Ok, but the warning I get when enabling 'Drop Broadcast and Multicast' is:
Warning: broadcast-filter arp should be enabled with this option. Otherwise ARP requests will be dropped!
Per the user guide, I thought this was done globally on the stateful firewall:
Select the Drop Broadcast and Multicast checkbox to filter out broadcast and
multicast traffic in the air.
Do not enable this option for virtual APs configured in bridge forwarding mode. This
configuration parameter is only intended for use for virtual APs in tunnel mode. In
tunnel mode, all packets travel to the controller, so the controller is able to drop all
broadcast traffic. When a virtual AP is configured to use bridge forwarding mode, most
data traffic stays local to the AP, and the controller is not able to filter out that
broadcast traffic.
IMPORTANT: If you enable this option, you must also enable the Broadcast-Filter
ARP parameter in the stateful firewall configuration to prevent ARP requests from
being dropped. To enable this setting:
1. Navigate to Configuration > Stateful Firewall.
2. Click the Global Setting tab.
3. Select the Broadcast-Filter ARP checkbox.
4. Click Apply to save your settings before you return to the Virtual AP Profile.
Note also that although a virtual AP profile can be replicated from a master controller
to local controllers, stateful firewall settings do not. If you select the Drop Broadcast
and Multicast option for a Virtual AP Profile on a master controller, you must enable
the Broadcast-Filter ARP setting on each individual local controller.
But the checkbox is missing although the parameter is present: