Re: [Ubnt_users] client isolation

2017-08-03 Thread Tim Densmore
I'm assuming you meant "share every subnet to every tower" here - I don't know what a setnet is if not.  This is a very attractive option if I can make it happen - currently we're looking at a more "traditional" option of subnet-per-POP. What kind of gear do you use

Re: [Ubnt_users] client isolation

2017-08-03 Thread Tim Densmore
So, I'm probably going to ask a few (several?) stupid questions on this list over the next couple of weeks.  We're working on redesigning a large portion of our network, and I want to make sure I'm thinking about things correctly.  I'm also trying to avoid having a

Re: [Ubnt_users] client isolation

2017-08-03 Thread J Portman
Residential class customers are directed to one of the many vpn sites that exist for just such occasions. Business class customers are pppoe with routing and it's a non issue. YMMV, JP On Thu, 3 Aug 2017 00:03:57 -0500, Adair Winter wrote > right. and 99.999% of internet users don't need to

Re: [Ubnt_users] client isolation

2017-08-03 Thread Shawn C. Peppers
You build vlan or vpn on the upstream router or switch. No brainer. Shawn C. Peppers Video Direct 866-680-8433 Toll Free http://www.video-direct.tv > On Aug 2, 2017, at 11:52 PM, Tim Densmore > wrote: > > So, how do you handle situations where you have two

Re: [Ubnt_users] client isolation

2017-08-02 Thread Josh Luthman
In case anyone else read it a few times and was confused :) Josh Luthman Office: 937-552-2340 Direct: 937-552-2343 1100 Wayne St Suite 1337 Troy, OH 45373 On Aug 3, 2017 12:54 AM, "Adair Winter" wrote: > Thanks? > > On Thu, Aug 3, 2017 at 12:52 AM, Josh Luthman

Re: [Ubnt_users] client isolation

2017-08-02 Thread Adair Winter
Thanks? On Thu, Aug 3, 2017 at 12:52 AM, Josh Luthman wrote: > Put not but > > Josh Luthman > Office: 937-552-2340 <(937)%20552-2340> > Direct: 937-552-2343 <(937)%20552-2343> > 1100 Wayne St > Suite 1337 > Troy, OH 45373 > > On Aug 2, 2017 11:56 PM, "Adair Winter"

Re: [Ubnt_users] client isolation

2017-08-02 Thread Josh Luthman
Put not but Josh Luthman Office: 937-552-2340 Direct: 937-552-2343 1100 Wayne St Suite 1337 Troy, OH 45373 On Aug 2, 2017 11:56 PM, "Adair Winter" wrote: In the rare event that has needed to happen. We just but the customers in different public subnets. so yes,

Re: [Ubnt_users] client isolation

2017-08-02 Thread Adair Winter
right. and 99.999% of internet users don't need to connect directly do each other. It's just not that big of a deal. Plus, I don't ever want customers to be able to pass traffic between each other at a point that I can't capture it. (read: CALEA). In our network, we have 11 public subnets (a

Re: [Ubnt_users] client isolation

2017-08-02 Thread Tim Densmore
My assumption is that with pppoe and host routing it wouldn't be an issue, but in a situation where one site would ARP for the other site, it wouldn't work out. On 08/02/2017 10:54 PM, Jeremy Austin wrote: I've often wondered about this —

Re: [Ubnt_users] client isolation

2017-08-02 Thread Jeremy Austin
On Wed, Aug 2, 2017 at 8:56 PM, Adair Winter wrote: > Never, there is always a solution. > The purist in me (yeah, somewhere down there) bridles at a manual solution, but the pragmatist accepts it. My advertising could read "99.99% of Internet reachability!" ;)

Re: [Ubnt_users] client isolation

2017-08-02 Thread Adair Winter
Never, there is always a solution. On Wed, Aug 2, 2017 at 11:54 PM, Jeremy Austin wrote: > I've often wondered about this — particularly when combined with DHCP and > public IPs. Are they just Sadly Out of Luck? > > On Wed, Aug 2, 2017 at 8:52 PM, Tim Densmore

Re: [Ubnt_users] client isolation

2017-08-02 Thread Adair Winter
In the rare event that has needed to happen. We just but the customers in different public subnets. so yes, they have to go to the core and back, it works. but it's mostly a non-issue. On Wed, Aug 2, 2017 at 11:52 PM, Tim Densmore < tdensm...@tarpit.cybermesa.com> wrote: > So, how do you handle

