This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Issue with access point on vlan ping times and dns

Hello, we've setup 3 apx 530 access points and are having some issues with vlans and dns.

Some background.

We have 2 ssid's setup.

One ssid is a guest network with no vlan.

The other ssid is setup to authenticate logins with a ms nps server. And we have several policies in place to assign users to their vlans depending upon who the user is. 

The NPS server is setup properly and handling the login requests and assigning the users to their vlans.

The vlans are setup on a cisco WS-C3750X. We've confirmed that the issue is only with the wireless. Devices plugged into the ethernet ports on the switch do not have this issue.

We have a sophos xg firewall with static routes assigned to it. I've been in contact with Sophos support. They've ruled out the firewall as the issue.

Sophos access points are connected to the switch in question.

Users connect normally and are assigned their vlans. However as soon as they try to surf the web. They cannot resolve DNS. And ping times are horrible with some timeouts.

So I'm wondering if there is some specific setting needed on the switch or nps server to resolve the issue.

Added TAGs
[edited by: Erick Jan at 5:03 AM (GMT -8) on 12 Jan 2024]
Parents Reply
  • Hi Alberto, 

    Good day and thanks for providing this. Upon checking the case there's a recommendation from the engr to have the AP directly connected to the FW and check if the issue would still persist. 

    On the network side, I may recommend you to tap and reach out to the L3/L2 switch vendor on the troubleshooting process and share the progress and steps that are already done on the AP and FW side. 

    Many thanks for your time and patience and thank you for choosing Sophos.


    Raphael Alganes
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos Product Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.