Virtual CHR as CAPsMAN for cAP ax with multiple SSIDs/VLANs and third party router/switch

Yes, I’m referring to the VLAN part. After some troubles I discovered that this link is actually for old versions and not applicable to me. The theory at least is the same but since my AP doesn’t have the /caps-man menu I have to refer to the new documentation.

Which appears to be this page here. Still it has the old /caps-man commands, though.

Unfortunately I could only find this forum post with the proper commands. I obviously had to adapt the commands to my usercase since I have a separate router from the CAPsMAN and what I don’t understand is if I did this step correctly.

Just to be clear about my intentions, I need to send clients from ssid_private to VLAN 2000 and clients from ssid_guest to VLAN 3000. Both the VLANs have to get out of ether1 on the cAP and go to the switch. That has to send the two client VLANs to the appropriate destination (basically the firewall-router that’s responsible for connecting everything to the internet) while the management VLAN 1000 has to go to the same L2 section where there also is the CHR VM. That’s the only thing I’m sure it’s working consistently. The cAP can ping with no problems the CAPsMAN every single time so I’m sure VLAN 1000 gets out of ether1 of the cAP with the proper TAG.