I have a WLC 4402 configured to run 1131AG LAPs in 11 buildings.
I already have a working SSID on VLAN 3 for public consumption.
Now, I want to add a second SSID on a separate VLAN 6 that uses a RADIUS server to authenticate our Windows domain users. This SSID will not be broadcast, either. Basically, what I want to end up with is two SSIDs (one public, one private) operating on different VLANs.
I've set up the new subnet scope and scope options on the same DHCP servers.
I've set up the subinterface on the router and added the same IP-Helper addresses of the DHCP servers.
I've got the IAS server configured and communicating with the WLC.
I've set up the second interface and WLAN on the WLC 4402.
When testing on a laptop, I can manually enter the SSID and get it to attempt to connect. The SSID is being seen, but the laptop is failing to obtain an IP address from the DHCP servers.
In troubleshooting this, I'm wondering how this configuration can work, since the LAPs are access ports on the switches assigned to VLAN 3. They cannot be made into trunk ports on the switch and work with the WLC.
I've searched for anything that would describe this kind of configuration, but haven't found anything, yet.
Does anyone have some kind of configuration example that would describe how to get all these components configured and operational to support two SSIDs on two VLANs?