cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1558
Views
16
Helpful
5
Replies

How to disable wireless client communication from AP FlexConnect

Ethan and Mia
Level 1
Level 1

Hi Master

I looking solution for disable wireless client communication(client to client) i try to action "drop" P2P Blocking on WLAN  butt still not working ,   Is there anyway to block communication from WLC ,  All APs on FlexConnection mode 

 

thank you

5 Replies 5

Restrictions on Peer-to-Peer Blocking

• Peer-to-peer blocking does not apply to multicast traffic.

• In FlexConnect, solution peer-to-peer blocking configuration cannot be applied only to a particular FlexConnect AP or a subset of APs. It is applied to all FlexConnect APs that broadcast the SSID.

• Cisco controller with central switching clients supports peer-to-peer upstream-forward. However, this is not supported in the FlexConnect solution. This is treated as peer-to-peer drop and client packets are dropped.

• Cisco controller with central switching clients supports peer-to-peer blocking for clients associated with different APs. However, this solution targets only clients

connected to the same AP. FlexConnect ACLs can be used as a workaround for this limitation

 

Besides flexconnect ACL, you can also apply ACL to the interface vlan on the layer3 device.

 Actually, ACL will be necessary when client belong to different vlans. When client belong to different vlan, the controller will hand off the traffic to the laser 3 device and will not Block P2P, even in local mode.

If few user 
you can use Mac ACL in SW that FLEX is connect.

Rich R
VIP
VIP

It depends on your network topology and requirements but you may need to use a combination of P2P blocking, ACLs and "switchport protected" on your switch ports.

Hello , rrudling

I never use port protected . Is it should on the port connected to APs right ? and from uplink switch to switch should have it?

 

 

Thank for your reply 

Rich R
VIP
VIP

On AP ports yes - to stop clients on 1 AP talking to clients on another AP but not the uplink port otherwise the AP and clients will be blocked from connectivity to the WLC and internet.

Review Cisco Networking for a $25 gift card