<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client Isolation and Bonjour Whitelists? in Access Points - Indoor and Outdoor</title>
    <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Client-Isolation-and-Bonjour-Whitelists/m-p/9667#M2179</link>
    <description>I would suggest creating a hidden wlan+ssid (possibly called "Apple-TV" or "bonjour" or "horrible-name-service") that does not have "clients on the same AP" isolation configured.&lt;BR /&gt;Then you can configure your Apple TV to associate w/ the hidden SSID.&lt;BR /&gt;&lt;BR /&gt;It's not a seamless or end-user transparent solution but it should work.&lt;BR /&gt;&lt;BR /&gt;AFAIK: the "whitelist" feature that exists for un-isolating "hosts on the same VLAN" does not apply to "clients on the same AP".&lt;BR /&gt;..which is unfortunate, but at least there's some kind of workaround for you.&lt;BR /&gt;&lt;BR /&gt;Alternatively, you could create a new "WLAN" w/ the same (not hidden) SSID that you use on your other APs.&lt;BR /&gt;That way, clients that associate w/ that one AP will be able to see each other but clients that associate to some other AP still won't be able to see each other.&lt;BR /&gt;&lt;BR /&gt;(the benefit to using the same ssid is that clients could still roam seamlessly between this AP and other APs)&lt;BR /&gt;&lt;BR /&gt;If you think you're getting a security win by using the local isolation feature, you're "only" losing that feature for clients on the one AP w/ the Apple TV on it.&lt;BR /&gt;if you're not also using "hosts on the same VLAN" isolation, you're not getting much of a security benefit anyway, unless you've only got one AP per VLAN/subnet.&lt;BR /&gt;&lt;BR /&gt;..and if you *do* use "hosts on the same VLAN" isolation, you had better configure your whitelist to allow communication to your wifi default gateway otherwise you'll break all your wifi connectivity.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Of course, the bonjour problem you're describing is the "simple" one.&lt;BR /&gt;If what you really want is to get bonjour/Apple-TV, etc. working *across* subnets, then things just got way more complicated.</description>
    <pubDate>Wed, 25 Nov 2015 20:53:57 GMT</pubDate>
    <dc:creator>bill_burns_6069</dc:creator>
    <dc:date>2015-11-25T20:53:57Z</dc:date>
    <item>
      <title>Client Isolation and Bonjour Whitelists?</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Client-Isolation-and-Bonjour-Whitelists/m-p/9666#M2178</link>
      <description>Is it possible to restrict clients to see all other clients on the WLAN but still allow an Apple TV or Chromecast by exception rule?</description>
      <pubDate>Wed, 25 Nov 2015 01:47:08 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Client-Isolation-and-Bonjour-Whitelists/m-p/9666#M2178</guid>
      <dc:creator>timothy_kamps</dc:creator>
      <dc:date>2015-11-25T01:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Client Isolation and Bonjour Whitelists?</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Client-Isolation-and-Bonjour-Whitelists/m-p/9667#M2179</link>
      <description>I would suggest creating a hidden wlan+ssid (possibly called "Apple-TV" or "bonjour" or "horrible-name-service") that does not have "clients on the same AP" isolation configured.&lt;BR /&gt;Then you can configure your Apple TV to associate w/ the hidden SSID.&lt;BR /&gt;&lt;BR /&gt;It's not a seamless or end-user transparent solution but it should work.&lt;BR /&gt;&lt;BR /&gt;AFAIK: the "whitelist" feature that exists for un-isolating "hosts on the same VLAN" does not apply to "clients on the same AP".&lt;BR /&gt;..which is unfortunate, but at least there's some kind of workaround for you.&lt;BR /&gt;&lt;BR /&gt;Alternatively, you could create a new "WLAN" w/ the same (not hidden) SSID that you use on your other APs.&lt;BR /&gt;That way, clients that associate w/ that one AP will be able to see each other but clients that associate to some other AP still won't be able to see each other.&lt;BR /&gt;&lt;BR /&gt;(the benefit to using the same ssid is that clients could still roam seamlessly between this AP and other APs)&lt;BR /&gt;&lt;BR /&gt;If you think you're getting a security win by using the local isolation feature, you're "only" losing that feature for clients on the one AP w/ the Apple TV on it.&lt;BR /&gt;if you're not also using "hosts on the same VLAN" isolation, you're not getting much of a security benefit anyway, unless you've only got one AP per VLAN/subnet.&lt;BR /&gt;&lt;BR /&gt;..and if you *do* use "hosts on the same VLAN" isolation, you had better configure your whitelist to allow communication to your wifi default gateway otherwise you'll break all your wifi connectivity.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Of course, the bonjour problem you're describing is the "simple" one.&lt;BR /&gt;If what you really want is to get bonjour/Apple-TV, etc. working *across* subnets, then things just got way more complicated.</description>
      <pubDate>Wed, 25 Nov 2015 20:53:57 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/Client-Isolation-and-Bonjour-Whitelists/m-p/9667#M2179</guid>
      <dc:creator>bill_burns_6069</dc:creator>
      <dc:date>2015-11-25T20:53:57Z</dc:date>
    </item>
  </channel>
</rss>

