RB750 + 2 EAP225, VLAN Setup

Hello all,

Finally made the leap from the consumer blaster world. Picked up a hEX and 2x TP-Link EAP225v3 WAPs. Initial setup is fine, largely plug & plan with a couple port forwards and that’s it.

Next step is setting up a seperate SSID/VLAN for my IoT junk, to segregate it from my personal home LAN. Also, I’d like to setup guest WiFi. The WAPs support 802.1q, SSID Isolation, and Guest Portal.

Goal:

  1. Wired/Wireless LAN: All my personal devices I manage
  2. WLAN only for IoT Devices
  3. Guest Wifi

I’ve attached a pic of my hardware layout. My confusion lies in how to set this up.

Question:

  1. Looking at the Webfig, where do I start for VLAN setup? → Interfaces? Bridge? Switch?
  2. TP-Link WAP configuration shows VLAN ID, do I just set that ID to the ID I create in the hEX?
  3. Looks like I may not need a VLAN for Guest WiFi, if I enable Guest Portal with authentication and SSID Isolation. Is this a good solution?

Thanks for your help! I look forward to learning more.
Network Layout.jpg
TPLINK SSID VLAN.PNG

Did you get this done with your setup? I have nearly the same config and I’m trying to do the exact same thing.

Hex S and 2 x EAP245

2 x SSIDs, one for general use and one for IoT devices.

I want to segregate the IoT Devices by VLAN.