Best way to separate CPE management & subscriber traffic?

I’m looking to get some input regarding the best method for separating CPE management & subscriber traffic in a bridged environment.

What I’m trying to achieve:

  • RFC1918 address on CPE for management, segmented from customer traffic.


  • Customer traffic bridged onto VLAN at AP.


  • Low complexity provisioning of CPE.


  • RADIUS provisioning of rate limit with burst allowance.

I’ve utilized CPE’s configured for Station-Bridge, Station-WDS, and Station w/ VPLS tunnels…each of which do not provide all of the features I am looking for. VAP’s are not an option as they are not supported in the Nv2 wireless protocol.

I haven’t investigated doing this with PPPoE. I know it supports burstable rate limits, but I don’t know if it’s possible to segment my management & IP traffic with a VLAN. Does anyone have any suggestions for me?

I don’t know if I can help you but I’m interested in why you need to separate management and customer traffic? I guess when you say management traffic you mean when somebody changes a setting on a CPE or something? I just can’t think of any reason why you would go to all that trouble and what the benefit is separating it?