Cambium cnMatrix PBA: VLAN Configuration Guide
Cambium cnMatrix: Policy-Based Automation VLAN Config
Policy-Based Automation (PBA) is the mechanism that eliminates manual port-by-port VLAN configuration on cnMatrix switches. This article explains how PBA VLAN assignment works and how to set it up for a typical Habitech installation with Cambium APs and third-party devices.
How PBA VLAN Assignment Works
When a device connects to a cnMatrix switch port, PBA identifies it via its device profile and automatically assigns the correct VLAN and QoS policy. No port-specific configuration is needed.
The process:
- Device connects to any available switch port.
- cnMatrix identifies the device against the configured device profiles (by MAC OUI, LLDP, or Cambium AP type).
- Policy applies — the port is placed into the correct VLAN, QoS is applied, and trunk or access mode is set per the profile.
- Device disconnects — PBA wipes the dynamic config from that port (Auto Policy Wipe), leaving it clean for the next device.
Typical VLAN Profile Structure
For a combined AP + IoT + staff deployment, a typical profile set would be:
| Profile | VLAN | Applied To |
|---|---|---|
| CambiumAP | Management VLAN (e.g. VLAN 10) | Cambium cnPilot and XV/XE APs (detected via Cambium OUI) |
| StaffWireless | VLAN 20 | Applied to AP trunk — allows staff SSID traffic |
| GuestWireless | VLAN 30 | Applied to AP trunk — isolates guest SSID |
| IoT | VLAN 40 | Building automation, door controllers, cameras (by OUI or LLDP type) |
| Unknown | VLAN 99 (quarantine) | Any device not matching a profile |
Site Survivability
If cnMaestro cloud connectivity is lost, all previously applied PBA policies remain active on the switch. Ports continue operating with their assigned VLANs. Only new device profile changes or config pushes require cloud connectivity.
This means a site outage on the Cambium cloud does not take down VLANs or connectivity for end users already on the network.
Wireless-Aware Monitoring
cnMatrix switches pass upstream context about connected wireless devices to cnMaestro. This allows cnMaestro to display:
- Which AP is connected to which switch port
- Which VLAN the AP management traffic is using
- Integrated wired + wireless topology view
Troubleshooting a client connectivity issue can be done from cnMaestro without needing to log into the switch separately.
Key Limitation
PBA profiles are configured in cnMaestro and pushed to the switch. Manual CLI VLAN configuration is still supported but will be overwritten by PBA policy on the next config sync. For any VLANs that must persist outside PBA (e.g., uplink trunk config), use static configuration committed before PBA is enabled.
This article was adapted from Cambium Networks' original guidance: "cnMatrix Ethernet Switches — Enterprise Network Switching Made Simple" — https://www.cambiumnetworks.com/products/switching/ Habitech-edited for UK trade installer context. Original © Cambium Networks, Ltd.