Issues with Multi-SSID VLAN

Issues with Multi-SSID VLAN

Issues with Multi-SSID VLAN
Issues with Multi-SSID VLAN
3 weeks ago - last edited 45 minutes ago
Model: TL-WA901ND  
Hardware Version: V5
Firmware Version: 3.16.9 Build 160929 Rel.37753n

I'm having issues with a Multi-SSID VLAN configuration, whereby I'm trying to implement a Guest Wifi SSID on VLAN 2. In my setup, I have the below:

 

  • 2 x TP-Link TL-WA901ND access points
  • 2 x TP-Link ES205G switches
  • 1 x HPE JL813A switch
  • 1 x SonicWall TZ270 firewall

 

The two access points are connected to their own ES205G switch. Both ES205G switches connect to the main JL813A switch - one switch is connected to port 3 on the JL813A, the other to port 9.

 

The SonicWall is connected to the JL813A switch on port 18.A virtual interface has been created on X0 (LAN) on the SonicWall (X0:V2). Ports 3, 9, and 18 have all been configured with Untagged on VLAN 1, Tagged on VLAN 2.

 

Each ES205G has all five ports Untagged on VLAN 1, Tagged on 2. The TL-WA901ND are configured in Multi-SSID mode, with Office Wifi on VLAN1, and Guest Wifi on VLAN2

 

DHCP has been configured on the SonicWall to provide DHCP to both the Office Wifi and Guest Wifi networks, each having theior own scope assigned to the relevant interface.The Office Wifi works fine on the default VLAN 1, but I can't get the Guest Wifi to work on VLAN 2 - the connection to the AP is established, but no IP is assigned.

 

I have tried connecting a laptop directly to a port on one of the ES205G switches (which has VLAN 1 Untagged, VLAN 2 Tagged), then set the VLAN ID 2 on the NIC to 2, and the connection works, with the device receiving an IP from DHCP on the SonicWall, and being able to browse the web - this makes me feel the issue is related to the APs. A diagram of the physical setup / VLAN config is below - any advice on why this is not working would be much appreciated.

 

  0      
  0      
#1
Options
1 Accepted Solution
Re:Issues with Multi-SSID VLAN-Solution
2 weeks ago - last edited 45 minutes ago

  @DavidRA 

 

If this setup is in production then you took the right approach.

Meanwhile here's an example for configuring VLANs on the Easysmart switches.

If this was helpful click on the arrow pointing upward to make it blue. If this solves your issue, click the star to make it blue and mark the post as a "Recommended Solution".
Recommended Solution
  0  
  0  
#6
Options
8 Reply
Re:Issues with Multi-SSID VLAN
3 weeks ago

Sorry, on the above diagram the ES205G on right should show as being connected to "Port 9 (VLAN 1 Untagged, VLAN 2 Tagged)" not Port 3 (the forum won't let me edit the original post until after 24 hours).

.

  0  
  0  
#2
Options
Re:Issues with Multi-SSID VLAN
3 weeks ago

  @DavidRA 

 

Make sure that you have updated your APs to its latest FW release - here.

The same goeas for the ES205G - here. Then test your connectivity.

If that still doesn't work for you, here's a guide oh how to configure the TP-Link multi-ssid AP and switch - double check your configuration.

If this was helpful click on the arrow pointing upward to make it blue. If this solves your issue, click the star to make it blue and mark the post as a "Recommended Solution".
  0  
  0  
#3
Options
Re:Issues with Multi-SSID VLAN
3 weeks ago

  @terziyski

 

Many thanks for coming back to me so quickly. I've started by upgrading the firmware on one of the two APs. Unfortunately, the AP has not come back up after the firmware upgrade, despite showing a "Successful upgrade" message shortly before rebooting. I am not at the same site as the hardware, so I can't currently check the LED status, etc. I should be able to contact someone at the site later today to check this for me, though.

 

In terms of the setup guide, I had seen this, but I may need some assistance in understanding the approach. The article suggests setting Port 2 (the firewall/router port) with multiple Untagged VLANs - my understanding where VLAN configuration is concerned is that this is not good practice, and therefore some switches (such as the HP switch that is in this configuration) do not even provide the facility to do so - e.g. how does the port know which VLAN ID to settle on once any unknown tags are stripped out? There doesn't appear to be any logic in being able to set multiple VLANs as Untagged on the same port unless I'm missing something different about TP-Link hardware?

 

Either way, as the firewall is connected to the HP switch, I can't set port 18 to Untagged for both VLAN 1 and VLAN 2, as it's not possible to do so. Any further advice on this would be much appreciated.

 

smiley

 

  0  
  0  
#4
Options
Re:Issues with Multi-SSID VLAN
2 weeks ago

  @terziyski

 

Just a quick update on this, I ended up getting someone onsite to power cycle the AP, and it has now come back online again (albeit it in a factory reset state) - the update did apply, however.

 

 

I have reinstated the previous settings and will be testing the Guest Wifi SSID later today, so will report back with any news. I have since disabled the Guest Wifi SSID on the other AP that is still installed with the older firmware. No switch firmware updates have been applied as yet, as I'd like to stage the updates to minimise downtime.

  0  
  0  
#5
Options
Re:Issues with Multi-SSID VLAN-Solution
2 weeks ago - last edited 45 minutes ago

  @DavidRA 

 

If this setup is in production then you took the right approach.

Meanwhile here's an example for configuring VLANs on the Easysmart switches.

If this was helpful click on the arrow pointing upward to make it blue. If this solves your issue, click the star to make it blue and mark the post as a "Recommended Solution".
Recommended Solution
  0  
  0  
#6
Options
Re:Issues with Multi-SSID VLAN
2 weeks ago

  @terziyski

 

Thanks for providing the additional link. I still don't quite fully understand the advice around setting multiple VLANs as Untagged on the same port(s), though - this goes against common practice.

 

I can certainly try this on the ES205G switches, though.If I'm reading the second article correctly, am I right in thinking that Port 1 and Port 2 on both switches should be set to VLAN 1 = Untagged and VLAN 2 = Untagged?

  0  
  0  
#7
Options
Re:Issues with Multi-SSID VLAN
2 weeks ago - last edited 2 weeks ago

  @terziyski

 

Actually, looks like the Guest Wifi is now working as I can now see a device connected, so I suspect this was fixed by the firmware upgrade. I'll repeat the work on the second AP, which should resolve the issue completely.

 

 

 

 

  0  
  0  
#8
Options
Re:Issues with Multi-SSID VLAN
2 weeks ago

  @DavidRA 

 

Sounds good. Be sure that you have the latest FW ( ES205G(UN)_V1_1.0.4 Build 20250609 ) on the switch as well - here.

If this was helpful click on the arrow pointing upward to make it blue. If this solves your issue, click the star to make it blue and mark the post as a "Recommended Solution".
  0  
  0  
#9
Options