<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking multicast and inter-station broken? in ExtremeWireless (IQE)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-iqe/blocking-multicast-and-inter-station-broken/m-p/118628#M1802</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to use the built in options in CloudIQ as well as the IP Firewall on user profiles to block multicast traffic like mDNS.&lt;/P&gt;&lt;P&gt;I have ticked "E&lt;SPAN class=""&gt;nable Multicast Drop" and unticked "Except for the following protocols: mDNS". I have also unticked "Enable Inter-station Traffic". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I have also added following Outbound IPFW rules with a Deny action:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Source: Any - Destination: Any - Service/Application mDNS (I have tried both the predefined Extreme mDNS application as well as my own manually defined service)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Source: Any - Destination: 224.0.0.0/4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Despite this I still see mDNS traffic originating from one client on the wireless to another. They are on the same Network Policy, same SSID, same HIVE, different APs. I am verifying by Wireshark capture that I still mDNS between the two clients. When inspecting the traffic, I see the IPv4 headers of the mDNS traffic match what I have configured in the IPFW rules, yet the traffic still goes between clients.&lt;/P&gt;&lt;P&gt;I have logged this with GTAC and demonstrated the issue and they have been unable to provide an explanation.&lt;/P&gt;&lt;P&gt;Are the options to block mDNS and other multicast traffic and the manual IPFW rules for CloudIQ APs just completely broken? I see the same issue with inter-station traffic that the APs seem incapable of blocking client to client communication, even if I add the manual IPFW for inter-station deny.&lt;/P&gt;&lt;P&gt;Other firewall rules such as blocking RFC1918 address ranges work ok.&lt;/P&gt;&lt;P&gt;We are running AP4000 on 10.7.5.0. Any ideas?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Apr 2025 23:29:31 GMT</pubDate>
    <dc:creator>FABRIC_2_EDGE</dc:creator>
    <dc:date>2025-04-24T23:29:31Z</dc:date>
    <item>
      <title>Blocking multicast and inter-station broken?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-iqe/blocking-multicast-and-inter-station-broken/m-p/118628#M1802</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to use the built in options in CloudIQ as well as the IP Firewall on user profiles to block multicast traffic like mDNS.&lt;/P&gt;&lt;P&gt;I have ticked "E&lt;SPAN class=""&gt;nable Multicast Drop" and unticked "Except for the following protocols: mDNS". I have also unticked "Enable Inter-station Traffic". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I have also added following Outbound IPFW rules with a Deny action:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Source: Any - Destination: Any - Service/Application mDNS (I have tried both the predefined Extreme mDNS application as well as my own manually defined service)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Source: Any - Destination: 224.0.0.0/4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Despite this I still see mDNS traffic originating from one client on the wireless to another. They are on the same Network Policy, same SSID, same HIVE, different APs. I am verifying by Wireshark capture that I still mDNS between the two clients. When inspecting the traffic, I see the IPv4 headers of the mDNS traffic match what I have configured in the IPFW rules, yet the traffic still goes between clients.&lt;/P&gt;&lt;P&gt;I have logged this with GTAC and demonstrated the issue and they have been unable to provide an explanation.&lt;/P&gt;&lt;P&gt;Are the options to block mDNS and other multicast traffic and the manual IPFW rules for CloudIQ APs just completely broken? I see the same issue with inter-station traffic that the APs seem incapable of blocking client to client communication, even if I add the manual IPFW for inter-station deny.&lt;/P&gt;&lt;P&gt;Other firewall rules such as blocking RFC1918 address ranges work ok.&lt;/P&gt;&lt;P&gt;We are running AP4000 on 10.7.5.0. Any ideas?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Apr 2025 23:29:31 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-iqe/blocking-multicast-and-inter-station-broken/m-p/118628#M1802</guid>
      <dc:creator>FABRIC_2_EDGE</dc:creator>
      <dc:date>2025-04-24T23:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking multicast and inter-station broken?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-iqe/blocking-multicast-and-inter-station-broken/m-p/121106#M1925</link>
      <description>&lt;P&gt;Ever get anywhere with this? Seeing the same issues on 10.8.5.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 20:32:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-iqe/blocking-multicast-and-inter-station-broken/m-p/121106#M1925</guid>
      <dc:creator>msmith0518</dc:creator>
      <dc:date>2026-01-16T20:32:21Z</dc:date>
    </item>
  </channel>
</rss>

