WiFi VLAN Config

I'm trying to implement the following config...

My question is, Can OpenWRT put 2.4GHz traffic on specific vlans?

I've read some older forums that seem to point to OpenWRT not able to route WiFi traffic to VLANS. Without that functionality I won't be able to do what I'm intending to configure.



Yes, you bridge the SSID with the Ethernet interface that carries the VLAN you desire. Multiple SSIDs can be used (on wireless hardware that support them) to, for example, have a 2.4 GHz IoT SSID, another for guests, and a third for "trusted clients", all on their own VLANs.

802.11 itself doesn't support VLANs.

1 Like

If I understand that, I have to dedicate one Ethernet interface to VLAN 2 traffic from the 2.4 network? So I can't plug anything into it that I don't want to be on VLAN 2?

Once you get to devices that aren’t both VLAN-aware and trusted, you need to be down to a single subnet per physical net. Trunking multiple VLANs over a single Ethernet cable to a managed switch is common practice when wired devices are involved.

You don't need a physical port for your vlans.
Simply create a new wireless network on your 2.4 wifi device and add it to a newly created vlan without physical port.

1 Like


How and where to add a new created wireless network to a newly created vlan ?
Could you explain please ?
I'm trying to but don't see where to do it.

Kind Regards

Are you using luci, uci or plain config files for configuration?


Many thanks for your reply.
I'm trying using luci.
But I will follow your way.
Could you share example or screen capture ?

Kind Regards


Any updates ?
Thank you for your help

Kind Regards

The setup is really straight forward...
You don't put your ap interfaces directly to a vlan, instead you create a bridge to which your wifi and your desired vlan is attached.
For the networks without a real vlan, create also a bridged interface with attached wifi ap, assign ip and create a firewall zone for each.

If you are struggling with this setup, i believe you won't be able to setup the other desired services like vpn and captive portal.

Good luck.


Thanks for your reply.
I was not understanding this sentence

Simply create a new wireless network on your 2.4 wifi device and add it to a newly created vlan without physical port.

Now I think I understand.

  • Create a VLAN with off for all switch port
  • Create a bridge over eth.vid and wifiAP
  • ... Firewall zone ..

Thank you

Kind Regards

1 Like