<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLAN on VLAN with ZD1200 - ICX7150 &amp;amp; Sophos XG fw in ZoneDirector</title>
    <link>https://community.ruckuswireless.com/t5/ZoneDirector/WLAN-on-VLAN-with-ZD1200-ICX7150-amp-Sophos-XG-fw/m-p/46073#M8104</link>
    <description>&lt;P&gt;New to Ruckus &amp;amp; Sophos, attempting to set up a WLAN on VLAN 132.&lt;BR /&gt;&lt;BR /&gt;Problem:&amp;nbsp;&lt;BR /&gt;Can connect to WLAN, don't get a lease.&amp;nbsp;&lt;BR /&gt;After adding a static IP on VLAN132 subnet, unable to ping DG or Internet.&lt;BR /&gt;arp -a doesn't show DG MAC on WIFI interface.&lt;/P&gt;&lt;P&gt;Logs on firewall don't show any traffic in/out for VLAN 132 subnet.&lt;BR /&gt;&lt;STRONG&gt;Can&lt;/STRONG&gt; ping from switch 10.10.8.2 --&amp;gt; 10.2.132.1&lt;BR /&gt;It seems like a WIFI config issue but neither Ruckus or Sophos are part of our normal stack so could be an issue in wifi/switch/firewall.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScreenConnect.WindowsClient_hCizUzdkPQ.png" style="width: 400px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2950iC4C70D0B26EF93CE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ScreenConnect.WindowsClient_hCizUzdkPQ.png" alt="ScreenConnect.WindowsClient_hCizUzdkPQ.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Thanks for your help!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Equipment&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;ZD1200&amp;nbsp; v10.5.0.0 build 212&lt;BR /&gt;Switch: Ruckus&amp;nbsp;icx7150-48zp - 10.10.8.2&lt;BR /&gt;&lt;BR /&gt;Firewall: Sophos XG230&lt;BR /&gt;VLAN1:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.10.8.1 on br0&lt;BR /&gt;VLAN 132:&amp;nbsp; &amp;nbsp;10.2.132.1 on br0.132&amp;nbsp;&lt;BR /&gt;DHCP Server: enabled on VLAN132&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScreenConnect.WindowsClient_VFDTIM9qDO.png" style="width: 400px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2951i2E6D48BB65C757E2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ScreenConnect.WindowsClient_VFDTIM9qDO.png" alt="ScreenConnect.WindowsClient_VFDTIM9qDO.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;FW Rules&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Zone: WIFI&lt;/P&gt;&lt;P&gt;Allow imcp to br0.132,&lt;BR /&gt;icmp to to WAN/Any&lt;/P&gt;&lt;P&gt;Any service to WAN from&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;Switch Config&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;sw 1/1/10 AP2: untagged vlan1, tagged vlan132&lt;BR /&gt;sw 1/2/5 Uplink to sophos: untagged vlan1, tagged132&lt;BR /&gt;&lt;BR /&gt;PORT-VLAN 132, Name WIFIGUEST, Priority level0, On&lt;BR /&gt;Untagged Ports: None&lt;BR /&gt;Tagged Ports: (U1/M1) 1 2 3 4 5 6 7 8 9 10 11 12&lt;BR /&gt;Tagged Ports: (U1/M1) 13&lt;BR /&gt;Tagged Ports: (U1/M2) 1 5&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;WLAN Config&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Tx. Rate of Management Frame(2.4GHz) = 2.0Mbps&lt;BR /&gt;Tx. Rate of Management Frame(5GHz) = 6.0Mbps&lt;BR /&gt;Beacon Interval = 100ms&lt;BR /&gt;SSID = xTest&lt;BR /&gt;Description = TEST&lt;BR /&gt;Type = Standard Usage&lt;BR /&gt;Authentication = open&lt;BR /&gt;Encryption = wpa2&lt;BR /&gt;Algorithm = aes&lt;BR /&gt;Passphrase = testing123&lt;BR /&gt;FT Roaming = Enabled&lt;BR /&gt;802.11k Neighbor report = Enabled&lt;BR /&gt;Web Authentication = Disabled&lt;BR /&gt;Authentication Server = Disabled&lt;BR /&gt;Called-Station-Id type = wlan-bssid&lt;BR /&gt;Tunnel Mode = Disabled&lt;BR /&gt;Background Scanning = Enabled&lt;BR /&gt;Max. Clients = 100&lt;BR /&gt;Isolation per AP = Enabled&lt;BR /&gt;Isolation across AP = Enabled&lt;BR /&gt;Zero-IT Activation = Disabled&lt;BR /&gt;Priority = High&lt;BR /&gt;Load Balancing = Disabled&lt;BR /&gt;Band Balancing = Disabled&lt;BR /&gt;Dynamic PSK = Disabled&lt;BR /&gt;Rate Limiting Uplink = Disabled&lt;BR /&gt;PerSSID Rate Limiting Uplink = 50&lt;BR /&gt;Rate Limiting Downlink = Disabled&lt;BR /&gt;PerSSID Rate Limiting Downlink = 0&lt;BR /&gt;Auto-Proxy configuration:&lt;BR /&gt;Status = Disabled&lt;BR /&gt;Inactivity Timeout:&lt;BR /&gt;Status = Enabled&lt;BR /&gt;Timeout = 5 Minutes&lt;BR /&gt;VLAN-ID = 132&lt;BR /&gt;Dynamic VLAN = Disabled&lt;BR /&gt;Closed System = Disabled&lt;BR /&gt;Https Redirection = Disabled&lt;BR /&gt;OFDM-Only State = Disabled&lt;BR /&gt;Multicast Filter State = Disabled&lt;BR /&gt;Directed Multicast= Enabled&lt;BR /&gt;802.11d State = Disabled&lt;BR /&gt;Force DHCP State = Disabled&lt;BR /&gt;Force DHCP Timeout = 10&lt;BR /&gt;DHCP Option82:&lt;BR /&gt;Status = Disabled&lt;BR /&gt;Option82 sub-Option1 = Disabled&lt;BR /&gt;Option82 sub-Option2 = Disabled&lt;BR /&gt;Option82 sub-Option150 = Disabled&lt;BR /&gt;Option82 sub-Option151 = Disabled&lt;BR /&gt;Ignore unauthorized client statistic = Disabled&lt;BR /&gt;STA Info Extraction State = Enabled&lt;BR /&gt;BSS Minrate = Disabled&lt;BR /&gt;DTIM period = 1&lt;BR /&gt;Directed MC/BC Threshold = 5&lt;BR /&gt;Call Admission Control State = Disabled&lt;BR /&gt;PMK Cache Timeout= 720 minutes&lt;BR /&gt;PMK Cache for Reconnect= Enabled&lt;BR /&gt;NAS-ID Type= wlan-bssid&lt;BR /&gt;Roaming Acct-Interim-Update= Disabled&lt;BR /&gt;PAP Message Authenticator = Enabled&lt;BR /&gt;Send EAP-Failure = Disabled&lt;BR /&gt;L2/MAC = No ACLS&lt;BR /&gt;L3/L4/IP Address = No ACLS&lt;BR /&gt;L3/L4/IPv6 Address = No ACLS&lt;BR /&gt;Precedence = Default&lt;BR /&gt;Proxy ARP = Disabled&lt;BR /&gt;Device Policy = No ACLS&lt;BR /&gt;Vlan Pool = No Pools&lt;BR /&gt;Role based Access Control Policy = Disabled&lt;BR /&gt;SmartRoam = Disabled Roam-factor = 1&lt;BR /&gt;White List = vlan132&lt;BR /&gt;URL Filtering = Disabled&lt;BR /&gt;Application Recognition &amp;amp; Control = Disabled&lt;BR /&gt;Apply ARC Policy = NO POLICY&lt;BR /&gt;Client Flow Data Logging = Disabled&lt;BR /&gt;Wlan Bind = all&lt;BR /&gt;Client Connection Data = Disabled&lt;BR /&gt;Transient Client Management = Disabled&lt;BR /&gt;80211w-pmf = Disabled&lt;BR /&gt;&lt;BR /&gt;WhiteList: vlan132&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="whitelist" style="width: 605px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2949iCE8EDCBCFCA4981E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScreenConnect.WindowsClient_w2uYSffaAx.png" alt="whitelist" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;whitelist&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Aug 2022 21:47:18 GMT</pubDate>
    <dc:creator>ed_fries</dc:creator>
    <dc:date>2022-08-18T21:47:18Z</dc:date>
    <item>