Re: [Ubnt_users] client isolation

2017-08-02 Thread Shawn C. Peppers
It stops traffic across the radio from station to station. Always turn it on. Shawn C. Peppers Video Direct 866-680-8433 Toll Free http://www.video-direct.tv > On Aug 2, 2017, at 7:44 PM, Jan Van Kort wrote: > > I was wondering the same thing earlier today. What

Re: [Ubnt_users] client isolation

2017-08-02 Thread Jan Van Kort
I was wondering the same thing earlier today. What is it for? On 07/27/2017 03:37 PM, Shawn C. Peppers wrote: This is why you need to switch to pppoe. This is why you dont bridge the customer CPE station. Client isolation will likely not fix this issue but try it and you should have it on

Re: [Ubnt_users] client isolation

2017-07-27 Thread CBB - Jay Fuller
Great idea Garth! Thanks - Original Message - From: G. Nicholas To: Ubiquiti Users Group Sent: Thursday, July 27, 2017 5:48 PM Subject: Re: [Ubnt_users] client isolation Jay, Sounds like you are running the radio in bridge mode? If so use the firewall on the client

Re: [Ubnt_users] client isolation

2017-07-27 Thread CBB - Jay Fuller
: lol. I almost said..never had to use that feature before not really sure how it will work but I was definitely curious. - Original Message - Subject: Re: [Ubnt_users] client isolation From: "CBB - Jay Fuller" <par...@cyberbroadband.net>

Re: [Ubnt_users] client isolation

2017-07-27 Thread CBB - Jay Fuller
programming in usernames and passwords - Original Message - From: Shawn C. Peppers To: Ubiquiti Users Group Sent: Thursday, July 27, 2017 5:37 PM Subject: Re: [Ubnt_users] client isolation This is why you need to switch to pppoe. This is why you dont bridge the customer CPE

Re: [Ubnt_users] client isolation

2017-07-27 Thread Josh Luthman
1100 Wayne St > Suite 1337 > Troy, OH 45373 > > On Jul 27, 2017 6:35 PM, "CBB - Jay Fuller" <par...@cyberbroadband.net> > wrote: > >> >> um, no, it won't ;) >> >> >> - Original Message - >> *From:* CBB - Jay Fuller <par...@cyberb

Re: [Ubnt_users] client isolation

2017-07-27 Thread Shawn C. Peppers
5 PM, "CBB - Jay Fuller" <par...@cyberbroadband.net> >> wrote: >> >> um, no, it won't ;) >> >> - Original Message - >> From: CBB - Jay Fuller >> To: Ubiquiti Users Group >> Sent: Thursday, July 27, 2017 5:18 PM >> S

Re: [Ubnt_users] client isolation

2017-07-27 Thread Josh Luthman
; wrote: > > um, no, it won't ;) > > > - Original Message - > *From:* CBB - Jay Fuller <par...@cyberbroadband.net> > *To:* Ubiquiti Users Group <ubnt_users@wispa.org> > *Sent:* Thursday, July 27, 2017 5:18 PM > *Subject:* [Ubnt_users] client isolation > &

Re: [Ubnt_users] client isolation

2017-07-27 Thread G. Nicholas
: [Ubnt_users] client isolation > > > Just found i have a business on a tower that has a tp link plugged in backwards. The invalid DHCP ranges are getting across the interface to other businesses on the same switch. If I enable "client isolation" on the access point will it pr

Re: [Ubnt_users] client isolation

2017-07-27 Thread Shawn C. Peppers
This is why you need to switch to pppoe. This is why you dont bridge the customer CPE station. Client isolation will likely not fix this issue but try it and you should have it on anyways. Shawn C. Peppers Video Direct 866-680-8433 Toll Free http://www.video-direct.tv > On Jul 27, 2017, at

Re: [Ubnt_users] client isolation

2017-07-27 Thread tyson
lol. I almost said..never had to use that feature before not really sure how it will work but I was definitely curious. - Original Message - Subject: Re: [Ubnt_users] client isolation From: "CBB - Jay Fuller" <par...@cyberbroadband.net> Date: 7/27/17 6:35

Re: [Ubnt_users] client isolation

2017-07-27 Thread CBB - Jay Fuller
um, no, it won't ;) - Original Message - From: CBB - Jay Fuller To: Ubiquiti Users Group Sent: Thursday, July 27, 2017 5:18 PM Subject: [Ubnt_users] client isolation Just found i have a business on a tower that has a tp link plugged in backwards. The invalid DHCP

[Ubnt_users] client isolation

2017-07-27 Thread CBB - Jay Fuller
Just found i have a business on a tower that has a tp link plugged in backwards. The invalid DHCP ranges are getting across the interface to other businesses on the same switch. If I enable "client isolation" on the access point will it prevent this until we can reach the business? There