06-07-2021 05:14 AM - edited 07-05-2021 01:24 PM
Hi board,
in AireOS, P2P blocking is supported only if the wireless clients are on the same WLC and in the same VLAN
Are there the same restrictions for the 9800? Assume client1 and client2 are in the same SSID but are assigned to different VLANs. Is P2P blocking drop working?
06-07-2021 07:58 AM
I really don't want to spoil, but obviously P2P blocking only works if the clients are in the same VLAN.
At least this is what I tested. The question is: Is this a "normal" behavior or considered a bug? If I don't find any documentation about it, it could be both, right?
06-07-2021 09:27 AM
I believe this is normal behavior since it follows how AireOS implements P2P blocking. I to have tested this on both AireOS and IOS and the only time I use this is when i have a single controller (not SSO and not N+1) where I may have ap's on both controllers, also when clients only gets put on a single subnet. I just tested this just now since I'm using iPSK and placing endpoint devices on specific vlans and P2P doesn't block.
10-16-2023 11:50 PM
This is one of those classic features that is completely misunderstood. Also from me for years due to inadequate documentation and logic.
If we look into the client table of our Controllers, there are all the information for blocking client peers in the same WLAN Profile:
- IP Addresses
- SSIDs and so on.
So from WLC perspective Peer Drop is a WLAN FEATURE. And this is the quote from Config Guide 17.12.1:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-12/config-guide/b_wl_17_12_cg/peer-to-peer-client-support.html?bookSearch=true
"Peer-to-peer client support can be applied to individual WLANs, with each client inheriting the peer-to-peer blocking setting of the WLAN to which it is associated. The peer-to-Peer Client Support feature provides a granular control over how traffic is directed. For example, you can choose to have traffic bridged locally within a device, dropped by a device, or forwarded to the upstream VLAN."
--> So this is documented information is completly wrong. Scott mentioned it right. It is based on the VLAN, not the WLAN.
For example: If you have two SSIDs leading to the same VLAN and only Peer Drop is active on SSID 1, all clients are not able to communicate with each another in both SSIDs.
If you use one SSID with VLAN Grouping, and Peer Drop is active, only Clients in the same VLAN will be blocked. Clients in different VLANs can reach one another. So this is a Blocking Gambling because of Round Robin.
If one of the old hands falls away from the faith, don't worry about it. I felt the same way.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide