RUCKUS Community Forums are now in READ-ONLY mode while we migrate to a new platform.
You will still be able to read posts and knowledge articles, but will be unable to post new content until Go Live on the new platform Monday August 17.
Lennar Smart Home customers: please contact [email protected] for assistance during the week of August 9-17.
09-09-2022 08:14 AM
So we use DPSK a lot in our various types of networks. However, often every group is assigned it's own vlan and users can connect with their own devices. However, we would like to implement a Guest-network where they are only allowed to communicate with the gateway.
When I try to enforce such a rule via the L3 firewall rule I end up without any connection at all or I can still ping other clients on the network. Question: is it possible to perform such a network or is it better to create a separate guest-network with it's own SSID?
09-09-2022 08:48 AM
Hello @Wouter,
Creating L3 ACLs for default gateway would we invalid. You would need to enable Client-Isolation in WLANs and create client isolation whitelist, so that you can limit the client communication on same subnet.
Regards,
Parik
09-13-2022 12:41 AM
Hi Parik, thanks for your reply.
The thing is we would like to have a single SSID for multiple purposes. If we enable client isolation I assume it would affect the users with DPSK-keys as well while we would like to have a personal environment for users with keys and guests can use a different key with limited access. If this is impossible or bad practice, maybe it's a nice feature request to define some of the WLAN specific aspects to a dpsk key such as client isolation or guest portal. (after all, client isolation should be just a firewall rule).
