<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Different Vlan not Communicate in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25631#M2435</link>
    <description>awaiting for the reply</description>
    <pubDate>Wed, 04 Jul 2018 10:57:00 GMT</pubDate>
    <dc:creator>Saravanamurthy_</dc:creator>
    <dc:date>2018-07-04T10:57:00Z</dc:date>
    <item>
      <title>Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25625#M2429</link>
      <description>Hi,&lt;BR /&gt;
I am using AP 7532, firmware is 5.9.2. I created two vlan (vlan1 &amp;amp; vlan2) &amp;amp; two SSID (Employee &amp;amp; Guest) in this AP. IP address are vlan1 &amp;amp; vlan2 as 192.168.10.10 &amp;amp; 192.168.2.10. SSID Employee is mapped to vlan1 and Guest is mapped to vlan2. after configuring i connected two client with different SSID. I reached guest to employee. but i cant employee to guest.&lt;BR /&gt;
&lt;BR /&gt;
Below Client connected to SSID Employee. This Client ip address is 192.168.10.105.&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2e98c941a668417bac7aeb6ddf8a1ea9_RackMultipart20180627-24158-14yt7o1-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/6037iC3ACD2C3E346063F/image-size/large?v=v2&amp;amp;px=999" role="button" title="2e98c941a668417bac7aeb6ddf8a1ea9_RackMultipart20180627-24158-14yt7o1-image_inline.png" alt="2e98c941a668417bac7aeb6ddf8a1ea9_RackMultipart20180627-24158-14yt7o1-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Another Client connected to SSID Guest. that IP address is 192.168.2.20. so Client from 192.168.2.10 to 192.168.10.105 is pinging. but from 192.168.10.105 to 192.168.2.20 is not pinging.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Jun 2018 15:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25625#M2429</guid>
      <dc:creator>Saravanamurthy_</dc:creator>
      <dc:date>2018-06-27T15:24:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25626#M2430</link>
      <description>What is responsible for routing between networks in your environment? It sounds like you possibly reversed your routing  and policy logic (meaning employee might be trusted more than guest and only ping in that direction). Regardless, those routes, rules and polocies are up to you.</description>
      <pubDate>Wed, 27 Jun 2018 16:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25626#M2430</guid>
      <dc:creator>Eric_Burke</dc:creator>
      <dc:date>2018-06-27T16:30:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25627#M2431</link>
      <description>Or the client in the guest network has a personal firewall installed that don't allow to ping the device.</description>
      <pubDate>Wed, 27 Jun 2018 16:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25627#M2431</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-06-27T16:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25628#M2432</link>
      <description>Can you show us the 'ip access-list nat-rule' you configured on AP&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Jun 2018 17:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25628#M2432</guid>
      <dc:creator>RobertZ</dc:creator>
      <dc:date>2018-06-27T17:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25629#M2433</link>
      <description>Now i share all my configuration details.&lt;BR /&gt;
&lt;U&gt;LAN:&lt;/U&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-17161-1imf2tz-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/139iA607EA8AE88FFCCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-17161-1imf2tz-image_inline.png" alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-17161-1imf2tz-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;U&gt;WAN:&lt;BR /&gt;
&lt;/U&gt;&lt;U&gt;&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-28662-13wa5is-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1550iBC1EF6DCBA64AE02/image-size/large?v=v2&amp;amp;px=999" role="button" title="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-28662-13wa5is-image_inline.png" alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-28662-13wa5is-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
Wireless:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-128682-1xc40px-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5838iBB5F54A9ED42B291/image-size/large?v=v2&amp;amp;px=999" role="button" title="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-128682-1xc40px-image_inline.png" alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-128682-1xc40px-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
