08-10-2018 08:54 AM
Not sure when this feature is visible through the Hivemanager GUI... can you elaborate a bit more on it, what exactly it is doing?
The last example from above is what we are currently using to mitigate Multicast (mDNS) traffic flooding our network. So I am wondering if "disabling Inter-SSID Flooding" would help, and if yes, what else would I have to configure?
Thanks,
carsten
Solved! Go to Solution.
08-10-2018 03:16 PM
To answer your questions-
Changes to the traffic flow
· How does it affect traffic within the same (B)SSID?
· Does this mean that IP Firewall rules (on the AP) can now be applied to Multicast traffic?
· Does this mean that Multicast traffic is not automatically sent as wireless broadcast traffic on the BSSID?
· I am explicitly looking for a matrix should how this is affecting Multicast traffic flow for the following configurations:
In general, multicast/broadcast issues are best dealt with via proper VLAN design. If you can provide more details on what issues you are running in to with multicast flooding and specifics on your topology, we might be able to help you. If you'd rather share these details with me directly, please feel free to email me at communityhelp@aerohive.com
08-13-2018 11:59 AM
Thanks a lot Sam! That indeed clarifies this setting and what it does.
And, as you already figured, it does not help me with the original issue: Multicast traffic generated by wireless Clients is being broadcasted to all clients on the same SSID (= same BSSID), even if the clients are on different VLANs (via PPSK groups).
This became a huge problem in some of our installations where 2 things happened in parallel:
While minimizig the amount of SSIDs in a network is usually a good thing, with the management traffic overhead being reduced, in some cases it proved to be counter-productive. In environments with > 500 clients we saw a significant increase of Multicast traffic flooded to all Wifi clients, even when using different VLANs. It went as far as Multicast traffic being more than 50% of all Wifi traffic. It took a while to understand this happens because Multicasts are sent as Wifi Broadcasts, which are sent to all clients connected on the the BSSID, which is L2 and thus independent from the VLAN any client is inside.
We tried to fix it by applying Firewall policies on the APs, but as they are L3, they are not gripping.
I am aware that this situation is known to Aerohive, and I am being told that better Multicast handling is in development. Which is good... but until then, we are looking for workarounds to mitigate this behaviour.
The only workaround(*) that seems to help is to identify as many "independent locations" (= no wifi roaming between them), and configure each location with its dedicated SSID object (= same SSID broadcast name, but DIFFERENT BSSID), AND (important) with a dedicated VLAN for each user group as well.
Example:
(*) Of course "disabling inter-station traffic" fixes the issue, too. But we cannot always do it, as sometimes access to Wifi devices on the same network is required (printers, Apple-TVs, Chromecasts, ...).
The reason for my original post here was to find out, if this configuration option might help me to find a different / additional workaround. It is obviously not, so I will go ahead with my original plan (as per example) and wait for the proper solution by Aerohive 😉
carsten
08-10-2018 03:16 PM
To answer your questions-
Changes to the traffic flow
· How does it affect traffic within the same (B)SSID?
· Does this mean that IP Firewall rules (on the AP) can now be applied to Multicast traffic?
· Does this mean that Multicast traffic is not automatically sent as wireless broadcast traffic on the BSSID?
· I am explicitly looking for a matrix should how this is affecting Multicast traffic flow for the following configurations:
In general, multicast/broadcast issues are best dealt with via proper VLAN design. If you can provide more details on what issues you are running in to with multicast flooding and specifics on your topology, we might be able to help you. If you'd rather share these details with me directly, please feel free to email me at communityhelp@aerohive.com