Can I block peer-to-peer communication over WiFi?
-
You will need to use Firewalla AP7's to do that. This is a layer 2 problem, can't be solved with just a firewall (firewalla)
See https://firewalla.com/products/firewalla-ap7
This unit can do VqLAN, VLAN and Device isolation.
-
Device isolation still doesn't block devices on my guest WiFi from being able to see each other. They can still do a ping sweep and ping other devices, although ports (L4 and above) are blocked. Other products have the option to disable peer-to-peer on a WiFi network. Curious why Firewalla's AP7s do not.
-
Can you please let me know and confirm both the client doing the ping and the isolated client are both on the same network segment? Or they are on different segment? also confirm, you don't have any allow rules?
Device isolation under AP7, should block pings for sure.
Also, may I know how you are generating the ping? was this just a ping, or a broadcast ping?
-
okay, so I found something very interesting. When connected to my guest Wi-Fi with my device set to isolation mode, I do a network scan using the App Network Analyzer and I can see all of the other devices on the same guest WiFi. I can see all devices connected to the Guest Wi-Fi, but only one device comes back as pingable. It looked up the MAC address of that device and it turns out to be my Firewalla AP7. For some reason, the AP I connect to gets assigned an IP address in my Guest WiFi LAN that's pingable from devices on the Guest Wi-Fi. When I look at the list of devices in Firewalla, the IP address doesn't show up nor does it show being linked to the AP7. I was able to determine that it's the AP7 from the mac address found from the netstat -a command. I can ping that IP address from multiple devices. I did a full port scan (1-65535 and nothing answered, so I guess there's little risk. But it is interesting that the AP7s assign themselves an IP address on LAN and is pingable, but not visible within the Firewalla app. Even with isolation enabled, that IP address is pingable. I have 3 AP7s and when I move my device to a different AP7, a completely different IP shows up and is pingable, so it appears each AP7 gets an IP address from the pool and my device can ping only the one that it's connected to.
Please sign in to leave a comment.
Comments
7 comments