Flint 3 (GL-BE9300) as AP/Router behind FireWalla Gold Plus

Hi all,

I am attempting to configure the Flint 3 (GL-BE9300) as an AP/router behind the Firewalla and a switch with multiple VLANs.

The flow of traffic goes: ATT Humax BGW320-500 → FireWalla Gold Plus → Aruba Aruba Instant On 1830 8-Port Gb Smart Switch → Flint 3 (GL-BE9300)

The VLANs that will passthrough to the Flint 3 are ‘10 Work’ and ‘20 Home’.

I would like the VLANs to passthrough the Flint 3 so that I can create two SSIDs, one for each VLAN.

I am running into issues when I attempt to configure the VLAN bridge in Network → Interfaces → Devices → br-lan. Once I attempt to do this, I am no longer able to access the router and LuCI/UCI.

Do not enable VLAN filtering on br-lan until a management path has been defined. Enabling it without keeping the bridge/CPU and your management port in an untagged management VLAN commonly removes access to LuCI. If the change was made with LuCI’s rollback-safe “Apply” option, wait for it to revert; otherwise, use another unchanged LAN port or restore the router to factory settings, noting that a reset erases its configuration.

For this topology, if Firewalla supplies routing and DHCP for VLANs 10 and 20, the Flint 3 should operate as a VLAN-aware AP: the Aruba port must carry VLANs 10 and 20 tagged, and each SSID must bridge to its corresponding tagged interface. Keep management on a separate untagged/native VLAN or a dedicated port while configuring. Multiple VLAN-to-SSID mapping is not currently supported in the standard GL.iNet interface and requires advanced LuCI/UCI configuration.

Before suggesting model-specific interface mappings, please confirm the Flint 3 firmware version, which physical port connects to the Aruba switch, and whether Firewalla provides DHCP for both VLANs. This determines whether the setup should be a pure bridge or use routed VLAN interfaces. This feature is not officially supported by GL.iNet. Any guidance is provided on a best-effort basis, and GL.iNet Technical Support may not be able to troubleshoot or maintain this configuration.

This reply was generated by AI. Please verify its accuracy.

GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.

Flint 3 firmware: 4.10.1
Physical port 2.5G WAN connects to the Aruba swith
Firewalla provides DHCP for both VLANs

Keep br-lan unchanged and use one LAN port as a dedicated management connection. On Flint 3, the 2.5G WAN port is eth0, so VLAN subinterfaces can be created directly on that port without enabling VLAN filtering on br-lan.

While connected through a LAN port, back up the configuration and create the two Layer-2 networks:

uci batch <<'EOF'
set network.work_dev='device'
set network.work_dev.type='8021q'
set network.work_dev.ifname='eth0'
set network.work_dev.vid='10'
set network.work_dev.name='eth0.10'

set network.br_work='device'
set network.br_work.type='bridge'
set network.br_work.name='br-work'
add_list network.br_work.ports='eth0.10'

set network.work='interface'
set network.work.proto='none'
set network.work.device='br-work'

set network.home_dev='device'
set network.home_dev.type='8021q'
set network.home_dev.ifname='eth0'
set network.home_dev.vid='20'
set network.home_dev.name='eth0.20'

set network.br_home='device'
set network.br_home.type='bridge'
set network.br_home.name='br-home'
add_list network.br_home.ports='eth0.20'

set network.home='interface'
set network.home.proto='none'
set network.home.device='br-home'
EOF

uci commit network
reboot

After reboot, use LuCI Network → Wireless to create an AP/SSID for Work and bind it only to the work network; create the Home SSID and bind it only to home. Repeat on each desired radio if the same SSID should be available on multiple bands. Do not enable DHCP on either Flint interface—Firewalla will supply it. Configure the Aruba port connected to the Flint WAN as a trunk with VLANs 10 and 20 tagged. Test VLAN 10 first and confirm that its client receives the expected Firewalla lease before adding VLAN 20. Keep management through the unchanged LAN port at this stage.

A closely matching Flint 3 staff configuration is available in this forum guide. Multiple VLAN-to-SSID mapping is not officially supported in the GL.iNet interface; this LuCI/UCI configuration is best-effort, and Technical Support may not be able to maintain or troubleshoot it.

This reply was generated by AI. Please verify its accuracy.

GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.

Hi,

Thank you for sharing your network setup.

You can refer to the following guide:

For your setup, you can adapt the example to use VLAN 10 (Work) and VLAN 20 (Home) , with Firewalla continuing to provide DHCP for both networks.

Hope this helps. Please let us know if you encounter any issues.