Layer 2 Isolation

Options
nielsscheldeman
nielsscheldeman Posts: 76 image  Ally Member
First Comment Friend Collector Third Anniversary
edited March 2024 in Nebula

Hello,

Normally for Wireless I'd like to use Layer2 Isolation with only access to gateway and fileserver. However, I'm now at a client where we temporarily need to share a printer through a wireless computer with other wireless computers. So I entered both MAC Addresses in Layer 2 Isolation (Nebula), but still they can't ping eachother.

This is strange I think? Both wireless cliënts are connected to same AP. (9 AP's total, but they are in same room, so Intra-BSS Traffic blocking counts too)

All Replies

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,317 image  Guru Member
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula

    Hi @nielsscheldeman ,

    Based on your description, it appears that the problem as the printer and the PC are unable to ping each other when they are connected to the same SSID with the Layer 2 isolation feature enabled and the same AP.

    Could you please verify if the MAC addresses for the gateway, printer, and PC have been correctly entered into the Layer 2 isolation feature's whitelist?

    image.png


    Also, ensure that the AP's configuration is Up to date before the time of conducting the ping tests.

    image.png

    Furthermore, I'd like to share that we conducted a simple replication of the scenario here and were able to achieve successful ping responses between two wireless clients.

    If you've followed the above recommendation and the issue persists, please enable Zyxel support.

    Additionally, please provide us with the name of your Nebula organization/site here or via the private message by clinking to my account > Message.

    Zyxel_Judy

    Untitled Image
  • nielsscheldeman
    nielsscheldeman Posts: 76 image  Ally Member
    First Comment Friend Collector Third Anniversary

    Hello, yes both MAC Addresses were added(was a USB Printer connected to a wireless computer and another wireless computer needs to be able to print). It was on an existing Layer 2 isolation list that I added the MAC Addresses.

    I'll set up a test environment in our own office to test this too. Thanks for the testing so far!

  • nielsscheldeman
    nielsscheldeman Posts: 76 image  Ally Member
    First Comment Friend Collector Third Anniversary

    To continue on this, I'm not sure if what I want is possible, but I'll try. Another client with Guestwifi has now a music installation with wireless controller for that music. I added MAC Address from that wireless controller to Layer 2 isolation, but it was still not visible for other wireless cliënts until I turned off Layer 2 Isolation. Is that because the wireless controller can't return traffic to the wireless cliënts because they aren't listed in L2 Isolation(just smartphones, so not ideal to put them all in that list)

Nebula Tips & Tricks