VLAN Management – How to Manage Access Point in a Different Subnet

access-pointmanagementprivate-vlanvlan

I am trying to setup a separate private network for a rented office in our building. I think i have succeeded in setting up two private LAN networks using port based VLAN's (192.168.10.0/24 and 192.168.20.0/24).

As the access points are required to be setup using management software on a computer I want to manage each access point from the control station without being able to communicate with the 192.168.20.0/24 network, is this possible? If not, what would be a way to have to private LAN's that cannot communicate with each other but would allow me to manage all access points.

enter image description here
Updated network:
enter image description here

Best Answer

One of your WAPs is in the 192.168.20.0/24 network on an unmanaged switch. That presents a problem if the controller is not allowed to access that network. What you really want to do is set up each WAP with a trunk. You want to trunk a management VLAN to the WAPs, along with the user VLANs for the WAPs. Unfortunately, you can't trunk with an unmanaged switch.

The ideal way is to create a management VLAN, and have the WAPs and the controller all connected to that VLAN. You also trunk whichever user VLANs you want the WAPs to advertise through SSIDs. You will need to replace the unmanaged switch with one that can do VLANs. This will also make the management of the WAPs more secure, and you can use the management VLAN to manage the switches, too.

Related Topic