Wireless Access

Reply
Contributor I

Using psk can you set wifi clients not to speak to each other?

Not sure this is a good idea as perhaps this stops them IM'ing each other but is there an option to do this?

Aruba Employee

Re: Using psk can you set wifi clients not to speak to each other?

In the VAP profile, there is an option named "Deny inter user traffic".  Check that and users will NOT be able to talk to each other.  IM, Voice and Facetime are a few things that may break, so be careful.

Contributor I

Re: Using psk can you set wifi clients not to speak to each other?

Thanks this wont be an option then as IM will need to work... anything else you can do to make PSK more secure?

Aruba Employee

Re: Using psk can you set wifi clients not to speak to each other?

Create a rule that allows the ports/protocols your IM uses, then denies everything else to/from your WLAN subnet(s).  Make sure that rule is near the bottom of your role ACL listing, but above anything that would allow user>user traffic.

Frequent Contributor II

why don't u create a FW policy to prevent it ?

why don't u create a FW policy to prevent it ? 

Contributor I

Re: why don't u create a FW policy to prevent it ?

Sounds complicated on howto fit with other rules... so we only allow http and https normally...

Aruba Employee

Re: why don't u create a FW policy to prevent it ?

Its not that complicated. 

 

Create an ACL that allows IM ports/protocols, then denies packets with the destination of your WLAN subnet.  Put those two ACLs into the role your users are using and VOILA, no more user>user traffic EXCEPT IM. 

 

The order of the rules is very important.  The rules are processed top down and first match.   Just make sure you allow DHCP, DNS and other critical services first, then the IM ACL, then the drop user-user ACL, then your HTTP/HTTPS allow ACL.  At the end is an implicit deny all.

Contributor I

Re: why don't u create a FW policy to prevent it ?

Thanks:)

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: