Yeah, this was a lame rant. Just create a single purpose SSID on your enterprise wireless controller that supports peer-to-peer (client to client connectivity). Bind the educational hardware to that, everything is fine. Really I dont see Google doing anything wrong here...
True that sounds tenable, but dealing with multicast can be a pain. There's no such thing as "enable p2p", there's enable multicast and open specific ports between clients, etc. Does Google give the IP and netmask for the multicast, or the requirements for TTL, or even just the multi-cast ports used, etc? Are they even using multicast? It's all basic info which could readily be listed allowing a configuration to meet the user's needs. Having a single "wide open on all ports" (e.g. consumer grade) SSID on a network could be a significant vulnerability vector.
There is enable p2p, its called disabling client isolation mode. This isn't even specifically about multicast. Its just the peers (clients) cannot make unicast connections to each other.
Buddy, client isolation mode or lack there of is sometimes called allowing 'peer to peer' traffic. I understand the ambiguity over TCP P2P networks, but given the context most network engineers know what you are talking about. Regarding the article mentioning multicast -- the engineer SUSPECTS its to do with multicast. Im saying it could be due to several configuration issues, but most likely client isolation mode (aka not allowing peer-to-peer traffic). Why pick a fight over this?
as far as picking a "fight" I was not, I was being technical. When it comes to talking about Technical things I prefer when people are technical. This is key when writing technical documentation.
For example, if you were writing a technical doc you would not put in the doc "Turn on P2P feature" as that feature does not exist, instead you would say "To enable P2P communication, turn off Client Isolation"
One should be technical when talking about technical things, and assuming "most network engineers know what you are talking about" is often how mistakes are made...
I have seen companies lose millions because one engineer assumed another engineer knew or thought about, or would preform steps not included implicitly in an instruction set
Very likely! But it could scan the subnet, like say a printer driver does. Multicast is the easiest, but not the only way. The issue mentioned in the article is likely related to both mDNS blocking and client isolation (peer to peer).
I have no idea of the peer discovery mechanism in this product -- I was just stating that multicast is not the only peer discovery mechanism, ala printers and other consumer kit that scans the subnet.
I believe one of the selling points of Expedition is that clients can run on students' phones. At that point you have to whitelist hardware of students which come and go, are not managed by you and you experience pain.