Multicast and Broadcast Filtering - Which Network?
I have a ton of IoT devices on their own Network/VLAN. I am a little confused by the description in the option for "Multicast and Broadcast Filtering". My trusted devices are on my regular LAN network.
Am I filtering on my main LAN network and only allowing (through the exception list) through what I want...or am I supposed to be filtering ON the VLAN Network? Sorry to ask, but unfortunately, this feature happens within the ATHx interface and TCPDUMP isn't really any help to triage
If I watch Wireshark for multicast on a laptop in the "trusted" LAN, I basically see all multicast die when filtering is enabled (which is obviously expected)...however, even devices that I add to the exception list are still getting blocked.
FWIW, I have the USG + 60Watt Switch + 3 Unifi NANOHDs
EDIT: The Unifi controller picks the wrong MAC address for the exception list for the USG - ssh into your USG, type in `ip addr` and grab the mac address for ETH1
Comments Section
"Multicast and Broadcast Filtering" only filters in the LAN to WLAN direction. That is, it blocks broadcasts from being transmitted by the AP. It has no effect on broadcasts transmitted by a Wi-Fi device; the AP will forward it to the LAN. Since this setting is per SSID, it will only affect the associated VLAN, if one is enabled. Likewise, the exception list only applies to the SSID.