We had a somewhat similar setup and the way we did it was: All SSIDs have a VLAN tagged on them, all are in bridged mode Switchport config like your example VLANs that want to simply go out to the internet, no VLAN interface on switches. Firewall(MX/ASA) on internet connection connected to a port with those VLANs on it Firewall runs DHCP for those VLANs VLAN(s) that you want to go to DC get their DHCP from a local L3 device, either the WAN router, or in our case the L3 core switches at the site. Port where WAN router is connected does not have local VLANs 52,53 on it, just 5
... View more