Thanks Colin,
In playing with this I noticed that vlan 1 seems to be dealt with differently from other vlans by the AP's switching component. If I use this wired AP profile on the AP downlink ports everything works as expected (248 is a VoIP vlan):
Wired AP enable Enabled
Trusted Trusted
Forward mode bridge
Switchport mode trunk
Access mode VLAN 2
Trunk mode native VLAN 2
Trunk mode allowed VLANs 2,248
Broadcast Broadcast
The switchport config on the link to the AP has vlan 2 & vlan 248 tagged, with our AP management vlan untagged. I can plug my laptop in and it appears on vlan 2, and my VoIP phone works on vlan 248.
However the same profile with Vlan 1 configured as the native vlan instead of vlan 2 (and vlan 1 added to the allowed list) results in my laptop appearing on our AP management vlan (which is untagged on the link to the AP) rather than vlan 1. It seems to be impossible to tag vlan 1 on the link to the switch. Is this expected behaviour?
(Note I am using a 'shutdown' wired port config on the AP enet0 uplink)
PS I'm aware that it is not recommended to use vlan 1, but we have customers whose networks are reasonably old and some (as in this case) still use vlan 1.