Ah, thanks, I think I see now. You put these L3 rules only on the ports connected to APs. The wireless clients can use the MACs of the wired devices and so use L2 to reach them, unaffected by the L3 limitations in the switch port connected to the AP.
So, Client Isolation for bridge-to-LAN/VLAN SSID's would be possible by adding the MACs of the other APs to the "blacklist" in each AP (assuming that's the technique in use)? I think you have a Feature suggestion there!
Ah, thanks, I think I see now. You put these L3 rules only on the ports connected to APs. The wireless clients can use the MACs of the wired devices and so use L2 to reach them, unaffected by the L3 limitations in the switch port connected to the AP.
So, Client Isolation for bridge-to-LAN/VLAN SSID's would be possible by adding the MACs of the other APs to the "blacklist" in each AP (assuming that's the technique in use)? I think you have a Feature suggestion there!