Is Guest Protect 'Block Lan Access' on Incontrol2?

Hi Is Guest protect called ‘block Lan Access’ within incontrol2?

with layer2 isolation ticked and block Lan access will i not expect to see layer 2 mac addresses if I do a scan?

I do see broadcasts from other connected wifi clients (same ssid) with layer 2 isolation.

Are you connected as wired or wireless?

1 Like

Wireless. I understand that there is another option to isolate to wired clients.

Is there an option to achieve this with Ac mini managed by incontrol2?

is there an option to enforce dhcp too?

thanks,

evan

Can you share what type of broadcast traffic you saw?

1 Like

I just did some more testing. On a SSID without layer 2 isolation I can see mac addresses and can ping each client connected.
When I test on my secured vlan I don’t see anything. Using wireshark. So it looks pretty good to me.
Any other tests you can think of to confirm that true layer 2 isolation is working? I’m looking into this due to an experience where a customer using two Aruba 200 series ap’s without a lan controller and the isolation is not secure enough.

Also any option to ensure a client can only connect on the network if it has received a dhcp address from the configured system? I’m using dhcp from my router, not the peplink ac mini

ta

As long as inter-access is failed between the Wifi clients then will be fine. You can further check with Wireshark. Please ensure the clients are connected to the same AP and same SSID. when you do the testing.

1 Like

I do not understand why the label of this checkbox is still not aligned, yet.
@TK_Liew : It‘s 7 years later now…


Oh~~ Good catch. I informed IC2 team and they will change it according. Thanks!