So you’re saying that in all the configuration of the cAP I just need to remove the pvid=1000 vlan-filtering=yes from the following part of the configuration? Just that?
/interface bridge
add name=bridge pvid=1000 vlan-filtering=yes
Probably it’s me that missed some part of the documentation and that I followed this forum post that was actually more updated than the documentation itself but it explicitly stated to actually enable vlan-filtering. Can you explain where and why I was wrong? In the meantime I’ll try to re-do the cAP without the vlan filtering.
EDIT: I did everything back again the same exact way and now even with vlan-filtering disabled the CAPsMAN can see the cAP and can tell them to enable to WiFi SSIDs. The client machines can enter the WiFi network and still can ping each other (with static IPs like 10.2.2.51 and 10.2.2.52) but not their default gateway with IP 10.2.2.1 (the firewall) and they still cannot ping a wired machine connected to the switch on a port configured to be access on VLAN 2000. The same wired machine can correctly ping the default gateway (from 10.2.2.50 to 10.2.2.1).
What’s driving me crazy is that if I enable the DHCP client on the two wireless devices I can see a DHCP discover and a DHCP offer if I enable the packet capture on the firewall. This means the L2 frame correctly gets to the switch and then to the firewall-router. I cannot understand why the DHCP offer doesn’t come back to the WiFi client devices.
EDIT2: to be fair now without VLAN filtering I cannot even see the DHCP discover coming to the firewall-router and obviously I cannot see the DHCP offer departing from the firewall-router. It actually seems to have made me going the opposite direction of where I wanted to go. I would love to understand if this is because of another missing configuration is it is actually a wrong direction, especially considering the post I mentioned before which clearly says to enable the VLAN filtering. I definitely need to explore more under the hood.