I'm hoping someone can help me here. This looks to be very straight forward, but it's just not working right now.
We've just replaced an old HP WAP with an IAP-305. Networking on this drop has our data/management network untagged and a Guest network tagged with vlan 70. This has been working for years and through a couple of different WAPs, so we know the switch is configured properly.
We've installed a new IAP-305 and configured two SSIDs .. Staff (untagged) and Guest (tagged vlan 70). The Staff network is working fine, but Guest is not. There's some partical communication working as DHCP is being pulled properly from our internal DHCP servers, but from there clients on the Guest network can't ping their gateway. Here's what we do see...
- DHCP requests from clients are hitting firewall Guest interface which is configured for DHCP relay to internal servers
- DHCP servers are responding as client picks up appropriate IP configuration (IP, GW, DNS, etc) and are registered in active leases
- Client, with IP in proper range for Guest network, cannot ping gateway
So we know that the IAP-305 is able to communicate with Guest network / vlan 70 as the DHCP request is being sent and received properly. What we can't figure out is why the clients can't communicate on that vlan.
Given that this works fine when we plug the old HP WAP back in, we know it's not an issue on the switch side of things. Thoughts?
Here's what I see in the way of configuration summary on the Guest network:
Name:Guest
Status:Enabled
Type:Employee
Passphrase Size:13
VLAN:70
Access:Unrestricted
CALEA:Disabled
Redirect Blocked HTTPS Traffic:disable
Security level: Personal
Any input would be appreciated!