Search code examples
firewallssidvlan

Why can't VLAN tagging work on a wifi SSID interface?


A little while I ago I issued a check-up/rundown/audit on our firewall environment. One of the things that popped up is the fact that we use a wifi SSID interface where VLAN tagging is happening on. But I don't quite understand why this is useless and unnecessary. I hope some of you can help me out here, thanks.


Solution

  • VLAN tagging is used on trunk interfaces to separate logical networks on a single physical interconnect. WLANs aren't (usually) used for interconnects.

    To separate clients in multiple logical networks it's much better to use separate SSIDs. Theses SSIDs you usually bridge / associate with different VLAN IDs for your wired network.