      <title>WLAN on VLAN with ZD1200 - ICX7150 &amp; Sophos XG fw</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/WLAN-on-VLAN-with-ZD1200-ICX7150-amp-Sophos-XG-fw/m-p/46073#M8104</link>
      <description>&lt;P&gt;New to Ruckus &amp;amp; Sophos, attempting to set up a WLAN on VLAN 132.&lt;BR /&gt;&lt;BR /&gt;Problem:&amp;nbsp;&lt;BR /&gt;Can connect to WLAN, don't get a lease.&amp;nbsp;&lt;BR /&gt;After adding a static IP on VLAN132 subnet, unable to ping DG or Internet.&lt;BR /&gt;arp -a doesn't show DG MAC on WIFI interface.&lt;/P&gt;&lt;P&gt;Logs on firewall don't show any traffic in/out for VLAN 132 subnet.&lt;BR /&gt;&lt;STRONG&gt;Can&lt;/STRONG&gt; ping from switch 10.10.8.2 --&amp;gt; 10.2.132.1&lt;BR /&gt;It seems like a WIFI config issue but neither Ruckus or Sophos are part of our normal stack so could be an issue in wifi/switch/firewall.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScreenConnect.WindowsClient_hCizUzdkPQ.png" style="width: 400px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2950iC4C70D0B26EF93CE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ScreenConnect.WindowsClient_hCizUzdkPQ.png" alt="ScreenConnect.WindowsClient_hCizUzdkPQ.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Thanks for your help!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Equipment&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;ZD1200&amp;nbsp; v10.5.0.0 build 212&lt;BR /&gt;Switch: Ruckus&amp;nbsp;icx7150-48zp - 10.10.8.2&lt;BR /&gt;&lt;BR /&gt;Firewall: Sophos XG230&lt;BR /&gt;VLAN1:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.10.8.1 on br0&lt;BR /&gt;VLAN 132:&amp;nbsp; &amp;nbsp;10.2.132.1 on br0.132&amp;nbsp;&lt;BR /&gt;DHCP Server: enabled on VLAN132&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ScreenConnect.WindowsClient_VFDTIM9qDO.png" style="width: 400px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2951i2E6D48BB65C757E2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="ScreenConnect.WindowsClient_VFDTIM9qDO.png" alt="ScreenConnect.WindowsClient_VFDTIM9qDO.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;FW Rules&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Zone: WIFI&lt;/P&gt;&lt;P&gt;Allow imcp to br0.132,&lt;BR /&gt;icmp to to WAN/Any&lt;/P&gt;&lt;P&gt;Any service to WAN from&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;Switch Config&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;sw 1/1/10 AP2: untagged vlan1, tagged vlan132&lt;BR /&gt;sw 1/2/5 Uplink to sophos: untagged vlan1, tagged132&lt;BR /&gt;&lt;BR /&gt;PORT-VLAN 132, Name WIFIGUEST, Priority level0, On&lt;BR /&gt;Untagged Ports: None&lt;BR /&gt;Tagged Ports: (U1/M1) 1 2 3 4 5 6 7 8 9 10 11 12&lt;BR /&gt;Tagged Ports: (U1/M1) 13&lt;BR /&gt;Tagged Ports: (U1/M2) 1 5&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;U&gt;WLAN Config&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Tx. Rate of Management Frame(2.4GHz) = 2.0Mbps&lt;BR /&gt;Tx. Rate of Management Frame(5GHz) = 6.0Mbps&lt;BR /&gt;Beacon Interval = 100ms&lt;BR /&gt;SSID = xTest&lt;BR /&gt;Description = TEST&lt;BR /&gt;Type = Standard Usage&lt;BR /&gt;Authentication = open&lt;BR /&gt;Encryption = wpa2&lt;BR /&gt;Algorithm = aes&lt;BR /&gt;Passphrase = testing123&lt;BR /&gt;FT Roaming = Enabled&lt;BR /&gt;802.11k Neighbor report = Enabled&lt;BR /&gt;Web Authentication = Disabled&lt;BR /&gt;Authentication Server = Disabled&lt;BR /&gt;Called-Station-Id type = wlan-bssid&lt;BR /&gt;Tunnel Mode = Disabled&lt;BR /&gt;Background Scanning = Enabled&lt;BR /&gt;Max. Clients = 100&lt;BR /&gt;Isolation per AP = Enabled&lt;BR /&gt;Isolation across AP = Enabled&lt;BR /&gt;Zero-IT Activation = Disabled&lt;BR /&gt;Priority = High&lt;BR /&gt;Load Balancing = Disabled&lt;BR /&gt;Band Balancing = Disabled&lt;BR /&gt;Dynamic PSK = Disabled&lt;BR /&gt;Rate Limiting Uplink = Disabled&lt;BR /&gt;PerSSID Rate Limiting Uplink = 50&lt;BR /&gt;Rate Limiting Downlink = Disabled&lt;BR /&gt;PerSSID Rate Limiting Downlink = 0&lt;BR /&gt;Auto-Proxy configuration:&lt;BR /&gt;Status = Disabled&lt;BR /&gt;Inactivity Timeout:&lt;BR /&gt;Status = Enabled&lt;BR /&gt;Timeout = 5 Minutes&lt;BR /&gt;VLAN-ID = 132&lt;BR /&gt;Dynamic VLAN = Disabled&lt;BR /&gt;Closed System = Disabled&lt;BR /&gt;Https Redirection = Disabled&lt;BR /&gt;OFDM-Only State = Disabled&lt;BR /&gt;Multicast Filter State = Disabled&lt;BR /&gt;Directed Multicast= Enabled&lt;BR /&gt;802.11d State = Disabled&lt;BR /&gt;Force DHCP State = Disabled&lt;BR /&gt;Force DHCP Timeout = 10&lt;BR /&gt;DHCP Option82:&lt;BR /&gt;Status = Disabled&lt;BR /&gt;Option82 sub-Option1 = Disabled&lt;BR /&gt;Option82 sub-Option2 = Disabled&lt;BR /&gt;Option82 sub-Option150 = Disabled&lt;BR /&gt;Option82 sub-Option151 = Disabled&lt;BR /&gt;Ignore unauthorized client statistic = Disabled&lt;BR /&gt;STA Info Extraction State = Enabled&lt;BR /&gt;BSS Minrate = Disabled&lt;BR /&gt;DTIM period = 1&lt;BR /&gt;Directed MC/BC Threshold = 5&lt;BR /&gt;Call Admission Control State = Disabled&lt;BR /&gt;PMK Cache Timeout= 720 minutes&lt;BR /&gt;PMK Cache for Reconnect= Enabled&lt;BR /&gt;NAS-ID Type= wlan-bssid&lt;BR /&gt;Roaming Acct-Interim-Update= Disabled&lt;BR /&gt;PAP Message Authenticator = Enabled&lt;BR /&gt;Send EAP-Failure = Disabled&lt;BR /&gt;L2/MAC = No ACLS&lt;BR /&gt;L3/L4/IP Address = No ACLS&lt;BR /&gt;L3/L4/IPv6 Address = No ACLS&lt;BR /&gt;Precedence = Default&lt;BR /&gt;Proxy ARP = Disabled&lt;BR /&gt;Device Policy = No ACLS&lt;BR /&gt;Vlan Pool = No Pools&lt;BR /&gt;Role based Access Control Policy = Disabled&lt;BR /&gt;SmartRoam = Disabled Roam-factor = 1&lt;BR /&gt;White List = vlan132&lt;BR /&gt;URL Filtering = Disabled&lt;BR /&gt;Application Recognition &amp;amp; Control = Disabled&lt;BR /&gt;Apply ARC Policy = NO POLICY&lt;BR /&gt;Client Flow Data Logging = Disabled&lt;BR /&gt;Wlan Bind = all&lt;BR /&gt;Client Connection Data = Disabled&lt;BR /&gt;Transient Client Management = Disabled&lt;BR /&gt;80211w-pmf = Disabled&lt;BR /&gt;&lt;BR /&gt;WhiteList: vlan132&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="whitelist" style="width: 605px;"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/2949iCE8EDCBCFCA4981E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ScreenConnect.WindowsClient_w2uYSffaAx.png" alt="whitelist" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;whitelist&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 21:47:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/WLAN-on-VLAN-with-ZD1200-ICX7150-amp-Sophos-XG-fw/m-p/46073#M8104</guid>
      <dc:creator>ed_fries</dc:creator>
      <dc:date>2022-08-18T21:47:18Z</dc:date>
    </item>
  </channel>
</rss>

