nanog mailing list archives

Re: Big Temporary Networks


From: William Herrin <bill () herrin us>
Date: Sat, 22 Sep 2012 02:12:03 -0400

On Fri, Sep 21, 2012 at 10:42 PM, Masataka Ohta
<mohta () necom830 hpcl titech ac jp> wrote:
William Herrin wrote:
that's getting close to omnipresent even in the low end APs. With this
feature enabled, stations are not allowed to talk to each other over
the wlan; they can only talk to hosts on the wired side of the lan.
The DAD packets are simply never sent to the other stations.

You are saying to disable DAD, which is a violation of SLAAC.

We do that on some wired ethernets too. The Cisco configuration
command is "switchport protected." It helps control virus outbreaks if
machines designated clients can't talk to each other at layer 2,
regardless of how that annoys layer 3.

Does this bother you? Tough.

Regards,
Bill Herrin


-- 
William D. Herrin ................ herrin () dirtside com  bill () herrin us
3005 Crane Dr. ...................... Web: <http://bill.herrin.us/>
Falls Church, VA 22042-3004


Current thread: