<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan. in Access Points - Indoor and Outdoor</title>
    <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38337#M10843</link>
    <description>&lt;P style="margin: 0;"&gt;I'm not eliminating untagged traffic, I'm just trying to place clients on the correct-for-them vlan. Since 1 is default native; I don't want newly onboarded equipment or any misconfigured device to be on my management network. It should be on lowest permission and then put into correct space.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Dec 2021 16:05:27 GMT</pubDate>
    <dc:creator>joshua_dunham</dc:creator>
    <dc:date>2021-12-27T16:05:27Z</dc:date>
    <item>
      <title>Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38333#M10839</link>
      <description>&lt;P style="margin: 0;"&gt;Hey Folks,&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I'm trying to phase out vlan1 from an existing deployment. It currently consists of 4 h510 APs and an ICX6610. Like OP on Dec 16 "Change Unleashed to be able to use VLANS",&amp;nbsp; I'm looking to clean-up.&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I've created 6 VLANs to service the separate user roles (10,20,25,30) and some for the management / back-office traffic (40,50). I assigned the VLANs to the WLAN settings in unleashed and they work just fine - clients get routed to the correct DHCP server etc. Since all client originating traffic goes to a specific VLAN I'm OK to treat untagged traffic (AP dhcp / heartbeat / ssh). The issue comes when I move the 'native' vlan from 1 to 40 by using dual-mode in vlan 40. DHCP to the AP works and it grabs the correct reserved IP but the cluster breaks (recover.me is seen as an ssid) and all but the master drops out.&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I've factory-reset the APs and set one up as a test but still the other APs do not join. I've SSH'd into the master and can ping the other APs just fine.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Here is vlan40 config from switch,&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;PRE&gt;&lt;CODE&gt;PORT-VLAN 40, Name mgmt-fe, Priority level0, Spanning tree OnUntagged Ports: NoneTagged Ports: (U1/M1)   3   4Tagged Ports: (U1/M3)   3Uplink Ports: (U1/M1)   3   4DualMode Ports: (U1/M1)  21  22  23  24Mac-Vlan Ports: NoneMonitoring: Disabled&lt;/CODE&gt;&lt;/PRE&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;The APs are driven from 4 POE enabled ports (1/121,22,23,24) and upstream to WAN is a Lagg on 1/1/3,4&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Does anyone have tips to get the cluster to re-form or to test what could be blocking comms b/w the APs? I've read it's just UDP heartbeats which should work?&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;J&lt;/P&gt;</description>
      <pubDate>Sun, 26 Dec 2021 23:17:32 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38333#M10839</guid>
      <dc:creator>joshua_dunham</dc:creator>
      <dc:date>2021-12-26T23:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38334#M10840</link>
      <description>&lt;P style="margin: 0;"&gt;My understanding is unleached can not use vlans for management traffic. Only for client traffic. You would need a zonedirector if you wanted to have vlans for your management traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 00:16:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38334#M10840</guid>
      <dc:creator>rob_m_istij3wx4</dc:creator>
      <dc:date>2021-12-27T00:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38335#M10841</link>
      <description>&lt;P style="margin: 0;"&gt;It can not be *configured* to use a specific vlan but on the switch side I should be able to set any/all untagged traffic to one specific vlan. This is a basic basic thing but I must have overlooked something. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 00:44:15 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38335#M10841</guid>
      <dc:creator>joshua_dunham</dc:creator>
      <dc:date>2021-12-27T00:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38336#M10842</link>
      <description>&lt;P style="margin: 0;"&gt;hi,&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;i think it has to do with multicast traffic.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;i don't see a reason to eliminate untagged traffic on a network, why you don't use the untagged vlan 1 as the "management network"?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 10:47:32 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38336#M10842</guid>
      <dc:creator>thomas_fankhaus</dc:creator>
      <dc:date>2021-12-27T10:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38337#M10843</link>
      <description>&lt;P style="margin: 0;"&gt;I'm not eliminating untagged traffic, I'm just trying to place clients on the correct-for-them vlan. Since 1 is default native; I don't want newly onboarded equipment or any misconfigured device to be on my management network. It should be on lowest permission and then put into correct space.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 16:05:27 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38337#M10843</guid>
      <dc:creator>joshua_dunham</dc:creator>
      <dc:date>2021-12-27T16:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38338#M10844</link>
      <description>&lt;P style="margin: 0;"&gt;The issue turned out to be I was blocking some needed traffic in the upstream firewall. I noticed that tracepath was traversing the firewall for queries so I started thinking maybe this config was setup for router-on-a-stick (which I don't want).&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I made a blanket deny all rule in the FW which logged everything and then went through line by line to block or pass as needed with no logging above the blanket deny.&amp;nbsp; At some point I had triaged enough that the main AP found the worker APs.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I found that the detection relies on UDP packets to some ports (maybe 22222 or 22223) so I'm still confused on why these went through the upstream firewall from the Ruckus switch or if there is another condition before UDP that wasn't met. If anyone has an answer I'd love to know.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Thanks everyone that took a moment to reply - much appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 01:10:54 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38338#M10844</guid>
      <dc:creator>joshua_dunham</dc:creator>
      <dc:date>2021-12-28T01:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38339#M10845</link>
      <description>&lt;P&gt;&lt;A href="https://forums.ruckuswireless.com/users/61c8e88c49c6e64e2a518aab"&gt;@joshua_dunham&lt;/A&gt; are all clients wireless?&amp;nbsp; If so there is no way for any client (authenticated or not) to end up on vlan 1 provided that all SSIDs are tagged.&amp;nbsp; You could also assign static address to all devices on vlan 1 (switched, APs, etc) and disable DHCP service.&amp;nbsp;&lt;/P&gt; 
&lt;P&gt;&lt;/P&gt; 
&lt;P&gt;If you insist on using vlan 40 for management, then you could configure the AP switch ports to have vlan 40 as the native untagged vlan.&amp;nbsp; Leave the APs set to vlan 1 so that management traffic is untagged.&amp;nbsp; The switch will put the untagged traffic is vlan 40.&amp;nbsp; Sure seems like you're going way overboard for a small 4 AP network.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 04:18:40 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38339#M10845</guid>
      <dc:creator>david_black_594</dc:creator>
      <dc:date>2021-12-29T04:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Move Ruckus (unleashed) AP originating traffic from native 1 vlan to 
'management' vlan.</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38340#M10846</link>
      <description>&lt;P style="margin: 0;"&gt;Hey &lt;A href="https://forums.ruckuswireless.com/users/5f9169f449d3ca752488cbdb" style=""&gt;@david_black_5940365&lt;/A&gt; ; The user clients are on wireless (but I have an h510 so can mark the ports in vlan as well).&amp;nbsp;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;The traffic of question is what originates from the AP though (heartbeat, ssh, etc). Your suggestion is what I had originally done but there was an extra step at the upstream router/firewall level.&amp;nbsp; Please see accepted answer for more details.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;I have received many such comments "... going way overboard for a small 4 AP network." and I'm not sure why. This is an increased measure of security unrelated to the footprint. I don't want my AP cluster traffic on the native vlan.&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;&lt;/P&gt; 
&lt;P style="margin: 0;"&gt;Thank you for following up though, I appreciate everyone's time to help out!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 15:07:37 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Move-Ruckus-unleashed-AP-originating-traffic-from-native-1-vlan/m-p/38340#M10846</guid>
      <dc:creator>joshua_dunham</dc:creator>
      <dc:date>2021-12-29T15:07:37Z</dc:date>
    </item>
  </channel>
</rss>

