Configuring Client Isolation Allowlists

When Wireless Client Isolation is enabled on a WLAN, all communication between clients and other local devices is blocked at the access point.

To prevent clients from communicating with other nodes, the access point drops all ARP packets from stations on the WLAN where client isolation is enabled and which are destined to IP addresses that are not part of a per-WLAN allowlist.

You can create exceptions to client isolation (for example, allowing access to a local printer) by creating client isolation allowlists.

Complete the following steps to configure a client isolation allowlist:

  1. Unleashed
    From the main menu, select Wi-Fi > Wi-Fi Networks > Wi-Fi Networks List. Click Add to create a new custom WLAN.
  2. In the Create Wi-Fi Network page, go to the left navigation pane and click the Advanced Options tab.
  3. In the Advanced Options page, click the Others tab.
  4. Under Wireless Client Isolation, select both the options:
    • Isolate wireless client traffic from other clients on the same AP
    • Isolate wireless client traffic from all hosts on the same VLAN/subnet
  5. Click the plus sign (+) next to the allowlist arrow.
  6. Enter a name and a description (optional) for the allowlist.
  7. Select Auto Allowlist checkbox, which is enabled by Default.
  8. Under Rules, click Add Rule to create multiple device-specific rules for each device to be allowlisted. For each rule, enter the following:
    • Order: Select the rule priority from the drop-down list.
      Please write the content for Order.
    • Description: Enter the description of the device.
    • MAC Address: Enter the MAC address of the device.
    • IPv4 Address: Enter the IP address of the device.
  9. Click Add to add the rule you created.
  10. To change the order in which rules are implemented, select the order from the menu in the Order column. You can also edit or clone rules from the Action column. To delete a rule, select the checkbox next to the rule and click Delete.
    Review the content for Action and Delete as the image doesn't have those options.
  11. Click Add to save the allowlist.

    Creating a Client Isolation Allowlist