Hello there- I have read numerous posts here and elsewhere about VLANs but I did not find my exact question so here goes:
We recently purchased a Balance 20x and an AP One AX Lite for our small office. I’ve got the Balance 20x set up and working great with all of our wired clients. The Balance is also set up to manage the AP. The AP is set up with 2 wireless networks, one for the internal trusted network and one untrusted network for wireless guests. The two SSIDs have been created and I set up a VLAN 22 that has been assigned to the guest wifi network. The trusted network has VLAN “none”.
I have the AP connected to a Netgear GS324TP managed POE switch which in turn is connected to one of the trunk ports on the Balance 20x. I know enough about VLANs to be dangerous (haha) but I am no expert.
I can connect to the trusted wifi network and get an IP assigned that corresponds to the trusted internal network and I can connect to the internet. I can connect to the untrusted guest wifi network and get an IP assigned to the untrusted guest network but I cannot connect to the internet, which I assume is because I still need to configure the switch for the guest VLAN.
My first question is about the Peplink AP. Does the AP know to tag the traffic with either VLAN 22 for the guest network or untagged for the trusted wifi network? (Actually, is the trusted wifi tagged 1 or untagged?)
My second question is about configuring the vlan on the Netgear switch. Do I leave all ports on the switch untagged, set the port that is connected to the AP as tagged for VLAN 22, and also set the uplink port to the Balance 20x as tagged for VLAN 22? Do I need to also tag those two ports with VLAN 1 in the switch? My confusion here is from the Netgear documentation for the switch, it says this:
“In the Ports table, click each port once, twice, or three times to configure one of the following
modes or reset the port to the default mode:
• T (Tagged). Selects the port as a tagged port in the VLAN. All frames transmitted on
the port are tagged for this VLAN.
• U (Untagged). Selects the port as an untagged port in the VLAN. All frames
transmitted on the port are untagged for this VLAN.
• Blank. The port is excluded from the VLAN.”
These instructions makes it seem like if I tag the AP port and the uplink port with VLAN 22, then all traffic (i.e. the untagged internal network) will have the VLAN 22 tag added.
Third question: Do I leave all ports on the Balance 20x as trunk?
Thank you!