Recommended Posts

I'm new to the whole managed switches thing, so I am completely lost right now. I have two buildings that are right next to each other, they are connected by fiber. The fiber terminates into unmanaged switches on both ends. This keeps the workstations/servers in both buildings connected to each other. Internet comes into one building, and we use an NSA 240 as our router/firewall. We have one SonicPoint connected directly to the NSA to provide wireless, there are two SSIDs (corporate and guest) broadcasting from the SonicPoint. Now we need to put two SonicPoints in the other building. I purchased two Dell PowerConnect 5524 switches thinking that we could use VLANs to connect the two new SonicPoints to the NSA. The SonicPoints need to be directly connected to a port on the NSA, I am thinking I could use VLAN's to trick the SonicPoints into thinking they are directly connected to the NSA. I figured I'd put one 5524 into each building, plug the fiber into each to connect the building, and then set up VLANs for workstation traffic and SonicPoint traffic. Problem is, I have no idea where to start. I've looked over the documentation multiple times, but I'm confused about access vs general vs trunk and native VLANs and PVIDs and everything else. Can someone please point me in the right direction? Thanks!

The sonicpoints need to be connected to the wlan port (which could by any port!), at this point if you want to allow wlan traffic to the lan, you have to bridge the two ports, and have ALL of your sonicpoints connected to a switch which connects to the wlan. You cannot and will not be able to use ANY sonicpoint on the LAN segment. A firmware update I believe will make the sonicpoints in the future become regular APs and be use on the LAN segment, but until then you have to use them on the wlan segment.

Not sure why you think you needed to introduce vlans for?

from the sonicpoint deployment guide

Layer 2 and Layer 3 considerations for SonicPoints

SonicWALL uses two proprietary protocols (SDP and SSPP) and both *cannot* be routed across any layer 3 device. Any SonicPoint that will be deployed must have an Ethernet connection back to the provisioning SonicWALL UTM appliance, in the same broadcast domain/network.

SonicWALL UTM appliance must have interface or sub-interface in same VLAN/broadcast domain as SonicPoint.

SonicPoints must be able to reach the DHCP scope on the SonicWALL; make sure other DHCP servers are not present on VLAN/broadcast domain.

Sharing SSIDs across SonicPoints attached to multiple interfaces may case connectivity issues as wireless client roams to different SonicPoint subnet.

From how you have described your network, your devices are all on the same broadcast domain. You should be able to plug your new sonicpoints into any port on the switch(es) in the other building without issue.

You do not need to use vlans from what I can see.

The sonicpoints need to be connected to the wlan port (which could by any port!), at this point if you want to allow wlan traffic to the lan, you have to bridge the two ports, and have ALL of your sonicpoints connected to a switch which connects to the wlan. You cannot and will not be able to use ANY sonicpoint on the LAN segment. A firmware update I believe will make the sonicpoints in the future become regular APs and be use on the LAN segment, but until then you have to use them on the wlan segment.

Currently the one SonicPoint is connected to the WLAN port, and we've bridged it to the LAN port so people on the corporate SSID can access servers/etc. But now I need to connect two more SonicPoints in the building across the street. Because I cannot physically plug the two SonicPoints into the back of the NSA, I need to find a way fool them into thinking they are.

Not sure why you think you needed to introduce vlans for?

from the sonicpoint deployment guide

Layer 2 and Layer 3 considerations for SonicPoints

SonicWALL uses two proprietary protocols (SDP and SSPP) and both *cannot* be routed across any layer 3 device. Any SonicPoint that will be deployed must have an Ethernet connection back to the provisioning SonicWALL UTM appliance, in the same broadcast domain/network.

SonicWALL UTM appliance must have interface or sub-interface in same VLAN/broadcast domain as SonicPoint.

SonicPoints must be able to reach the DHCP scope on the SonicWALL; make sure other DHCP servers are not present on VLAN/broadcast domain.

Sharing SSIDs across SonicPoints attached to multiple interfaces may case connectivity issues as wireless client roams to different SonicPoint subnet.

From how you have described your network, your devices are all on the same broadcast domain. You should be able to plug your new sonicpoints into any port on the switch(es) in the other building without issue.

You do not need to use vlans from what I can see.

I think this isn't working for us because we've bridged the wireless and lan ports on the NSA unit.

If you have bridged the wlan to lan, then you can plug into any lan port. If you connect to other dumb switches, you could connect to any of them. Your on one big dumb broadcast domain. So you can plug in anything anywhere and get anywhere that is plugged into any other port on any of the switches, etc.

So again I am no seeing where you need to setup vlans, or what this is going to do - since you don't have any setup now.

No where in the guide does it say you have to be directly connected to anything, nor does setting up a vlan accomplish that even if did.

I am looking at the picture of the nsa 240 -- where is this WLAN port you talk about? Says it can support up to 16 sonicpoints - it clearly does not have 16 ports ;) So not sure what you are talking about with a WLAN port

post-14624-0-65038600-1343825172.png

The individual ports are "programmable", so you can define a port as WAN, LAN, WLAN, etc. In our case, port X6 is the WLAN port, it's bridged to X0 (the LAN port). Port X6 also has a VLAN so we can have two SSIDs running off one SonicPoint.

Capture.jpg

Just wanted to come back and let everyone know that I got this to work. I had to set up the same VLAN's on the switches that were created in the Sonicwall, and then trunk the switch to the Sonicwall. Created access ports for the SonicPoints and was good to go. Thanks for the help everyone!

  • 1 year later...

I'm trying to configure pretty much the same setup. Can you give me more information on how you connected the Sonicwall to your network switches?  Di you plug X0 and X2 into the same switch?  If so, how were they provisioned?  Did you set them up as an aggregate/trunk?

