Skip to main content
tkanneganti
Staff
Staff
September 14, 2022

Techincal Tip: How 'Block intra-SSID traffic' option on SSID configuration works on bridge mode SSID on FortiGate/FortiAP

  • September 14, 2022
  • 0 replies
  • 12730 views

Description

This article describes an overview of how the 'Block intra-SSID traffic' option in the SSID configuration works on the bridge-mode SSID, as there is slight variation between tunneled and bridged modes.

Scope

FortiOS v7.x.

Solution

Tunneled mode:

  • Enabling Block intra-SSID traffic will restrict communication between 2 wireless clients connected on the same SSID on FortiAPs.

  • In tunneled mode, the traffic will be completely blocked between 2 wireless clients on the same SSID irrespective of the client associated with FortiAPs (same FortiAP or different FortiAP).


Bridge mode:

  • Traffic between two wireless clients will be blocked when associated with the same FortiAP.

  • The traffic will be allowed when wireless clients are associated to different FortiAP's (though connected to the same SSID).

  • Traffic coming to AP-1 through Ethernet from AP-2 associated wireless clients will be treated as wired traffic, hence will not be blocked.


In Simple Bridge mode, an SSID with the 'Block intra-SSID traffic' option enabled,

Wireless clients connected on the same SSID, Same FortiAP: communication blocked
Wireless clients connected on the same SSID, but different FortiAPs: communication allowed (traffic will be considered as wired traffic between clients connected on different FortiAP's. ).


This option in CLI is available as 'intra-vap-privacy' under VAP configuration. Example as below:

 

config wireless-controller vap
    edit test          
        set intra-vap-privacy
     next
end

 

Notes:

  • 'test' is the bridge SSID name/intra-vap-privacy: Enable/disable blocking communication between clients on the same SSID (called intra-SSID privacy, default = disable).

  • Starting with FortiOS v8.0, the intra-vap-privacy setting is no longer available for local-bridging VAPs (set local-bridging enable).

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!