Allow intra-BSS communication
Hello, can someone explain what this setting does?
When I disable "Allow intra-BSS communication" I can't connect between any two wireless clients, no matter what firewall rules I use.
If I enable "Allow intra-BSS communication" I can't filter between any two wireless clients, at all, and they can connect freely to each other.
Does that mean I can only have either a completely open AP (all AP clients are available for every other AP client) or completely isolated wireless clients?
This is kind of unexpected. It seems there should be something in between "allow all" and "allow nothing".
What you described is the expected behavior. Wireless client traffic does not flow back through pfSense in a way it can be filtered when the clients talk directly. It's the same as any other wired network in that regard.
If you want to filter between sets of clients, place them in different networks. Separate SSIDs on distinct VLANs for example.