HCHTech
Well-Known Member
- Reaction score
- 4,157
- Location
- Pittsburgh, PA - USA
I need a bit of guidance for a simple setup - just when I think I've got the barest grip on this stuff, some little perturbation comes along and I'm off the rails again.
So, We have an small assisted living center client. There are two floors. We currently have a Sonicwall at the edge, 2 Unifi APs on the first floor and a single Unifi AP on the 2nd floor. We have the APs broadcasting a "resident" SSID (= guest network) with a VLAN tag and a private SSID that is untagged. I have the resident VLAN setup as a sub-interface on the Sonicwall for 3 of the ports that are part of the LAN zone. This means that untagged wifi traffic is part of the private network and wifi traffic with the VLAN tag is part of the resident network (which is in a guest zone on the Sonicwall). So far so good. This all works as desired. Guest network connections are individually isolated and cannot communicate with the private LAN. Private wifi traffic is not isolated and can communicate with the private LAN.
The Client wants to add an 2 additional APs on the 2nd floor AND provide some wired connections to a couple of the resident rooms. We want those wired connections to be on the resident (guest) network instead of the private LAN, of course.
They have a managed TP-Link (TLGS2008) switch they'd like to use for this purpose on the 2nd floor (The Sonicwall is on the first floor, and running additional lines to the 2nd floor is problematic, so they would like to avoid that). It's got 4 POE+ ports and 4 non-POE ports. For the APs, I believe I just need to tag the POE ports with the correct VLAN tag and I'm done. For the non-POE ports where we want to force the wired connections to be on the guest network, I'm trying to force all traffic on those ports to have that VLAN tag, I believe that's possible, but can't seem to make that happen.
Can someone translate my verbiage into the correct terms and give me a hint on how to accomplish this? TIA!
So, We have an small assisted living center client. There are two floors. We currently have a Sonicwall at the edge, 2 Unifi APs on the first floor and a single Unifi AP on the 2nd floor. We have the APs broadcasting a "resident" SSID (= guest network) with a VLAN tag and a private SSID that is untagged. I have the resident VLAN setup as a sub-interface on the Sonicwall for 3 of the ports that are part of the LAN zone. This means that untagged wifi traffic is part of the private network and wifi traffic with the VLAN tag is part of the resident network (which is in a guest zone on the Sonicwall). So far so good. This all works as desired. Guest network connections are individually isolated and cannot communicate with the private LAN. Private wifi traffic is not isolated and can communicate with the private LAN.
The Client wants to add an 2 additional APs on the 2nd floor AND provide some wired connections to a couple of the resident rooms. We want those wired connections to be on the resident (guest) network instead of the private LAN, of course.
They have a managed TP-Link (TLGS2008) switch they'd like to use for this purpose on the 2nd floor (The Sonicwall is on the first floor, and running additional lines to the 2nd floor is problematic, so they would like to avoid that). It's got 4 POE+ ports and 4 non-POE ports. For the APs, I believe I just need to tag the POE ports with the correct VLAN tag and I'm done. For the non-POE ports where we want to force the wired connections to be on the guest network, I'm trying to force all traffic on those ports to have that VLAN tag, I believe that's possible, but can't seem to make that happen.
Can someone translate my verbiage into the correct terms and give me a hint on how to accomplish this? TIA!