Hello Group,
I am wondering if someone can clarify a configuration for me. I posted earlier regarding this but my post may have confused people. So here goes,
In our company we have a Cisco 871 router (with the 4-port switch built in) a 2950 switch and a 1231 Access Point. We are trying to configure VLANS to support guest internet access and corporate internet access on the Access Point. In all documentation in states for good security to place all trunk ports in a VLAN that is not being used on any other port. Our configuration is as follows.
Router Fastethernet0 switchport trunk native vlan4 switchport mode trunk
Interface VLAN2 (corporate VLAN) IP Address 192.168.10.0 255.255.255.0
Interface VLAN3 (guest internet access) ip address 172.16.29.1 255.255.255.0
interface vlan4 (trunk VLAN) ip address 172.16.99.1 255.255.255.0
VLAN1 is disabled
switch
interfaceFE0/24 (trunk port) switchport trunk native vlan 4 switchport mode trunk
Interface Vlan2 ip address 192.168.10.2 255.255.255.0
Interface VLAN1 is shutdown
Access Point
Inteface BVI1 ip address 172.16.99.11 255.255.255.0
Interface DOT11Radio0.2 (corporate VLAN) bridge group 2
Interface DOT11Radio0.3 (guest VLAN) bridge group 3
Interface DOT11Radio0.4 (native VLAN) bridge group 1
interface Fasteth0.2 bridge-group 2
interface Fasteth0.4 bridge-group 4 encaps dot1q 4 native
So my question is I have the native VLAN on the switch AP and Router set up for VLAN4. SHould the IP Address of the AP's BVI1 interface be in the 192.168.10.0/24 range or is it correct to place it in the VLAN4 range of 172.16.99.0/24. If I change the IP address of the access point to 192.168.10.12/24 everthing seems to work, but if I leave it as
172.16.99.12/24 I can authenticate to the radio but can not pull down an IP address or if I manually assign myself one cannot ping anything at all. Another point is that if I assign the access point an IP address of 192.168.10.12/24 everything seems to work but I can nolonger manage the AP or ping it from a PC on the 192.168.10.0/24 network unless I configure a switch port for swithport access vlan 4 and then use a pc connected to that. Right now I do not have any restrctions on the router in terms of access-lists.Thanks you very much,
Joe