Controllerless Networks

last person joined: yesterday 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

How to deny broadcast/multicast between IAP

This thread has been viewed 9 times
  • 1.  How to deny broadcast/multicast between IAP

    Posted Oct 25, 2016 07:48 AM

    Hello

    We have instant AP cluster with 120 AP's and we want to deny Layer 2 broadcast and multicast between clients on different AP's. As I understand enableing "deny inter user bridging" is only denying l2 traffic between clients on the same AP but what can we do to deny traffic between different AP's if we are using instant AP cluster not the controller solution.

    On layer 3 its easily done by access rules but what about layer 2 traffic?

     

    Aruba instant

    version 6.4.4.8-4.2.4.2_56164



  • 2.  RE: How to deny broadcast/multicast between IAP

    EMPLOYEE
    Posted Oct 25, 2016 08:59 AM

    Edit the SSID.  Under Advanced, turn on Broadcast Filter ARP for all of your SSIDs.



  • 3.  RE: How to deny broadcast/multicast between IAP

    Posted Oct 26, 2016 02:00 AM

    thanks for the reply! This setting does not help. My problem is between AP's in the same SSID I can see other AP client MAC addresses from different AP in the same SSID.

    Like if 2 clients are connected to same SSID and to AP A and other 2 are connected to same SSID AP B then A and B clients can see their mac addresses visa versa. Every client can see two mac addresses on the arp table.

    Access points are connected together with L2 switches. Can i even fix that with this kind of design?



  • 4.  RE: How to deny broadcast/multicast between IAP

    EMPLOYEE
    Posted Oct 26, 2016 05:14 AM

    In that case, you would use "Deny Inter User Bridging" under the Advanced Section of the SSID.



  • 5.  RE: How to deny broadcast/multicast between IAP

    Posted Oct 26, 2016 05:41 AM

    yes but if you read my first post as i mentioned deny inter user bridging is only denying client communication inside one AP but not between clients on different AP (same SSID).

     

    Currently if i send ARP request to each IP on the subnet I get back answers from all the clients which are not connected to same AP from where i did the request Ergo getting IP and mac addresses from all the active clients wich is security issue!

    With the broadcast filter AP's are converting ARP request to unicast but whatever i do i still get answers from clients who are not on the same AP. Ergo how can i deny all l2 traffic between clients. Basically i only need ARP request to reach DHCP server nowhere else.



  • 6.  RE: How to deny broadcast/multicast between IAP

    EMPLOYEE
    Posted Oct 26, 2016 05:44 AM

    Under Access, Create a network rule that blocks traffic from users to the subnet that users are on.

    Screenshot 2016-10-26 at 04.46.15.png



  • 7.  RE: How to deny broadcast/multicast between IAP

    Posted Oct 26, 2016 05:47 AM

    I have done that. But Access Rules are only blocking Layer3 traffic. How can I deny clients for sending arp request wich is layer2 traffic.



  • 8.  RE: How to deny broadcast/multicast between IAP

    EMPLOYEE
    Posted Oct 26, 2016 05:49 AM

    I don't know how that would be accomplished.



  • 9.  RE: How to deny broadcast/multicast between IAP

    Posted Oct 26, 2016 05:57 AM

    is it design error of instant access point solution with virtual controller? If we go over to controller version can we accomplish this with controller?

    I know that Juniper controller is able to make ACL to deny l2 traffic based on mac address. In juniper controller i can make a rule to deny all layer 2 traffic except dhcp mac address and problem is solved.



  • 10.  RE: How to deny broadcast/multicast between IAP

    EMPLOYEE
    Posted Oct 26, 2016 06:01 AM

    You should open a case with TAC and see if that feature exists the way you need it.  Instant is not an exact copy of a controller-based environment.



  • 11.  RE: How to deny broadcast/multicast between IAP

    Posted Nov 02, 2016 05:19 AM

    Hi,

     

    I got response from TAC that i was right, it is not possible to deny l2 traffic between clients on different AP's with IAP cluster. It can be done only with the controller. We will make request for future enhancement. We should be able to make ACL to deny client L2 traffic going out from any AP.

    It shouldn't be too hard to code i think.



  • 12.  RE: How to deny broadcast/multicast between IAP

    Posted Nov 08, 2016 06:56 AM


  • 13.  RE: How to deny broadcast/multicast between IAP

    Posted Jan 20, 2018 11:00 PM

    I am facing the same issues too. The isolation of clients works fine within a WAP however, between two WAP's it doesn't. This issue could be seen even in the latest IAP firmware 6.5.4.4 too.

     

    Please let us know if there is a solution for this problem.

     

    Regards,

    Shiva



  • 14.  RE: How to deny broadcast/multicast between IAP

    Posted Feb 03, 2020 06:15 AM

    I believe starting from 8.5 we can use deny Intra-VLAN feature. The Deny Intra-VLAN Traffic feature isolates clients from one another and disables all communication between peers in the VLAN network. Enabling this feature disables all peer-to-peer communication and only allows traffic from a client to gateway and whitelisted servers to flow in the network. All other traffic will be dropped by the Instant AP.

     

    For servers to serve the network they must be added to the Intra-VLAN Traffic Whitelist table. The Intra-VLAN Traffic Whitelist is a global whitelist for all WLAN SSIDs and wired networks configured with the feature.

    Deny Intra-VLAN traffic.PNG