VLAN implementation into established non-vlan network
Posted: Tue Feb 18, 2020 9:28 pm
Hi,
I have a small wisp with around 100 customers.
Our current setup:
We have a core router with our two ISP fibre feeds. We branch out to other sites with wireless bridges. these sites have customer AP's. Their ubnt airmax CPE radio is also bridge mode.
The problem we are facing is:
We are piratically giving our customers layer 2 access to our whole network if they plug a laptop directly into the CPE poe injector.
We want to configure the CPE radio's in router mode and PPPOE client. I have tested this and it works great. But I want a separate management IP assigned statically to the CPE because the PPPOE address is dynamic.
The problem is, we cannot assign a different management address to the same interface as the pppoe client / WAN. The only way to do this says ubnt is to create a VLAN and set the management interface as vlan.xxx. This still leaves normal traffic as non-vlan traffic.
I cannot for the life of me get non-vlan traffic and management traffic working simultaneously on the bench
All our sites have netonix DC switches which vary in size. On the test bench I try changing the management vlan to 200 on all devices including the wisp switch. I then tag the port with the AP that CPE's connect to. I can the access the management IP of the CPE BUT customers loose connection to our core router.
Im not sure if what im trying to do is even possible as i am fairly new to the concept of vlans.
I could set a management vlan AND a vlan for normal traffic BUT I have to change ALL CPE's at once, then change ALL the backhauls then change ALL the switches manually which would take days. During that time all customers would be offline which we just cannot have.
Has anyone else out there overcome this problem? or know of an alternate / workaround solution.
Thanks in advanced,
TL;DR
CPE is ubnt powerbeam > Bridge mode to core router via bridged sites.
Change CPE to router mode / PPPOE (dynamic wan address).
Cannot set Management IP to same interface. Must create vlan.
Struggling to pass management / vlan traffic through same switch port. (wisp switch)
I have a small wisp with around 100 customers.
Our current setup:
We have a core router with our two ISP fibre feeds. We branch out to other sites with wireless bridges. these sites have customer AP's. Their ubnt airmax CPE radio is also bridge mode.
The problem we are facing is:
We are piratically giving our customers layer 2 access to our whole network if they plug a laptop directly into the CPE poe injector.
We want to configure the CPE radio's in router mode and PPPOE client. I have tested this and it works great. But I want a separate management IP assigned statically to the CPE because the PPPOE address is dynamic.
The problem is, we cannot assign a different management address to the same interface as the pppoe client / WAN. The only way to do this says ubnt is to create a VLAN and set the management interface as vlan.xxx. This still leaves normal traffic as non-vlan traffic.
I cannot for the life of me get non-vlan traffic and management traffic working simultaneously on the bench
All our sites have netonix DC switches which vary in size. On the test bench I try changing the management vlan to 200 on all devices including the wisp switch. I then tag the port with the AP that CPE's connect to. I can the access the management IP of the CPE BUT customers loose connection to our core router.
Im not sure if what im trying to do is even possible as i am fairly new to the concept of vlans.
I could set a management vlan AND a vlan for normal traffic BUT I have to change ALL CPE's at once, then change ALL the backhauls then change ALL the switches manually which would take days. During that time all customers would be offline which we just cannot have.
Has anyone else out there overcome this problem? or know of an alternate / workaround solution.
Thanks in advanced,
TL;DR
CPE is ubnt powerbeam > Bridge mode to core router via bridged sites.
Change CPE to router mode / PPPOE (dynamic wan address).
Cannot set Management IP to same interface. Must create vlan.
Struggling to pass management / vlan traffic through same switch port. (wisp switch)