× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Reply

WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

jesusdf
Aspirant

WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

As the title says, I could reproduce what was told in this post:

 

https://community.netgear.com/t5/Business-Wireless/WAX220-WPA2-Enterprise-help-with-VLAN/td-p/232390...

 

But I have managed to find a way for it to work, however the workaround is not a valid solution for us.

 

My desired configuration is as follows:

 

Updated to latest firmware to date (v1.0.3.4).
Management VLAN: 20
WAX220 Management IP (DHCP): 172.16.20.10, gateway on 172.16.20.1
RADIUS server on another VLAN, IP 10.0.10.30, the firewall has rules to allow the connection.
Access Point: "MyWiFi" -> WPA2 Enterprise (or WPA3 Enterprise, same behaviour) + VLAN Isolation 30 (Users)

 

Expected behaviour: Wireless works and user gets connected to the VLAN 30 (Users).
Tested behaviour: No connection, not a single packet sent over the network (made many packet catpures on all the VLANs).

 

Workaround that I found while I was testing:

 

If I set the Access Point "MyWiFi" VLAN to the same id of the management VLAN (VLAN 20), the radius server receives the authentication packet and the wireless connection works, however, wireless client gets an IP on the management VLAN, instead of the desired Users VLAN (30).

 

Seems like there is some kind of problem with the routing table and the RADIUS authentication is not sent over the correct network interface.

Message 1 of 13

Accepted Solutions
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

The proposed solution is to RMA the devices for a different (newer) model, which I accepted.

I hope that fixes it, if not, seems like OpenWRT would be the best solution for that use case.

View solution in original post

Message 12 of 13

All Replies
ErwinL
NETGEAR Moderator

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hello jesusdf

 

And welcome to the NETGEAR Community! 🙂

 

What is your switch configuration, specifically the port where the AP is connected? 

 

Have a lovely day,
Erwin
Netgear Team

Message 2 of 13
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hi, All the VLANs are setup as tagged on that port, so it works as a trunk. The VLAN 1 (untagged) is not used anywhere, everything has a VLAN.

Message 3 of 13
ErwinL
NETGEAR Moderator

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hello jesusdf

 

Looks like the port is also a member of VLAN 20. May I know which port is your DHCP server for all VLANs is connected? Is that port a member of all the VLANs on the switch? Is it coming from a router, switch or a PC? Is it tagged as well? 

 

Have a lovely day,
Erwin
Netgear Team

Message 4 of 13
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Everything is connected to a pfSense firewall and a switch. The switch configuration is fine, it's a problem with the netgear firmware.

 

To reproduce it:

 

1) Management with VLAN A.

2) Wireless with VLAN B.

3) If the access point security is WPA3 personal, the connection works as expected, the users get into VLAN B, and the web administration is on VLAN A.

4) If you switch the security to WPA3 enterprise, the connection only workis if A = B. In any other case, the access point does not send a single RADIUS packet.

 

I have opened a support ticket for this same issue. I will update here if there's any change.

Message 5 of 13
ErwinL
NETGEAR Moderator

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hello jesusdf

 

Thank you for reaching out to our support team for assistance. Please keep us updated on any progress with your ticket.

 

Have a lovely day,
Erwin
Netgear Team

Message 6 of 13
ErwinL
NETGEAR Moderator

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hello jesusdf

 

Could you please share the current status of the issue you raised with our support team?

 

Have a lovely day,
Erwin
Netgear Team

Message 7 of 13
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hi,

   The support team has passed the issue to the developers and they are reviewing it.

   They have agreed to tell me about the current progress this week.

 

Best regards,

Jesus

Message 8 of 13
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hi, I quote what I received today:

 


... in reference to your case for an issue to use WPA3 entreprise authentication on separate VLANs.

 

I received an update from the firmware developers indicating that they are still investigating the issue.

 

I'll let you know as soon as I have more information.


Best regards

Message 9 of 13
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Issue still open. Two months have passed by. No response, no hope.

 

On the other hand... https://forum.openwrt.org/t/netgear-wax220-support-almost-complete/152065/202

 

Message 10 of 13
Nivedita
NETGEAR Expert

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Our Internal team is working on this issue and keep you posted on the updates.

Message 11 of 13
jesusdf
Aspirant

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

The proposed solution is to RMA the devices for a different (newer) model, which I accepted.

I hope that fixes it, if not, seems like OpenWRT would be the best solution for that use case.

Message 12 of 13
ErwinL
NETGEAR Moderator

Re: WAX220 v1.0.3.4 + Management VLAN + Radius + AP VLAN = No connection

Hello @jesusdf 

 

I do apologize for the inconvenience but hanks for accepting the replacement device. I do hope the replacement unit works for you. Moving this thread to closed since you have a different device now. 

 

Have a lovely day,
Erwin
Netgear Team
 

Message 13 of 13
Top Contributors
Discussion stats
  • 12 replies
  • 2003 views
  • 0 kudos
  • 3 in conversation
Announcements