Hi all.
in my access points I have a bridge between: wlan+some dynamic wds and one eoip tunnel.
the users use station-pseudobridge or station wds.
I need to isolate each user from each other.
I cannot use horizon because wds users cannot have an horizon.
I know I must use bridge firewall.
Then the questions:
how heavy is for a 411AH cpu to enable bridge firewall in AP having 80 users and delivering 10Mbits ?
could someone share a simple bridge firewall rule to do this ?
RB433AH should be fine. Blocking broadcast from GW to clients is impossible. Blocking broadcast from clients it’s certainly doable by dropping all traffic except from client to your server(s). How many ethernet interfaces are your user computers communicating with (for DHCP, NTP, default GW etc)?
thanks.
I need to block broadcast from one user to another (i.e. dhcp).
broadcast must forward through eoip (pppoe)
users are connected to wlan, someone using wds
Glad it’s working. I cannot tell from your reply, so make sure that you filter at the AP (closest to the client), if you filter at the other end you’ll see traffic dropped but clients will still be able to communicate.