<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Yet another issue with msm 730 - 760 guest access and Vlan Configuration in M and MSM Series</title>
    <link>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5388073#M2539</link>
    <description>&lt;P&gt;maybe your switch is routing or your firewall is routing&lt;/P&gt;</description>
    <pubDate>Fri, 11 Nov 2011 13:58:50 GMT</pubDate>
    <dc:creator>MSMenthousiast</dc:creator>
    <dc:date>2011-11-11T13:58:50Z</dc:date>
    <item>
      <title>Yet another issue with msm 730 - 760 guest access and Vlan Configuration</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5291463#M2536</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi HP MSM's mates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since a few weeks (or month) we try to add a guest access to our existing wireless configuration :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;MSM730 controlller&lt;/LI&gt;
&lt;LI&gt;Few AP's connected on the lan port into a specific VLAN on the switche(s) (unttaged)&lt;/LI&gt;
&lt;LI&gt;Hp PoE switches&lt;/LI&gt;
&lt;LI&gt;2 VSC each egressed to a different vlan on internet port :&lt;/LI&gt;
&lt;LI&gt;First VSC = business &amp;gt; egressed to vlan 2 on the internet port with an ip adress &amp;gt; this internet port connected to a firewall on vlan 2 to connect to the rest of the network&lt;/LI&gt;
&lt;LI&gt;Second VCS = guest &amp;gt; egressed to vlan 4 on the internet port with an ip adress &amp;gt; internet port connected to the same firewall / routeur on the vlan 4 to connect to map to the internet.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Specials options on the MSM :&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Expand Internet port subnet to the Lan Port&lt;/LI&gt;
&lt;LI&gt;Dhcp relay on each VSC, redirecting each VSC to 2 different dhcp server. IP adressing works fine.&lt;/LI&gt;
&lt;LI&gt;Access control enabled on each VSC.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;With this configuration we can connect to each VSC an obtain the good IP adress and association.&lt;/P&gt;
&lt;P&gt;You can ping controller vlan on the internet port and firewall vlan port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;1-&lt;/STRONG&gt;&lt;/EM&gt; Does this configuration seems to be correct for you?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;2-&lt;/STRONG&gt;&lt;/EM&gt; The lan port seems to doing route job beetween the two VLAN (and then between the two VSC). So even if a client of one VSC can't ping a client on the other VSC, I'm suprised to see that a client associated on a VSC can ping the VLAN port of the other VSC. The Vlans dont's seems to be completely isolated.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;3-&lt;/STRONG&gt;&lt;/EM&gt; How do you configure the routing table to permit to the two VSC clients to be routed to the good place on the firewall ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this is not too confusing. I can give additionnal informations on demand. Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S : If I completely mismatch the good configuration could you suggest me the good one? Bye&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. This thread has been moved from Communications, Wireless (Legacy ITRC forum) to MSM Series. - Hp Forum Moderator&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 03:16:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5291463#M2536</guid>
      <dc:creator>Poilou</dc:creator>
      <dc:date>2013-12-02T03:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Yet another issue with msm 730 - 760 guest access and Vlan Configuration</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5292791#M2537</link>
      <description>&lt;P&gt;I answer to myself, but unfortunately not to tell you that I solved my problem.&lt;/P&gt;&lt;P&gt;I really don't understand WHY my two Vlans aren't perfectly isolated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A user connected to a VSC egressed to a Vlan X can ping the adress of the internet port of MSM VLAN's Y !&lt;/LI&gt;&lt;LI&gt;That certainly the reason why I can't put two routes in the routing table. I'd like to put one route per vlan, but this, as we can guess, crash the controller&amp;nbsp; management interface. (the packets don't know which route to use).&lt;/LI&gt;&lt;LI&gt;Ho can I correctly isolate my two Vlans??? (or where do I make a network mistake?)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any help would be fully appreciated...&lt;/P&gt;&lt;P&gt;Poilou&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2011 13:02:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5292791#M2537</guid>
      <dc:creator>Poilou</dc:creator>
      <dc:date>2011-08-05T13:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Yet another issue with msm 730 - 760 guest access and Vlan Configuration</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5294387#M2538</link>
      <description>&lt;P&gt;Another try, another problem :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really don't know how to isolate (separate) traffic between two VSC. No success with Vlan configuration, no success without.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't find how to make the internal firewall works, because it controls the internet port and all trafic follow the bridge port to communicate inter-vsc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even with the "Allow traffic between "no" Wireless clients", my public clients ping the workers clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No one?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2011 15:32:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5294387#M2538</guid>
      <dc:creator>Poilou</dc:creator>
      <dc:date>2011-08-08T15:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Yet another issue with msm 730 - 760 guest access and Vlan Configuration</title>
      <link>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5388073#M2539</link>
      <description>&lt;P&gt;maybe your switch is routing or your firewall is routing&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2011 13:58:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/m-and-msm-series/yet-another-issue-with-msm-730-760-guest-access-and-vlan/m-p/5388073#M2539</guid>
      <dc:creator>MSMenthousiast</dc:creator>
      <dc:date>2011-11-11T13:58:50Z</dc:date>
    </item>
  </channel>
</rss>

