I am planning to replace about 20 remote branch office firewalls with RAPs. Most offices will have a few wireless laptops connected and a wired network printer. I plan to create a VLAN for workstations and a VLAN for printers. I have the following questions/concerns:
Should all branch's wireless clients be in the same VLAN assuming they can all fit? When this is done, doesn't broadcast traffic traverse each RAP's IPSec tunnel, wasting bandwidth? If so, shouldn't that be a concern and can it be mitigated without causing network connectivity issues?
Should the wired printers be configured on a separate VLAN? If so, can the RAP allow local connectivity between the wireless workstation VLAN and the wired printer VLAN? Again, my concern is minimizing traffic that traverses the tunnel.
I would appreciate any input. Thank you.