wireless client isolation

Hi,

I have an RB1000 setup in a hotel running hotspot connected to a radius server for authentication.

My access points are all HP. Even though i have wireless client isolation on the HP, you are still able to search and scan the network.
Is there a forward filter rule i can use to block windows and mac’s from scanning and searching the network, but not blocking port 80 for internet traffic.

Thanks in advance

make firewall rules that block access from and to certain address ranges.