Enable Client Isolation on Bridge-to-LAN/VLAN SSIDs
Currently, you can select this, but it only applies between wireless clients on the same AP. Check out CClasen's insightful design suggestion on the User BB: https://www.astaro.org/other-products/wireless-security/55448-client-isolation-2.html#post285163
Renzo Patricio Carpio commented
In case this has not been implemented, I think the best way to get this is to allow isolated devices to communicate with only one MAC address (the UTM by default but with the option to set it up manually in case the APs are behind a L3 switch.
Ryan DeBok commented
This would be a nice feature... a simple way to keep guests from scanning the network for other devices on their network.