Is it possible to set Layer 2 isolation in AP?
Do connected clients not discover each other with software like Fing or Wifiman?
For other products it is possible to disable MAC forwarding, for Ruckus MAC whitelist, for Mikrotik disable default forwarding, or for Zyxel enable layer 2 isolation.
Its called Client isolation in the WLAN. Disable means that clients can learn each other, Enable means that clients can only see the default gateway, so no client to client communications in the Wifi network.
The guest vlan works perfectly, they only reach what I allow on the network, ping does not work between them.
But the discovery software (mobile app) Wifiman and Fing can see other clients on the network.
That is what you should expect. The way wifi works is that every client and AP need to see each other so that the contention mechanism works…otherwise, RF collisions would hurt capacity. But not being able to communicate between clients is expected.
If neighbor device discovery mechanism is either using Multicast or broadcast packets, yes you will still see the neighbors but you cannot pass any traffic between clients.
However, with client isolation enabled, do enable drop multicast and this will help reduce neighbour devices. Please follow steps below:
Now it works as I want, the discovery software shows that I am alone.
I analysed the traffic with the wire shark and disabling the broadcast packets solved the problem.
It works perfectly with the correct ACL rules.