Services:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-8772-1k3ig2o-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4183i321C315CDC155110/image-size/large?v=v2&amp;amp;px=999" role="button" title="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-8772-1k3ig2o-image_inline.png" alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-8772-1k3ig2o-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Access Point:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-8772-sewroe-image_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4903i55116DB77F68D597/image-size/large?v=v2&amp;amp;px=999" role="button" title="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-8772-sewroe-image_inline.png" alt="ebf0dd825f3b408d90fb94a8b01c51b3_RackMultipart20180628-8772-sewroe-image_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;/U&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:17:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25629#M2433</guid>
      <dc:creator>Saravanamurthy_</dc:creator>
      <dc:date>2018-06-28T11:17:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25630#M2434</link>
      <description>ap7532-18A21C#sh running-config&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    ! Configuration of AP7532 version 5.9.2.0-032R&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    version 2.5&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    client-identity-group default&lt;BR /&gt;
&lt;BR /&gt;
     load  default-fingerprints&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    ip access-list BROADCAST-MULTICAST-CONTROL&lt;BR /&gt;
&lt;BR /&gt;
     permit tcp any any  rule-precedence 10 rule-description "permit all TCP traffic"&lt;BR /&gt;
&lt;BR /&gt;
     permit udp any eq 67  any eq dhcpc rule-precedence 11 rule-description "permit DHCP  replies"&lt;BR /&gt;
&lt;BR /&gt;
     deny udp any range  137 138 any range 137 138 rule-precedence 20 rule-description "deny  windows netbios"&lt;BR /&gt;
&lt;BR /&gt;
     deny ip any  224.0.0.0/4 rule-precedence 21 rule-description "deny IP multicast"&lt;BR /&gt;
&lt;BR /&gt;
     deny ip any host  255.255.255.255 rule-precedence 22 rule-description "deny IP local  broadcast"&lt;BR /&gt;
&lt;BR /&gt;
     permit ip any any  rule-precedence 100 rule-description "permit all IP traffic"&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    ip access-list default-B8500118A21C-nat&lt;BR /&gt;
&lt;BR /&gt;
     permit ip any any  rule-precedence 1&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    mac access-list PERMIT-ARP-AND-IPv4&lt;BR /&gt;
&lt;BR /&gt;
     permit any any type  ip rule-precedence 10 rule-description "permit all IPv4 traffic"&lt;BR /&gt;
&lt;BR /&gt;
     permit any any type  arp rule-precedence 20 rule-description "permit all ARP traffic"&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    ip snmp-access-list default&lt;BR /&gt;
&lt;BR /&gt;
     permit any&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    firewall-policy default&lt;BR /&gt;
&lt;BR /&gt;
     no ip dos  tcp-sequence-past-window&lt;BR /&gt;
&lt;BR /&gt;
     no  stateful-packet-inspection-l2&lt;BR /&gt;
&lt;BR /&gt;
     ip tcp adjust-mss  1400&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    mint-policy global-default&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    meshpoint-qos-policy default&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    wlan-qos-policy Employee&lt;BR /&gt;
&lt;BR /&gt;
     rate-limit client  to-air rate 5000&lt;BR /&gt;
&lt;BR /&gt;
     rate-limit client  from-air rate 5000&lt;BR /&gt;
&lt;BR /&gt;
     qos trust dscp&lt;BR /&gt;
&lt;BR /&gt;
     qos trust wmm&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    wlan-qos-policy Guest&lt;BR /&gt;
&lt;BR /&gt;
    --More—&lt;BR /&gt;
&lt;BR /&gt;
    rate-limit client to-air rate 5000&lt;BR /&gt;
&lt;BR /&gt;
     rate-limit client  from-air rate 5000&lt;BR /&gt;
&lt;BR /&gt;
     qos trust dscp&lt;BR /&gt;
&lt;BR /&gt;
     qos trust wmm&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    wlan-qos-policy default&lt;BR /&gt;
&lt;BR /&gt;
     qos trust dscp&lt;BR /&gt;
&lt;BR /&gt;
     qos trust wmm&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    radio-qos-policy default&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    wlan Employee&lt;BR /&gt;
&lt;BR /&gt;
     description Employee&lt;BR /&gt;
&lt;BR /&gt;
     ssid Employee&lt;BR /&gt;
&lt;BR /&gt;
     vlan 1&lt;BR /&gt;
&lt;BR /&gt;
     bridging-mode local&lt;BR /&gt;
&lt;BR /&gt;
     encryption-type ccmp&lt;BR /&gt;
&lt;BR /&gt;
     authentication-type  none&lt;BR /&gt;
&lt;BR /&gt;
     no fast-bss-transition  over-ds&lt;BR /&gt;
&lt;BR /&gt;
     wpa-wpa2 psk 0  Employee@123&lt;BR /&gt;
&lt;BR /&gt;
     use wlan-qos-policy  Employee&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    wlan Guest&lt;BR /&gt;
&lt;BR /&gt;
