Wi-Fi networks that keep devices apart
Why BeeBEEP cannot connect two devices on a Wi-Fi with client isolation, how to recognize such a network, and what gets you through.
For: users, administrators · From BeeBEEP 6.0.0 · Updated on
Some Wi-Fi networks do not let the devices on them talk to each other: each one reaches the Internet, and nothing else. This is called client isolation, and on such a network BeeBEEP cannot connect two devices the way it normally does. This page explains why, how to tell that you are on one, and what gets you through anyway.
What client isolation is
A Wi-Fi access point with client isolation drops every packet that goes from one wireless device to another. It is meant to protect strangers from each other, so you find it where strangers share a network:
- guest networks, at home and in offices;
- hotels, airports, stations, cafes and most public hotspots;
- some office and school networks, set up that way by their administrators.
A device connected by cable usually stays reachable from the Wi-Fi: the isolation applies between wireless devices, not toward the cable.
Why BeeBEEP cannot work there as usual
BeeBEEP has no server. Two devices find each other with announcements on the local network, and then talk over a direct connection between them. Client isolation stops both:
- the announcements of one wireless device never reach the other, so nobody appears in Users;
- a direct connection between the two is dropped too, so adding the other device by its address does not help either.
This is what sets client isolation apart from a network that only stops broadcast packets, such as a router between two subnets or a VPN: there, adding the other computer by its address connects the two, as finding the people you want to reach explains. Under client isolation nothing direct gets through, whatever BeeBEEP tries, because the network is built to prevent exactly that.
How to recognize it
- You and a colleague are on the same Wi-Fi, BeeBEEP is running on both devices, and Users stays empty on both.
- In Users, Find or add users (the + button), you write your colleague's address under Add a user by address, and BeeBEEP says that it has no answer yet although the address is on this network.
- A colleague connected by cable appears, and wireless ones do not.
- The network's name says "guest", or you are in a public place.
A firewall on the other device gives the same signs from one side only: if one of you sees the other and not the reverse, look at the firewall first (see the frequently asked questions).
What gets you through
- A cable on one of the two devices. A wireless device and a wired one usually reach each other.
- A BeeBEEP on a computer connected by cable that both of you can reach. It sees both wireless devices, and passes your messages from one to the other, still encrypted end to end, so that computer cannot read them: chats and groups work through it. A file does not: you see that it was sent, and it downloads once the two devices can connect directly. This is Relay messages for others in Settings, on for everyone by default on a computer.
- Bluetooth, for someone nearby. Turn on Bluetooth in Find or add users: two devices close to each other find each other with no network at all.
- Another network. A staff Wi-Fi without client isolation, or the same Wi-Fi with isolation turned off for your devices: for an office, this is the administrator's choice, and the one that makes everything work as usual.
For whoever runs the network
If BeeBEEP is meant to work on your Wi-Fi, give its users a network without client isolation, or allow traffic between their devices. Where isolation has to stay, a computer on the cable running BeeBEEP lets the wireless devices talk through it; the ports it needs are in what the network must let through.