This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AP55 not appearing on VLAN

I have an SG310 and an AP55 Access Point.

I have a switch with 3 VLANS:
- VLAN 1 is the default / LAN
- VLAN 150 is called Management
- VLAN 30 is WiFi

 

If I plug my AP55 Access Point into a switch port that is untagged on VLAN 1, the AP55 gets an IP address on that subnet and it appears in the 'Pending Access Points' section on the SG310 web admin portal (Wireless Protection > Access Points). So this works fine.

But I want my AP55 to be on the 150 network. So I unplugged it and then plugged it into a switch port that is untagged on the 150 (Management) VLAN.

After a few moments the AP55 gets an IP address in the management subnet. But the access point never appears on the Access Points page.

Is there some sort of rule or setting on the SG310 that says the access points have to live in the default VLAN (1)?

Trying to figure out why I can't see the AP55 when it is assigned an IP on the management VLAN.

Some more info in case it's helpful:

DHCP for the default VLAN is handled through a Windows Server running DHCP.
But DHCP for the management VLAN is handled through the Sophos SG310.

If I go to Network Services > DHCP and open the Live Log, I can watch as the Sophos grants IP 192.168.150.195 to the AP55. And I can ping the device. But as I mentioned, it's not showing up on the SG310 Access Points page.

If I unplug the AP55 and plug it back into the default VLAN, it gets an IP on that subnet AND it appears on the Access Points page. So the AP55 appears to work fine. I just want it to have a .150 ip address. (To clarify: This is the IP of the device itself - I am trying to get all of my network devices on the management VLAN. This has nothing to do with the wireless network that is being broadcast from this AP or the subnet of wireless clients that connect to the AP)



This thread was automatically locked due to age.
Parents
  • Hi ecar13,

    have you put the Managment-Interface of the SG310 in Wireless Protection -> Global -> Allowed Interfaces ?

    Only defined interfaces on this tab allows connections from APs to Sophos UTM.

    If you are planning to use vlans on APs you have to select the AP and configure under advanced options VLAN tagging.

    Here you can select the management vlan. (Tagging must be enabled on the switch).

    Then you can select bridge to vlan with your prefered vlan tag.

    Best regards

    DKNL

Reply
  • Hi ecar13,

    have you put the Managment-Interface of the SG310 in Wireless Protection -> Global -> Allowed Interfaces ?

    Only defined interfaces on this tab allows connections from APs to Sophos UTM.

    If you are planning to use vlans on APs you have to select the AP and configure under advanced options VLAN tagging.

    Here you can select the management vlan. (Tagging must be enabled on the switch).

    Then you can select bridge to vlan with your prefered vlan tag.

    Best regards

    DKNL

Children
  • DKNL,

    That was the problem. I had to add the management interface to the Allowed Interfaces. As soon as I did that, the Access Point appeared. Thanks for your help.

  • VLAN 1 is reserved in the UTM.  I'm surprised Wireless Protection is working, so if you have any strangeness, you will want to change from VLAN1.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA