Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Wireless AP Setup

    Scheduled Pinned Locked Moved Wireless
    14 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @stevencavanagh
      last edited by

      @stevencavanagh I’d create a guest vlan on your pfSense router and create a guest SSID.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      S 1 Reply Last reply Reply Quote 0
      • S
        stevencavanagh @NogBadTheBad
        last edited by

        I have a guest VLAN already exists and a guest SSID also exists on each of the Drayteks along with VLAN tag but unfortunately the Devolo’s cannot handle VLAN tagging

        1 Reply Last reply Reply Quote 0
        • V
          viragomann @stevencavanagh
          last edited by

          @stevencavanagh
          Since you have the Devolos connected to a managed switch, configure the switch for the IoT VLAN. So you can have the Devolos on the IoT VLAN segmented from your other subnets.

          S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Yup that^. Use switches to add the Devolos on to a VLAN.

            1 Reply Last reply Reply Quote 0
            • S
              stevencavanagh @viragomann
              last edited by

              @viragomann

              The Devolo’s are on the IOT network but the problem is most of the IOT devices are wifi and they can sometimes connect to other APs. I suppose I could remove the password from the other APs from them but a quick look shows a number of them on the Drayteks having moved over when the Devolo’s have momentarily gone off line. Is this the best / only option?

              V 1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                If they are all using different SSIDs then you would have to allow those devices to connect to the other APs. You can simply remove the login credentials for the Draytek APs from those devices you don't want to connect to them.

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann @stevencavanagh
                  last edited by

                  @stevencavanagh
                  You need to configure a different wifi SSID for IoT and additionally change the password for your other wifi. So the IoT devices are not be able to connect anymore.

                  The spawn up an IoT VLAN between pfSense and the switch. On the switch add all concerned ports as untagged to the IoT VLAN.

                  NogBadTheBadN 1 Reply Last reply Reply Quote 1
                  • NogBadTheBadN
                    NogBadTheBad @viragomann
                    last edited by

                    FYI Devolo’s Powerline stuff will pass multiple vlans, I use 3 and pass 7 vlans through them.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      stevencavanagh @NogBadTheBad
                      last edited by

                      @NogBadTheBad said in Wireless AP Setup:

                      FYI Devolo’s Powerline stuff will pass multiple vlans, I use 3 and pass 7 vlans through them.

                      I am using the DLan 1200s, I will try again

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @stevencavanagh
                        last edited by NogBadTheBad

                        @stevencavanagh

                        Switch, pfSense port 1, Aruba AP22 port3 & Devolo port 8:-

                        Screenshot 2023-09-21 at 18.48.44.png

                        pfSense:-

                        Screenshot 2023-09-21 at 18.50.04.png

                        Each switch has port 8 connected to the Devolo's

                        You'd just need just need to set up a port on your managed switch to be untagged in the IOT VLAN and plug the 1st Devolo if you're only using them for IOT, like GE5 & GE7 on my screenshot.

                        My Devolo's are the non Wi-Fi 1200's.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          stevencavanagh @NogBadTheBad
                          last edited by

                          All,

                          Managed to have a play with it last night.

                          So, currently the managed switch has a port defined as 'access' to the IOT VLAN, so anything connected to the Devolo (all wifi) will get an IP address in the range 192.168.50.XXX, which is fine and works as it should.

                          However, any device connecting to the 'guest' network on the Devolo will also get an IP address in the range 192.168.50.XXX rather than in the 192.168.70.XXX (guest VLAN) and this is due to the fact there is no option to assign a VLAN tag in Devolo, so I will have to delete the Devolo guest network, I assume.

                          I've removed the credentials from the IOT devices that allowed them to connect to the Draytek APs and that has solved that problem.

                          In short, all works except there won't be an option of the guest network (wifi) via the Devolo homeplugs.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Yes, if those APs can't put different SSIDs onto different VLANs then they can really only do one. So, as you said, I would remove the guest SSID from there.

                            S 1 Reply Last reply Reply Quote 0
                            • S
                              stevencavanagh @stephenw10
                              last edited by

                              @stephenw10

                              Yep, that's the way to go!

                              Cheers!

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.