Stations are connected to different SSIDs with NAT mode enabled, but are able to discover each other

Options
Zyxel_JoyLee
Zyxel_JoyLee Posts: 154 image  Zyxel Employee
Friend Collector First Anniversary

The NAT mode of an SSID is used to assign IP addresses to devices when there is no gateway or router in the environment to provide DHCP service. However, it is not a true Layer 3 isolation mechanism and cannot fully isolate devices from each other.

To prevent devices on different NAT-mode SSIDs from communicating with each other, enable the Guest Network function. This will automatically create firewall rules to isolate wireless clients.

  1. Go to Site-wide > Configure > Access points > SSID settings and enable “Guest Network"
image.png

2. Go to Site-wide > Configure > Access points > SSID advanced settings and the firewall rule is enabled

image.png