I updated my wAP's to 6.41.2 and would like to configure them as best as possible to avoid mistakes, security leaks, bandwidth loss, etc ... to be honest, I was not successful to do it nor to find a perfect red-line-story / tutorial
My target is to distribute some radios as vAP to connect un-tagged clients, eg: NAS, Notebooks, Smartphones, Tablets, IoT, etc...
On the (only one) ether1, there is a trunk with vlan1-un-tagged and some additional tagged-vlans (10,20,30,40,50,60,70,80,90).
All vlans are external (L3/Firewall) managed by GW, Routing, DHCP-Server, NTP, etc ... that works fine with 6.40.3.
vlan1 (un-tagged) is the administrative vlan only with network 10.0.100.0/24. In this network there are the L3/Firewall, some Switch and some wAP-ac.
vlan10 = 10.0.10.0/24
vlan20 = 10.0.20.0/24
etc.
Now, I would like to set-up a well working configuration
I created a bridge with following setup:
- ARP, enabled
- IGMP Snooping, unchecked
- Fast Forward, unchecked
- Protocol mode, none
- PVID = 1
- VLAN Filtering, unchecked
- DHCP-Client (on DHCP-Server as static / MAC "connected")
- Bridge IP = 10.0.100.4
Now I added ether1 to the bridge via Port ...
Ether settings are:
- PVID = 1
- Frame Types = admit all
- Ingress Filtering, unchecked
- HW Offload, unchecked
Than I added wlan1 (2.4GHz) and wlan2 (5GHz) via bridge port with following configuration (these bridge ports are usually inactive to avoid to put my administrative vlan1 on the air):
- Mode = ap bridge
- WMM Support, enabled
- Bridge Mode, enabled
- VLAN Mode = no tag
- VLAN ID = 1
- Frame Types = admit all
- Ingress Filtering, unchecked
- HW Offload, unchecked
Now, if I connect wit my MBP to the wlan2, than it see some big bandwidth loss from (on average) approximately 700 Mbps (1,000) to 60 Mbps what make me not that happy
Is there any miss-configuration in my first step with only vlan1 on the air ?
Here some examples of OK and NOK:
The second step, my main step, is to add vAP according to my VLANs ... but this, I maybe will describe after may bandwidth topic with vlan1 is solved ...
Any help is really very appreciated
Have a nice day !!