802.11s - Simple VLAN trunk

If you intend to set a Mesh network to distribute more than one subnet, the only way to achieve this with plain 802.11s is by setting a new mesh interface for every subnet. This is not optimal as you for example crow radio frequency spectrum and your devices will need to create many vifs, at least two per subnet.

Using this way to insert multiple networks inside one mesh network is the most simple one perfect for domestic or any network where there is only just one wan access node. You can set any amount of nodes you want but usually when there is a large amount of nodes, is practical to configure more than 1 node to bring wan connectivity, so you avoid having many HOPs till Internet access. That's the only reason this setup is perfect for domestic or any only one wan node environment. In the future perhaps this guide could add multiwan setup, but only when a simple way to setup with pure LuCI is possible.

A mesh with VLAN works exactly like a ethernet VLAN trunk. It seems that not all WiFi chipsets are able to support this and at the moment are know to work mt76 devices like the MT7915E using OpenWrt 23.05 and later.

WIP.

The steps to insert 802.1q VLAN bridge is quite simple, the mesh vif becames just one more port in the bridge.

Setting up the "main" node

Main node is referred to that node that usually has wan connectivity and dhcp, ra, dns server...

First you must have wpad mesh or full variants installed, basic ones doesn't support 802.11s networks.

Second a mesh network, go into Network → Wi-Fi and simply add one 802.11s network with the ID and security setting you want. Do not assign any network. Enable the network and take a look to the id it gets, usually some kind of wl0-mesh0 or phy0-mesh0, and remember it.

Third set up the VLAN bridge by going to Network → Interfaces → Devices. Select configure in the br-lan device and in bridge ports drop down the combo and in Custom write the id of the mesh network. Go into VLAN filtering tag and Add the VLANs you need and check all the VLANs you want to insert into the mesh as Tagged for the mesh port, now Save.

DO NOT apply the changes yet as you will lost access to the router needing to rollback o accessing IPv6 Link Local to it. Instead return to Interfaces tab and edit the lan interface. Drop down the device combo and select Software VLAN: br-lan.##. ## is the VLAN you are going to use for you normal network. Now you can safely apply changes.

Setting up the "secondary" nodes

Secondary nodes are referred to any other node not being the main one. There is a important difference with the secondary ones and the main one. The main one must be part of the VLAN as it supply DHCP, wan access and so on. The secondary nodes instead can be or not be part of the different VLANs. Be aware that if you don't make it part of any VLAN, at least the one corresponding to your main lan you will lost access to the node itself and you will have to use IPv6 Link Local. Also, not letting the node to be part of the Layer 3 in a VLAN will make it to unable use 802.11v Proxy ARP (if you try to enable it the vif won't even start) or use active steering like usteer or dawn.

Install wpad mesh or full and set up the mesh wifi network as in the main one, use the same mash id and security settings and do not assign any network, take note of the id it gets wl0-mesh0, phy0-mesh0... the one that gets for you.

Go into Network → Interfaces → Devices and configure br-lan, as in the main router add the mesh as a port by setting is in the Custom field and go to VLAN filtering replicating the same VLANs you setted up in the main node and tag all of them in the mesh port, you can for the VLANs that you don't want this particular node to be present at Layer 3 deselect the Local checkbox. The recommendation is to leave at least Local in one of the VLANs usually the VLAN corresponding to your main lan. For other VLANs you can uncheck it if you are not going to use Proxy ARP or active steering in the VLANs you uncheck.

Again DO NOT save yet, go to Interfaces tab and configure the lan interface, set a static IP to not conflict with the main node one or DHCP and the device from br-lan to br-lan.## being ## your main VLAN (you should have let the Local tick at least for this VLAN). This step must be done with careful, as the IP will change so you will have to access the new IP in the browser.

Mixed hardware / driver generations (802.11ax + 802.11ac)

If your mesh backhaul mixes an 802.11ax (HE) capable radio with an older 802.11ac (VHT)-only radio, make sure both sides use the same htmode (e.g. VHT80 on both), even if one radio supports HE80.

  • Last modified: 2026/09/22 12:50
  • by howl