     description Guest&lt;BR /&gt;
&lt;BR /&gt;
     ssid Guest&lt;BR /&gt;
&lt;BR /&gt;
     vlan 2&lt;BR /&gt;
&lt;BR /&gt;
     bridging-mode local&lt;BR /&gt;
&lt;BR /&gt;
     encryption-type ccmp&lt;BR /&gt;
&lt;BR /&gt;
     authentication-type  none&lt;BR /&gt;
&lt;BR /&gt;
     no  fast-bss-transition over-ds&lt;BR /&gt;
&lt;BR /&gt;
     wpa-wpa2 psk 0  Guest@123&lt;BR /&gt;
&lt;BR /&gt;
     use wlan-qos-policy  Guest&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    dhcp-server-policy WiNGExpressDhcpSvrPolicy&lt;BR /&gt;
&lt;BR /&gt;
     dhcp-pool  default-vlan2-pool&lt;BR /&gt;
&lt;BR /&gt;
      network  192.168.2.0/24&lt;BR /&gt;
&lt;BR /&gt;
      address range  192.168.2.11 192.168.2.20&lt;BR /&gt;
&lt;BR /&gt;
      default-router  192.168.2.10&lt;BR /&gt;
&lt;BR /&gt;
      dns-server  192.168.2.10 8.8.8.8&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    management-policy default&lt;BR /&gt;
&lt;BR /&gt;
     telnet&lt;BR /&gt;
&lt;BR /&gt;
     no http server&lt;BR /&gt;
&lt;BR /&gt;
     https server&lt;BR /&gt;
&lt;BR /&gt;
    ip address zeroconf secondary&lt;BR /&gt;
&lt;BR /&gt;
      ip dhcp client  request options all&lt;BR /&gt;
&lt;BR /&gt;
     interface vlan2&lt;BR /&gt;
&lt;BR /&gt;
      description Guest&lt;BR /&gt;
&lt;BR /&gt;
      ip address dhcp&lt;BR /&gt;
&lt;BR /&gt;
     interface pppoe1&lt;BR /&gt;
&lt;BR /&gt;
     use firewall-policy  default&lt;BR /&gt;
&lt;BR /&gt;
     use  client-identity-group default&lt;BR /&gt;
&lt;BR /&gt;
     logging on&lt;BR /&gt;
&lt;BR /&gt;
     service pm  sys-restart&lt;BR /&gt;
&lt;BR /&gt;
     router ospf&lt;BR /&gt;
&lt;BR /&gt;
     adoption-mode  controller&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    rf-domain default&lt;BR /&gt;
&lt;BR /&gt;
     timezone  Asia/Calcutta&lt;BR /&gt;
&lt;BR /&gt;
     country-code in&lt;BR /&gt;
&lt;BR /&gt;
     use nsight-policy  default&lt;BR /&gt;
&lt;BR /&gt;
    !&lt;BR /&gt;
&lt;BR /&gt;
    ap7532 B8-50-01-18-A2-1C&lt;BR /&gt;
&lt;BR /&gt;
     use profile  default-ap7532&lt;BR /&gt;
&lt;BR /&gt;
     use rf-domain default&lt;BR /&gt;
&lt;BR /&gt;
     hostname  ap7532-18A21C&lt;BR /&gt;
&lt;BR /&gt;
     location default&lt;BR /&gt;
&lt;BR /&gt;
     ip name-server  8.8.8.8&lt;BR /&gt;
&lt;BR /&gt;
     ip name-server  4.2.2.2&lt;BR /&gt;
&lt;BR /&gt;
     ip default-gateway  192.168.10.1&lt;BR /&gt;
&lt;BR /&gt;
     interface vlan1&lt;BR /&gt;
&lt;BR /&gt;
      description  "WAN Interface"&lt;BR /&gt;
&lt;BR /&gt;
      ip address  192.168.10.10/24&lt;BR /&gt;
&lt;BR /&gt;
      no ip dhcp client  request options all&lt;BR /&gt;
&lt;BR /&gt;
      ip nat inside&lt;BR /&gt;
&lt;BR /&gt;
      no shutdown&lt;BR /&gt;
&lt;BR /&gt;
     interface vlan2&lt;BR /&gt;
&lt;BR /&gt;
      description Guest&lt;BR /&gt;
&lt;BR /&gt;
      ip address  192.168.2.10/24&lt;BR /&gt;
&lt;BR /&gt;
      ip nat inside&lt;BR /&gt;
&lt;BR /&gt;
     use  dhcp-server-policy WiNGExpressDhcpSvrPolicy&lt;BR /&gt;
&lt;BR /&gt;
     virtual-controller&lt;BR /&gt;
&lt;BR /&gt;
     rf-domain-manager  capable&lt;BR /&gt;
&lt;BR /&gt;
     ip dns-server-forward&lt;BR /&gt;
&lt;BR /&gt;
     ip nat inside source  list default-B8500118A21C-nat precedence 1 interface vlan1 overload&lt;BR /&gt;
&lt;BR /&gt;
     no adoption-mode&lt;BR /&gt;
&lt;BR /&gt;
     !&lt;BR /&gt;
&lt;BR /&gt;
     !&lt;BR /&gt;
&lt;BR /&gt;
    &lt;BR /&gt;
&lt;BR /&gt;
 end&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Jun 2018 11:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25630#M2434</guid>
      <dc:creator>Saravanamurthy_</dc:creator>
      <dc:date>2018-06-28T11:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25631#M2435</link>
      <description>awaiting for the reply</description>
      <pubDate>Wed, 04 Jul 2018 10:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25631#M2435</guid>
      <dc:creator>Saravanamurthy_</dc:creator>
      <dc:date>2018-07-04T10:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: Different Vlan not Communicate</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25632#M2436</link>
      <description>let us start with configuring the firewall for best practice&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/What-is-the-best-practice-firewall-settings-to-be-configured-on-WM3000-series" target="_blank" rel="nofollow noreferrer noopener"&gt;How To: How to apply the best practices firewall policy to WiNG APs&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Jul 2018 09:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/different-vlan-not-communicate/m-p/25632#M2436</guid>
      <dc:creator>RobertZ</dc:creator>
      <dc:date>2018-07-05T09:01:00Z</dc:date>
    </item>
  </channel>
</rss>

