Layer-2 isolation and subnet problem
Hello,
I'm trying to setup a guest wifi with layer-2 isolation on a WAC6103D-I but i can't get it working properly.
I have added mac adresses of "VPN GW" and "Internet GW" in my Layer-2 Isolation profile but it still allows users to browse web servers on the main site and internet sites.
If i remove VPN GW from my list, i can't connect to anything.
I have successfully configured another AP with a guest wifi and Layer2-Isolation on my main site without trouble.
What can i do to really isolate users on my guest Wifi?
Thanks!?
All Replies
-
Hi @Y_L
Welcome to ZYXEL community.
Layer-2-isolation is used to block same subnet client can’t communicate with each other. If a device’s MAC addresses is NOT listed in a layer-2 isolation profile, it is blocked from communicating with other devices in an SSID on which layer-2 isolation is enabled.
Since you added the mac addresses of "VPN GW" and "Internet GW" in Layer-2 Isolation profile, it means that these two devices are allowed to be accessed by other devices in the SSID to which the layer-2 isolation profile is applied. So, the Guest Wifi clients can access the internet and intranet.
If you want to isolate Guest Wifi in the office, just create a Layer-2-isolation profile without any whitelists.
Hope it helps.
Joslyn.
0 -
I think that the answer is here: "same subnet".
It's not my case, so in this configuration i can't use Layer-2 Isolation.
The goal is to isolate my "guest wifi" users from everything. I just want them to access internet through the "Internet GW" located in my main site.
I'll have a look to my firewall config.
Thank your very much for your help! ?️
Yann
0
Categories
- All Categories
- 414 Beta Program
- 2.2K Nebula
- 131 Nebula Ideas
- 91 Nebula Status and Incidents
- 5.4K Security
- 175 USG FLEX H Series
- 256 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1K Wireless
- 36 Wireless Ideas
- 6.2K Consumer Product
- 235 Service & License
- 372 News and Release
- 79 Security Advisories
- 24 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 81 About Community
- 69 Security Highlight