<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Client isolation?]]></title><description><![CDATA[<p dir="auto">not 100% related to pfsense but i'm sure somebody on here will know.<br />
my friend has a 50 bedroom hotel and wants to provided wired access to each room so client isolation comes into the equation.<br />
easy with wireless but wired? first thought is to put every room on a seperate vlan but 50 vlans (1 per room?)<br />
anybody come across this before? we are looking at 3 x 24 port zyxel managed switches to a pfsense firewall.</p>
<p dir="auto">regards,<br />
louis</p>
]]></description><link>https://forum.netgate.com/topic/20673/client-isolation</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 22:32:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/20673.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 14 Jan 2010 08:30:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Client isolation? on Fri, 12 Mar 2010 00:52:46 GMT]]></title><description><![CDATA[<p dir="auto">johnjces:<br />
Some access points have a feature you can enable to do that and pfSense also has a simple checkbox to do it when it acts as the access point (with a wireless network card supporting access point mode in FreeBSD).  Any further discussion of this should probably go in a different thread.</p>
]]></description><link>https://forum.netgate.com/post/225873</link><guid isPermaLink="true">https://forum.netgate.com/post/225873</guid><dc:creator><![CDATA[Efonnes]]></dc:creator><pubDate>Fri, 12 Mar 2010 00:52:46 GMT</pubDate></item><item><title><![CDATA[Reply to Client isolation? on Thu, 11 Mar 2010 22:35:44 GMT]]></title><description><![CDATA[<p dir="auto">Quick question… as I am pretyt stupid when it comes to this, but...</p>
<blockquote>
<p dir="auto">so client isolation comes into the equation. easy with wireless</p>
</blockquote>
<p dir="auto">Can this be done with pfSense and wireless Access Points? If so, how? Or wherfe to search. I've Googled but really never found anything.</p>
<p dir="auto">TIA!</p>
<p dir="auto">John</p>
]]></description><link>https://forum.netgate.com/post/225863</link><guid isPermaLink="true">https://forum.netgate.com/post/225863</guid><dc:creator><![CDATA[johnjces]]></dc:creator><pubDate>Thu, 11 Mar 2010 22:35:44 GMT</pubDate></item><item><title><![CDATA[Reply to Client isolation? on Tue, 19 Jan 2010 01:24:27 GMT]]></title><description><![CDATA[<p dir="auto">It depends on if the switch has the capability to filter layer 3 traffic like that. I don't have experience with the Zyxel switches so I'm not sure if they are capable of that.</p>
]]></description><link>https://forum.netgate.com/post/219966</link><guid isPermaLink="true">https://forum.netgate.com/post/219966</guid><dc:creator><![CDATA[blak111]]></dc:creator><pubDate>Tue, 19 Jan 2010 01:24:27 GMT</pubDate></item><item><title><![CDATA[Reply to Client isolation? on Fri, 15 Jan 2010 21:50:26 GMT]]></title><description><![CDATA[<p dir="auto">yeah i like the thought of that…...<br />
a primary vlan with secondary vlans within that can only communicate with the primary vlan. just wondering if an ACL would work on the port eg only allow anything on the port to communicate with IP of gateway.</p>
]]></description><link>https://forum.netgate.com/post/219682</link><guid isPermaLink="true">https://forum.netgate.com/post/219682</guid><dc:creator><![CDATA[louis-m]]></dc:creator><pubDate>Fri, 15 Jan 2010 21:50:26 GMT</pubDate></item><item><title><![CDATA[Reply to Client isolation? on Thu, 14 Jan 2010 21:15:31 GMT]]></title><description><![CDATA[<p dir="auto">There is also a feature on cisco switches called private VLANs and public VLANs.<br />
All of the members of the private VLAN (clients) can only communicate with the machines on a public VLAN (pfsense).<br />
It might be worth looking to see if the zyxel switches support it to avoid creating many separate VLANs.</p>
]]></description><link>https://forum.netgate.com/post/219573</link><guid isPermaLink="true">https://forum.netgate.com/post/219573</guid><dc:creator><![CDATA[blak111]]></dc:creator><pubDate>Thu, 14 Jan 2010 21:15:31 GMT</pubDate></item><item><title><![CDATA[Reply to Client isolation? on Thu, 14 Jan 2010 22:07:55 GMT]]></title><description><![CDATA[<p dir="auto">Yes i have done that before.<br />
We used it for a LAN party, so that everyone that comes the first time and isn't registered yet is in it's own VLAN.<br />
Additionally he's blocked from the internet by the captive portal, but all the "big" antivirus pages were on the passthrough IP list. (To update anti-virus definitions).<br />
After registration and check by a staff if his antivirus is up to date and a full-scan-log his port/MAC gets moved to the public VLAN.</p>
<p dir="auto">I dont think that you need anything from the pfSense for your scenario.<br />
So just rules on the switch.</p>
]]></description><link>https://forum.netgate.com/post/219480</link><guid isPermaLink="true">https://forum.netgate.com/post/219480</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Thu, 14 Jan 2010 22:07:55 GMT</pubDate></item></channel></rss>