A wireless virtual local area network (VLAN) and a device selectively
connecting to the wireless VLAN over a second wireless network that may
be independent of the wireless VLAN. The device is capable of connecting
to at least the wireless VLAN and to the second wireless network.
Wireless VLAN access points are each connected to an Ethernet aggregation
switch, which is VLAN aware and matches client traffic from connected
access points with access VLANs. A wireless VLAN switch maintains an
association table between access VLANs and core VLANs. The second
wireless network may be remotely connected over the Internet or a private
network to a tunnel endpoint. The tunnel endpoint is connected to the
VLAN switch, which uses the association table to manage free-form client
traffic between connected devices and other mobile stations at access
VLANs and appropriate core VLANs.