Why isolate WiFi clients?

Because on an open network, or even one shared with guests, the person at the next table is just a step away from your smartphone: file sharing, printers, services left open. With isolation enabled, the access point does not forward traffic from one wireless client to another: each client sees only the router and the internet.

How to enable it with the wifi package in RouterOS 7?

The wifi package collects settings into reusable profiles. The one we are interested in is in the datapath:

/interface wifi datapath add name=dp-ospiti bridge=bridge-ospiti client-isolation=yes
/interface wifi configuration add name=cfg-ospiti ssid="Ospiti" mode=ap \
    datapath=dp-ospiti security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="cambiami"
/interface wifi set [find default-name=wifi1] configuration=cfg-ospiti disabled=no

The same configuration is used with the CAPsMAN in the wifi package: you assign cfg-ospiti to the access points via provisioning rules, and all APs that receive it isolate their clients.

/interface wifi capsman set enabled=yes interfaces=bridge-ospiti
/interface wifi provisioning add action=create-dynamic-enabled master-configuration=cfg-ospiti \
    supported-bands=2ghz-ax,2ghz-n,5ghz-ax,5ghz-ac

What about the old wireless package?

On devices still using wireless, isolation on a single access point is achieved by removing default forwarding from the interface:

/interface wireless set [find default-name=wlan1] default-forwarding=no

With the “legacy” CAPsMAN (v1, menu /caps-man), it was the datapath, as in the original 2015 article:

/caps-man datapath set [find name=datapath1] client-to-client-forwarding=no

Does isolation apply between different access points?

This is the point where people most often make mistakes. client-isolation prevents traffic between clients on the same access point. If the APs forward traffic locally within their bridge (local forwarding), two clients on two different APs can still see each other via the wired network.

To close that path as well, there are two options:

  • route all guest traffic through the central router, in a dedicated VLAN, and filter it there;
  • use the bridge horizon on the ports facing the APs: ports with the same horizon value do not exchange traffic.
    /interface bridge port set [find interface=ether2] horizon=1
    /interface bridge port set [find interface=ether3] horizon=1

With horizon=1 on both, what comes in from ether2 does not go out from ether3 and vice versa: the access points only talk to the router.

How do I verify it works?

With two smartphones on the guest network: from one, try pinging the other’s address (you can read it in the DHCP leases). With isolation enabled, the ping will not respond, while browsing works.

/ip dhcp-server lease print where server=dhcp-ospiti
/interface wifi registration-table print

Frequently asked questions

Where do you enable client isolation in RouterOS 7?

With the wifi package, it is enabled in the datapath, with client-isolation=yes, and the datapath is assigned to the interface configuration or CAPsMAN.

Does client isolation block internet access?

No. Client isolation only prevents direct traffic between wireless clients; traffic towards the router and therefore towards the internet passes normally.

Are two clients on different access points isolated?

Not necessarily. Client isolation acts on the single access point; to isolate clients connected to different APs as well, you need a dedicated VLAN filtered by the router or the bridge horizon on the ports facing the APs.

What did client-to-client-forwarding do?

It was the datapath option in the legacy CAPsMAN of RouterOS 6 (menu /caps-man): set to no, it prevented clients on the same access point from communicating with each other.

This howto updates a 2015 article from my old blog wirelessguru.it, now offline, to RouterOS 7.