Bonjour Fencing
While Bonjour Fencing is related to Bonjour Gateway, they are designed for different purposes. Bonjour Gateway bridges mDNS services across VLANs, and is useful because mDNS or Bonjour packets are restricted to the same VLAN or subnet and cannot be routed to other VLANs. Bonjour Fencing limits the range of Bonjour service discovery within a physical space, which is useful because logical network boundaries (for example, VLANs) do not always correlate well to physical boundaries within a building or floor.
The following considerations should be taken into account before deploying Bonjour Fencing policies:
- Bonjour Fencing is not supported on Mesh APs.
- Switch interfaces to which APs are connected must be configured in VLAN trunk mode so that Bonjour traffic gets forwarded across VLANs based on Bonjour Gateway policies.
- Bonjour Fencing is implemented at the AP, not at the controller.
- Fencing policies can be applied on a zone level only, and cannot be configured per AP group.
- For a wired fencing policy to work properly, wireless fencing for the same mDNS service must also be enabled. If wired fencing is enabled but wireless is disabled, APs that are not the "closest AP" will be unable to determine whether the source of the mDNS advertisement is wired or wireless.
- Bonjour Fencing works for local breakout scenarios, but does not work for tunnel-based configuration. (This feature is supported only for SZ300 controllers)