Wireless

stalesnapshotverified 2026-07-12

Status: stale Last fully verified: 2026-07-12 Current evidence boundary: an authenticated read-only controller capture on 2026-07-20 supports the cluster, firmware, radio, WLAN, VLAN, security, and controller-side client-policy details below. Management takeover, explicit 802.11v state, and end-to-end QoS preservation remain unverified, so this page stays stale.

Purpose

Wireless extends the wired VLAN fabric rather than creating separate security policy. Access points bridge clients into defined trust zones; routing and inter-zone authorization remain at the edge router.


Current Cluster and Radio Evidence

The 2026-07-20 authenticated capture confirms:

Both AP records report mesh capability enabled, but the capture does not expose an explicit management-failover setting or test actual takeover. Failover behavior therefore remains an unresolved operational claim rather than a current fact.


Current Verification Status

The scheduled wireless health producer is current, and the authenticated capture covers the controller-side configuration published below. The remaining gaps require evidence outside that capture rather than guesses from nearby settings.

Because management takeover, explicit 802.11v state, and end-to-end QoS behavior remain unverified, this page stays stale and its last_verified date is unchanged.


Current WLAN and VLAN Policy

The controller exposes two locally bridged wireless classes aligned with the wired trust model:

Both use personal authentication without publishing passphrases. Neither is a guest WLAN, and captive-portal authentication is disabled. No camera WLAN is present. The controller mappings agree with the documented AP uplinks: trusted traffic is native and IoT traffic is tagged before the switching fabric carries it to the router-owned security boundary.


Current Roaming and Client Policy

Both classes advertise 802.11k neighbor reports and enable controller-assisted smart roaming. Their remaining policy intentionally differs:

The capture does not expose an unambiguous 802.11v field. Smart-roaming and neighbor-report settings are not treated as substitutes for that missing protocol evidence.


Remaining Evidence Before Active Status

Cluster membership, models, current controller role, firmware, radio policy, WLAN/VLAN mapping, authentication, protected management frames, isolation, guest posture, 802.11k, 802.11r, smart roaming, balancing, and controller-side QoS are covered by the current evidence.


Architectural Invariants

Even while the snapshot is stale, these design boundaries remain intentional: