MSM7xx Controllers Configuration Guide v6.4.0
Limitations
Bonjour features are not supported in the following cases:
• Roaming users that are making use of mobility traffic manager (MTM)
• On APs that are connected via local mesh links
• When WPA security is enabled on a VSC and it is terminated at the controller
• Over any PPP tunnel created by the following features: PPTP client, PPPoE, PPTP server
• Over any GRE, L2TP, or IPSec tunnel
• Over a static NAT mapping
• For access-controlled wired clients
• For client stations connected to a third-party AP
• On APs running in autonomous mode
Important
Take note of the following:
• When more than one controller is installed on a network, Bonjour gateway must be configured
on each controller so that there is only one forwarding path between any two networks or
VLANs. Otherwise, an mDNS loop can occur resulting in excessive amounts of network traffic.
• On a controller team, Bonjour gateway is configured only on the team manager.
• Bonjour is a service discovery protocol, not a service access protocol. It can be used to restrict
service discovery, but if a network administrator wants to restrict service access, they must use
some other means.
• Just because a client can discover a service using Bonjour does not mean that the client will
be able to reach that service. It is up to the network administrator to configure the network to
allow clients to reach the services that they should have access to.
• When both Bonjour gateway and traffic management are enabled, all Bonjour IPv6 traffic is
dropped by the APs.
Bonjour gateway
The Bonjour gateway feature forwards Bonjour traffic between interfaces defined on the controller.
The gateway is transparent to the Bonjour protocol. It only modifies the IP header fields as required
to have a valid IP packet on the new subnet. Packet contents are not changed. Bonjour gateway
functions differently for client stations connected to access-controlled and non-access controlled
VSCs.
NOTE:
• The gateway does not filter Bonjour traffic. To do this, you must define Bonjour filter profiles
and assign them to a VSC, AP, or user. See “Bonjour traffic filtering” (page 238).
• The gateway can only function on interfaces and VLANs that have a valid IP address.
Access-controlled VSCs
The following diagrams shows how Bonjour traffic is handled when using access-controlled VSCs.
Access controlled VSC with no VLANs
Bonjour gateway 231










