When attempting to connect to an SSID on the new EAP245 the client never obtains an IP address, and defaults to 169.x.x.x
A packet capture on the Fortigate shows no DHCP traffic ever reaches it. If I plug the old AP into the same port, it all works as expected (clients get an IP from each vlan depending on the ssid).
This points to an issue on the AP. Each SSID is assigned a vlan.
Are there known issues with this?
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
What type are the existing access points, and how have you configured the vlan on the access points? some screenshots would help.
Is there a problem with all the VLANs
- Copy Link
- Report Inappropriate Content
Screenshot attached of the SSID and VLAN [have also tried attaching as a network and tagging the LAN interface (vlan)]
All VLANs have the same problem; but only if going through the EAP245v3; if I connect a laptop to the port; or my old AP with VLAN'd SSID's; every client gets an IP.
- Copy Link
- Report Inappropriate Content
I understand, but there is no screenshot, I was also wondering what the old access points are called. If the access point gets an IP address, VLAN1 should work. You almost have to explain a little more about how you have set up your network, then it is easier to give help.
- Copy Link
- Report Inappropriate Content
@MR.S sorry for some reason can't get screenshots or files to load!
Have added screenshots to imgur below:
https://imgur.com/a/UDXuuvV
Current AP is a AC1200 non Omada TPlink access point. SSID's configured the same (ssid name and vlan added)
- Copy Link
- Report Inappropriate Content
The Omada setup looks correct, so if all VLANs are tagged out from the Fortigate router then it should work.
But why are you using DHCP relay? It's not necessary, is it?
Is VLAN1 untagged out from the Fortigate router?
- Copy Link
- Report Inappropriate Content
@MR.S yeah I didn't have the dhcp relays configured at first; ended up putting them in as a hail mary.
I've removed them again now just as a test - no change.
VLAN1 isn't configured on the fortigate at all actually.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
@MR.S VLAN 90 as management on switch and AP (AP gets DHCP from VLAN 90)
If I create a test SSID with no vlan configured - it gets a DHCP lease from the default interface pool on the Fortigate - so the communication is definitely there. It's just something happening with the VLAN tagging from the SSID's - just not sure if I keep troubleshooting or return the thing!! It's driving me nuts!!
- Copy Link
- Report Inappropriate Content
yes there is something with your VLAN settings, but VLAN is VLAN, tagged vlan 10 should talk to tagged vlan 10 regardless of brand, so you have to check your vlan settings, the tag must follow all the way. it is not so easy to give any advice as long as I do not have an overview of your entire network. in the starting point Omada switches and access points need an untagged network to function, so you have to look at the vlan management on your switch and access points that the untagged network matches the fortigate,
you are using vlan 90 which I assume is untagged.
- Copy Link
- Report Inappropriate Content
Hi @kidhexa
Is the issue fixed?
Do you have a switch? Is it TP-Link? If not, we also need the VLAN config for the switch.
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 683
Replies: 10
Voters 0
No one has voted for it yet.
