Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi

Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi

Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
2026-04-24 07:36:10
Model: EAP653  
Hardware Version: V1
Firmware Version: 1.3.7

Hi all,

 

For various reasons my Omada controller is running in a container on a computer connected via Wifi, I know it's not an ideal situation but until the cabling situation is sorted it is what it is.

 

It's a very basic setup with a simple stupid non-Omada switch/router, software Omada Controller (v6.2 now) and a couple of EAPs. Everything on a single network.

 

This all worked brilliantly as long as it was connected to an old EAP225 AP (v3 ver 5.2.3).  Plugging in a new device in the network worked fine, just wait until the device showed in the Omada controller device list and adopt it.

 

However, when changing the AP serving the controller computer to an EAP653 (v1 ver 1.3.7) new devices suddenly doesn't show up in the device list. Old devices are still managed OK, I have connectivity to the new device (I can ping it and access it's web interface) but it simply doesn't show up in the device list allowing me to click adopt!

 

Changing the AP back to the EAP225 it shows up and can be adopted fine.

 

Do any of you know if this might be  due to some setting I've done in my Omada WLAN setup that only takes effect with newer EAPs, or some hidden security feature in the newer EAPs to avoid having rogue Wifi clients adopting devices?

 

I'd really prefer not having to use the old EAP until I've got the cabling situation sorted, so if there's a setting for this I'd be happy to know about it.

 

  0      
0
#1
Options
6 Reply
Re:Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
2026-04-24 09:17:03 - last edited 2026-04-27 07:00:25

  @ZNikke 

 

I have never tested this and its a bit of a niche setup until you sort the cables, but im not familiar with anything that might prevent adoption over wifi as long as

 

- the SSID isnt in guest mode

- you dont have any EAP ACLs configured that would restrict your controller IP

- your single SSID is correctly configured for the native management vlan

  0  
0
#2
Options
Re:Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
2026-04-28 03:40:14

Hi  @ZNikke 

 

Thanks for posting here.

To confirm, new device refers to the EAP653 and old device refers to the EAP225, right?

 

To understand the situation better, please give us the following info:

1. Screenshots of the device list page and the topology page when the controller is connecting to the EAP225;

2. Screenshots of the device list page and the topology page when the controller is connecting to the EAP653;

3. When connecting the controller to the EAP653, is the EAP225 unplugged from the network? 

4. A screenshot of the SSID list page;

5. When connecting the controller to the EAP653, did the Internet access of the network affected?

  0  
0
#3
Options
Re:Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
2026-04-30 09:18:36

Hi  @Vincent-TP 

 

EAP653 and EAP225 refers to the AP that serves Wifi connection with the computer running the Omada Software controller.

 

"New devices" refers to ANY new device connected to the network that is expected to show up in the adoption list.

 

With an EAP653 as the AP serving my Omada Software controller computer no new devices shows up for adoption in the list.

 

Replacing the EAP653 with an EAP225 then new devices shows up and I can adopt them fine. Both of those EAPs are adopted/configured in the system, but I swap which is connected so only one at a time. I should note that the new devices shows up very fast when I replace the EAP653 with the EAP225, even before the Omada controller detects that the EAP653 is down...

 

Note that I have IP connectivity to the new devices regardless of which AP serves my Omada Software controller computer, ie ping and web interface access works.

 

Also note that after I have adopted the device, I can switch the AP serving my Omada Software Controller computer back to an EAP653 and everything still works.

 

This is why I suspect that there is some kind of broadcast/multicast/udp related filtering going on (depending on what is actually used to implement the device announcement for adoption detection/notification thing).

 

I'll see if I can cobble together some screenshots, but the only difference shown on them would be the new devices being present in the list for adoption or not.

 

 

  0  
0
#4
Options
Re:Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
2026-05-06 03:29:22

Hi  @ZNikke 

 

Thank you for your reply. So, the new devices you mentioned refer to SDN devices that were newly connected to the network after the controller was connected to the EAP653, correct?

Additionally, since switching to EAP225 allows normal adoption of new devices, after switching back to EAP653, the controller can still manage these devices properly, right?

 

To clarify, let me give an example: Suppose we now connect the controller to the EAP653, and then plug in a new EAP610 to this network. At this point, the controller cannot discover this EAP610. However, if we switch the controller to the EAP225, it can successfully discover and adopt this EAP610. Then, when we switch the controller back to the EAP653, this EAP610 will still appear in the device list and can be managed normally, correct? But in this case, if we add another EAP650 to the network, the controller still won’t be able to discover this new EAP650, right?

  0  
0
#5
Options
Re:Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
2 weeks ago

  @Vincent-TP Hi, sorry for being slow to answer. Travel, work and whatnot...
Your example exactly describes what I am experiencing, although I have EAP653s and no 650/610. I should note that I haven't verified this with the latest minor version of the controller though, I should be able to bring another EAP653 to test this by end of next week.

A theory of mine is that it has something to do with broadcast/multicast-to-unicast things that the APs can do, but I haven't had time to investigate this further after solving my initial adoption problem by temporarily downgrading the AP my controller computer connects to...

 

  0  
0
#6
Options
Re:Firewall/filter in EAP653 not present in EAP225 prohibiting Omada discovery when controller on Wifi
Yesterday

@Vincent-TP Hi, tried now with latest controller version and behavior is the same. I did some fiddling, and it seems that as soon as the controller has discovered the new AP I can swap the AP the controller connects to from the temporary EAP225 back to the EAP653 and continue the adoption process.

 

This points toward the actual discovery being the issue, suggesting broadcast/multicast issues.

 

  0  
0
#7
Options