QuestionQ15

Switching

A client connected to a tunneled open network is receiving an incorrect VLAN. Your customer has a gateway and provided a packet capture from a switch-port mirror on the upstream switch, along with packet captures from the IPsec tunnel and the GRE tunnel, to help identify the VLAN sent from the controller to the AP.

Where can the VLAN assignment be seen?

Explanation

GRE encapsulation preserves the client Layer 2 frame and its VLAN tag, allowing the VLAN assignment to be inspected in the GRE tunnel capture. IPsec encrypts the payload, and an upstream switch-port mirror exposes the outer transport traffic rather than the encapsulated client VLAN.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!