Skip to main content

L2 Isolation

Last updated: October 25, 2024

s
Written by shuochun su
Updated over 11 months ago

Layer 2 isolation prevents wireless clients from communicating with other devices under same SSID or the same VLAN. When enabled, clients can only access gateway of the network to get internet access and but any attempt of communication directly between devices will be blocked. This is an easy security function especially for guest networks that difficult to manage client behaviors.

Note: Wired clients of on VIP can still be accessed.

Bridge Mode

L2 isolation is available for SSIDs in Bridge mode but is disabled by default. When an SSID operates in Bridge mode, clients are bridged through the Access Point, possibly onto a specific VLAN. Upon connecting to the AP, clients can issue a DHCP request on their assigned VLAN. After DHCP completes, the MAC address of the default gateway is tracked for that client.

This MAC address is then allowed through a Layer 2 firewall, which blocks all other traffic to and from the wireless client. Since this feature depends on DHCP, clients with static IPs connected to an SSID with L2 isolation enabled won't be able to transmit meaningful traffic.

L2 isolation is disabled

Wireless clients and wired clients can communicate with each other.

L2 isolation is enabled

With L2 isolation enabled, clients can only communicate with the default gateway and are blocked from communicating with other devices on the same VLAN or broadcast domain. For a wireless client to reach another device, communication must go through the upstream gateway (e.g., using inter-VLAN routing or ACLs). Any traffic destined for an address on the same VLAN as an isolated client will be denied, while traffic to other VLANs will be forwarded and routed as usual.

NAT Mode

L2 isolation is disabled

NAT mode supports basic L2 isolation, where wireless clients cannot communicate with each other but can still communicate with the AP uplink.

L2 isolation is enabled

When L2 isolation is enabled, it blocks wireless clients from communicating with any devices on the network, except for the gateway.

How to Configurate

Navigate to Configure > Access Point > SSID List > Wireless > Advanced Settings

This configuration option is disabled by default but can be enabled on a per SSID basis.

Did this answer your question?