 

If I plug a SonicPoint into X2 it works just the way I want. I'm not sure how to "extend" that XO port to my switches?  I have tried a few ways but each time I lose DHCP on the Geast WLAN.

 

Thanks

  • 2 months later...

I'm trying to configure pretty much the same setup. Can you give me more information on how you connected the Sonicwall to your network switches?  Di you plug X0 and X2 into the same switch?  If so, how were they provisioned?  Did you set them up as an aggregate/trunk?

 

If I plug a SonicPoint into X2 it works just the way I want. I'm not sure how to "extend" that XO port to my switches?  I have tried a few ways but each time I lose DHCP on the Geast WLAN.

 

Thanks

Hello, 

 

I recently completed a 25 Sonicpoint deployment for a school.  My recommendation for a secure and stable installation.  You should get a POE switch or switches to provide power and data to your access points.  Not sure how many access points you are delpoying, but get a POE switch to handle the  number of access points.  We used Cisco Small Business gigabit POE managed switch, which works great.

 

I strongly recommed using VLANs on the Sonicwall and the POE switch.  If you create VLANs you setup will be easy and manageble.  As an example we created 3 VLANs and created those sub-interfaces  (50, 60, and 70) on the WLAN (X4).  50 was for Corp users, 60 for guest users, and 70 is for another function, but readily available.    On your POE switch(s) create VLANs as well.  Be sure to assign each port that will host a Sonic access point to VLANs 50 and 60 respectively.

 

I hope this helps.

This topic is now closed to further replies.
  • Posts

    • Google pitches Spanner as one database for all AI agents with these new featues by Karthik Mudaliar Google Cloud is introducing new features within Spanner, its distributed database, as a place where enterprises should keep their data, using which AI agents could make smarter and better decisions. In a detailed blog post, Google highlighted quite a few features coming to Spanner, including relational data, graph relationships, vector search, key-value access, full-text search, and operational analytics together in one database architecture. Google says that today's systems aren't well-made for AI agents. There could be data that is present in one system, search indexes in another, embeddings in a vector database, and relationship data in a graph database. This fragmentation isn't great for AI agents to do their jobs because they don't have access to all of this data in one place. This is where Google is positioning Spanner as a solution. Spanner is already a globally distributed relational database with strong consistency, and Google wants its customers to see it as a broader data layer for AI applications. The company introduced something called Spanner Graph, along with integrated vector search, full-text search, a Cassandra-compatible key-value endpoint, and a columnar engine for analytical queries on operational data. Google also added that its ScaNN-powered vector search can support indexes with more than 10 billion vectors, while the columnar engine can make some analytical scans up to 200 times faster. All of this isn't just exclusive to the Google Cloud Platform, and there's support for multi-cloud as well. This comes via Spanner Omni, which Google says is a downloadable, containerized version of Spanner that can run on Kubernetes and in environments outside Google Cloud, including Microsoft Azure and AWS, and even on-premises infrastructure as well as edge deployments. Google says that customers who are interested in the full-featured edition should contact the company, and there's no word on commercial availability or separate pricing. Those interested can read the full blog by Google Cloud, which details these features individually.
    • Kalmuri 4.2.5 by Razvan Serea Kalmuri is your all-in-one, portable screen capture and recording solution designed for speed, simplicity, and flexibility. Whether you need a full-screen snapshot, a custom area, a scrolling webpage, or smooth video recording, Kalmuri delivers with ease. Capture text instantly from images with built-in OCR, keep floating images on top for quick reference, and use the precise color picker for perfect design matching. Customize hotkeys to work your way and share results instantly with built-in upload options. Kalmuri runs without installation, making it ideal for USB use, and offers an intuitive interface that’s easy to learn. Kalmuri key features: Video recording support (designation of whole screen and area) Whole screen, active program, window control, area application Extract text from images using optical character recognition (OCR). Support for PNG, JPG, WEBP, BMP, GIF file formats MP4 video recording powered by FFmpeg for high-quality results Full web page capture Share the captured image on the web Color extraction function Printer output Hotkey settings Adjustable via keyboard for area capture (Arrow key, Ctrl+Arrow key, Shift+Arrow key) File name format (sequential, datetime) Free to use it at work, at home, in government offices, at school, etc. Using Kalmuri portable for video recording Kalmuri’s portable version doesn’t include FFmpeg, which is required for video recording. Without it, you’ll get an “error FFmpeg.exe not found” message. To fix this, download FFmpeg from the provided link, extract it, and place FFmpeg.exe in Kalmuri’s folder. Kalmuri will then recognize it automatically, allowing you to start recording in high quality instantly. Kalmuri 4.2.5 changelog: Fixed an intermittent crash when using Area Capture Improved stability for Area Capture and screen recording Resolved a capture issue that could occur right after startup Download: Kalmuri 4.2.5 | 24.2 MB (Freeware) Download: Kalmuri Portable 4.2.5 | 2.1 MB View: Kalmuri Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • They have lots of info on me, I have a facebook account and have done so for years, it was the thing to have then. My phone number is not on it. I don't have the Facebook app on my phone these days, just the messenger part, and only for a couple of people to contact me, most will text me via SMS or phone. I agree, Meta, like others, even without an account will know something about me. Just have to try and keep some things private Also, never saw the need for Whatsapp, people used to ask for me to join it, but as I said to them, I have SMS and a phone, use that, or email
  • Recent Achievements

    • First Post
      rosiecharles earned a badge
      First Post
    • Reacting Well
      Juan Dela earned a badge
      Reacting Well
    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      271
    3. 3
      PsYcHoKiLLa
      145
    4. 4
      Steven P.
      98
    5. 5
      macoman
      54
  • Tell a friend

    Love Neowin? Tell a friend!