cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
5029
Views
5
Helpful
4
Replies

P2P Blocking Action behavior

mpitts
Level 1
Level 1

Hello!

I am looking to isolate client traffic for a certain WLAN. I want to deny traffic from clients on the same WLAN, across all APs.

Can anyone explain how p2p blocking action works? Are there any considerations? Please let me know if you need more information,

WLC2504 - FW version 7.6.120.0

Thanks!

4 Replies 4

Ric Beeching
Level 7
Level 7

Hey,

It is fairly straight forward when using centrally switched WLANs or with APs in local mode on the same WLC. If you apply P2P Blocking action of drop globally on your WLAN this will stop the APs/WLC forwarding packets between clients attached to all APs.

This does not apply to multicast traffic however.

Ric

-----------------------------
Please rate helpful / correct posts

Thanks Ric!

What if I have APs in flexconnect with local switching?

I am hearing conflicting information.

I appreciate you answering my questions!

No probs,

For your version of software it appears that P2P blocking is supported on locally switched WLANs:

Peer-to-peer blocking is supported for clients that are associated with the local switching WLAN.

http://www.cisco.com/c/en/us/td/docs/wireless/controller/7-6/configuration-guide/b_cg76/b_cg76_chapter_01001100.html

Ric

-----------------------------
Please rate helpful / correct posts

Sadly the documentation regarding P2P blocking with local switching (FlexConnect) is incomplete if you ask me.

What really happens when you enable this feature is that "bridge-group x port-protected" is being enabled on the dot11 radio (sub) interfaces. This feature should* prevent traffic between two wireless connected end-points on the same access-point. There is no "distribution system" by which the other access-points are being informed about other guest clients. This means that you need to implement something like private VLANs on the wired side as well.

*: does not seem to work with latest 8.3 AirOS code, even if both clients are connected on the same radio of the access-point.

Review Cisco Networking products for a $25 gift card