How to block client to client forwarding between caps?

In the capsman configuration setting,all the cap interface will add to same bridge and not allow client to client forwarding by default. I try two client under the same cap, it work, but client between caps still can ping. In this case if I have lots of hap,client under one of the cap send any broadcasting packet will reach every caps. I going to set up a network with about 500 caps.
Is there any setting I can set to prevent this happend? Thanks !

datapath.bridge-horizon?

what is it for ? :open_mouth:

in a bridge, ports will communicate between them only if no bridge horizon value is set, or if is different. By setting all ports to the same horizon value (but the “master”, or “local” port) you’ll isolate them, and only communication between any port <==> master port will happen.

Thanks for you help ! :smiley: :smiley:

Interesting, will this be on a college or university campus?

Yes, you are right~ Is someone do this before?

We haven´t done this with MikroTik, yet. Also we haven´t reached 500 access points. For new installations I´d like to go with MikroTik and someday replace every old access point with MikroTik based devices.

Nowadays, I´d take

  • for the wifi controller part: Mikrotik CHR P-Unlimited license running von VMWare
  • for indoor access point: MikroTik HAP AC + RF Elements StationBox® InSpot + MikroTik Gigabit PoE adapter (RBGPOE)
  • outdoor: NetMetal 5

I´m still waiting for my first HAP AC devices to throw into some lecture halls…