Configuring Client Isolation Allowlists
When Wireless Client Isolation is enabled
on a WLAN, all communication between clients and other local devices is blocked
at the
access point.
To prevent clients from communicating with other nodes, the access point drops all ARP packets from stations on the WLAN where client isolation is enabled and which are destined to IP addresses that are not part of a per-WLAN allowlist.
You can create exceptions to client isolation (for example, allowing access to a local printer) by creating client isolation allowlists.
Complete the following steps to configure a client isolation allowlist:
- Go to Wi-Fi Networks > Advanced Options > Others.
- Under Wireless Client Isolation, select both the options:
- Click Create Allowlist.
- Enter a name and a description (optional) for the allowlist.
- Auto Allowlist is enabled by Default, which allows the APs to auto-discover gateway devices and add them to the isolation allowlist.
- Under Rules, click Create New to create multiple device-specific rules for each device to be allowlisted. For each rule, enter the following:
- Click Save to save the rule you created.
- To change the order in which rules are implemented, select the order from the drop-down menu in the Order column. You can also edit or clone rules from the Action column. To delete a rule, select the check box next to the rule and click Delete.
- Click OK to save the allowlist.
