Configuring Client Isolation Allowlists

When Wireless Client Isolation is enabled on a WLAN, all communication between clients and other local devices is blocked at the access point.

To prevent clients from communicating with other nodes, the access point drops all ARP packets from stations on the WLAN where client isolation is enabled and which are destined to IP addresses that are not part of a per-WLAN allowlist.

You can create exceptions to client isolation (for example, allowing access to a local printer) by creating client isolation allowlists.

Complete the following steps to configure a client isolation allowlist:

  1. Go to Wi-Fi Networks > Advanced Options > Others.
  2. Under Wireless Client Isolation, select both the options:
    • Isolate wireless client traffic from other clients on the same AP
    • Isolate wireless client traffic from all hosts on the same VLAN/subnet
  3. Click Create Allowlist.
  4. Enter a name and a description (optional) for the allowlist.
  5. Auto Allowlist is enabled by Default, which allows the APs to auto-discover gateway devices and add them to the isolation allowlist.
  6. Under Rules, click Create New to create multiple device-specific rules for each device to be allowlisted. For each rule, enter the following:
    • Description: Description of the device.
    • MAC Address: Enter the MAC address of the device.
    • IPv4 Address: Enter the IP address of the device.
  7. Click Save to save the rule you created.
  8. To change the order in which rules are implemented, select the order from the drop-down menu in the Order column. You can also edit or clone rules from the Action column. To delete a rule, select the check box next to the rule and click Delete.
  9. Click OK to save the allowlist.

    Creating a Client Isolation Allowlist