how to isolate vlan from others & WAP

May 25, 2007 2 Replies

Need the following objectives:



Need 1 WAP Cisco 1130 to have 2 SSID's and each one it's own separate VLAN. - Vlan 18 is going to for employess - Vlan 19 is going to be "public" it will only have access to Internet



I have 1 vlan for internet which is Vlan 154 I have Vlan 100 is for the servers



- Vlan 18 should comunicate with both of them. - Vlan 19 should only communicate with the internet Vlan, 154 but should also get a DHCP address from the server wich is 192.168.100.200



Help! How to isolate the VLan?



I have a similar set up at my office but we have a total of 4 ssids tied into different vlans. i am assuming that you know how to go through the web interface on the wap to configure the ssid and assign it to a specific vlan, i don't think that was the essence of your question. after that, what i have done is configure the switchport that the wap connects to, to trunk (pretty obvious) the vlans that I have tied the ssids to. as far as the rest of your question, i have implemented vlan acls that keep my Guest ssid/vlan from communicating with my internal ssid/vlan, they pretty much just have port 80 out of my network. your dhcp address should not be a problem just remember to allow udp/tcp port 53 through the acl. Is the dhcp server on the same vlan/subnet as the guest ssid? or are you using a helper? vlan acls can be tricky so i would approach them with caution...

i am not sure what type of gear you are working with, this is just the way i have implemented a similar scenario.

I have a Cisco 1130 WAP and a Catalyst 3560 -

Did you pub the ACL in the Guest at the switch or did you do it on the WAP??

How did you do the ACL can you explain that part? thanks!

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required