Hi
We have a Wi-Fi deployment that using a Tunneled-SSID architecture.
- Guest-SSID is tunneled to a Guest-VLAN (500), back to an Aruba 9114 GW in our Datacenter.
- VLAN500 is the Guest-WiFi VLAN that is used for all general internet traffic.
- SSID Authentication is PSK; after the user authenticates, they will get redirected to the default Aruba Cloud-Guest captive-portal, which then the user "Accepts", and is given access to internet.
Our issue is we have a few clients / devices that we want to "block", but we are unable to do so.
- After going to the AP Group> Clients> Find the device> Actions> Block Client, the device's MAC is put on this "Denylist", but even so, the user is still connected. The client does not even get disconnected.
- The only thing that works is disabling the AP, which is not ideal as it affects all other clients.
- When I do the above to a device connected on an SSID that does not use captive-portal, (It's using PSK only) the block works.

- So the "block client" action only works for SSID's that are not using the captive-portal.
Our SSID config is as follows:
- Security Level: Visitors
- Cloud Guest (Aruba Captive-Portal)
- Access Rules
- Unrestricted
- Not using role or network based access
- Not using Clearpass or any equivalent products for our wireless networks.
Any idea or help is greatly appreciated.
Regards,
VC
-------------------------------------------