Communications and Wireless
1849171 Members
5739 Online
104041 Solutions
New Discussion

Re: VLAN Issue?

 
Jason Baird
Advisor

VLAN Issue?

Here is the situation. I have 1 HP 720 and 1 740 setup using a wireless vlan. I will simplify. I have the HP ProCurve 4000 (2) with the wireless vlan tagged for the switch ports that the 420 APs are plugged into. I can ping anything on the wireless vlan but not on the default vlan 1. I can however ping a device on the default vlan on another switch. It seems like APs that are connected to a Procurve 4000 can ping anything on the default vlan but can ping to ANYTHING on another switch. Any ideas?
5 REPLIES 5
Mohieddin Kharnoub
Honored Contributor

Re: VLAN Issue?

Hi

Usuall to control any AP by using the Security access control, they should all connect to the 720 device.

Anyway
Have you done Vlan tagging from the AP side, in the SSID page?
What kind of authentication methode you are using in the 740 ? and do you allow a wireless client to reach the default Vlan ?
Usually a guest user will not be able to access the default Vlan, but the authenticated user is allowed based on the auth. policy.

More info about your setup will help us to find the problem.

Good Luck !!!
Science for Everyone
Jason Baird
Advisor

Re: VLAN Issue?

The 740 controls all the 15 or so APs. On each AP I have 2 ssid's 1 for private and 1 for guests. Both are tagged on the APs. We are using WPA-PSK TKIP for security currently until our AD upgrade happens. We have guest access set to allow access only to the Internet using the 42. addresses. While internal enterprise laptop and tablets have access to our network. The APs are using firmware 2.1.5 and the 700s are using 4.4.0.50. Hope this helps.

Jason
Mohieddin Kharnoub
Honored Contributor

Re: VLAN Issue?

Hi Jason

First of all, i have a similar setup, but i use only one SSID, and on the Portal, the user has to authenticate, so we will be having either a GUEST or STAFF, and staff authenitacte against the Active Directory, and of course we control the time and bandwidth fo rguest access.

And i beliEve that is better than having 2 SSIDs since one of the SSIDs will not be broadcasted by the AP, and its not convenient to give a security code for guests whenever they want to connect.

Now for the Tagging issue, i believe you don;t have to do that on the SSID or on the switch, because the 720 will give the user an IP address in a different range of your default Vlan, and its a Secure subnet and controlled by the security policy configured on the 740.

If you interested with this scenario i can give you more details :)

Good Luck !!!
Science for Everyone
Jason Baird
Advisor

Re: VLAN Issue?

When I back revved the firmware to 4.1.4.4 the problem mysteriously went away. Guess I won't be upgrading to 4.4.0.50 after all.

Jason
Mohieddin Kharnoub
Honored Contributor

Re: VLAN Issue?

Hi

Thats true, i found some issues in the version 4.4.0.50.
Science for Everyone