Access Ports
All Access Ports are set to Untag (native) VLAN 1 by default. This means that all Access Ports belong to the native VLAN and are all part of a single broadcast domain. When untagged frames from a client arrive at an AP's Access Port, they are given an 802.1Q VLAN header with "1" as their VLAN ID before being passed onto the wired network.
When VLAN 1 traffic arrives destined for the client, the VLAN tag is removed and it is sent as plain (untagged) 802.11 traffic. When any tagged traffic other than VLAN 1 traffic arrives at the same Access Port, it is dropped rather than forwarded to the client.
To remove ports from the native VLAN and assign them to specific VLANs, select Access Portand enter any valid VLAN ID in the VLAN IDfield (valid VLAN IDs are 2-4094).
The following table describes the behavior of incoming and outgoing traffic for Access Ports with VLANs configured.
Access Ports with VLANs configured
| VLAN Settings | Incoming Traffic (from the client) | Outgoing Traffic (to the client) |
|---|---|---|
| Access Port, Untag VLAN 1 | All incoming traffic is native VLAN (VLAN 1). | All outgoing traffic on the port is sent untagged. |
| Access Port, Untag VLAN [2-4094] | All incoming traffic is sent to the VLANs specified. | Only traffic belonging to the specified VLAN is forwarded. All other VLAN traffic is dropped. |