Hi SELBYCA, Thanks for your input. Please see my current working config EX2300 v3 and a config from an EX2200 v1 which is doing the same role. With regards to the EX2200 config, it is patched to an interface on a Fortigate Firewall with the main interface being the WirelessDMZ, then all the other subnets are subinterfaces and configured as vlans. The EX2200 is works as intended with the default untagged vlan being the WirelessDMZ and all the other vlans tagged. The EX2200 in this instance is the core switch with three other WirelessDMZ switches uplinking to it. When an "AP" is patched to a trunk port, it receives an IP address from the WirelessDMZ range, which is the management vlan, then each SSID with issue an ip from any other the tagged vlans depending on what vlan id the ssid has. I have tried to replicate the config in the EX2300 as in the EX2200, but I suppose that dealing with different switches and different firewalls, you don't always get the result you want, unless I'm missing something.
... View more