I'm no expert, but I think most enterprise & university networks enable client isolation in the routers.
If I know the IP of a friend on the LAN, I can connect to him directly, as normal - the connection will not be blocked by the router. But other than that, the router shows my device a view of the world in which it is the only thing connected to the LAN.
Enumerating the private IP space and trying to connect to all of the possible addresses might reveal the actual stuff though? But the multicast protocols I assume use a smarter and more efficient approach which gets blocked by client isolation.
Client isolation is just wireless clients on the same AP. PIM routing acts like a proxy, and the multicast address for whatever service your routing will be proxied to the clients local multicast address.
Ruckus calls it bonjour fencing, and has pretty good support for creating useful policy.
Client Isolation mode is layer 2 -- its done at the Wireless AP. It should prevent enumeration of the private network space (if the other peers are on the Wireless AP). Neither Multicast nor unicast will work for traffic between clients.
If I know the IP of a friend on the LAN, I can connect to him directly, as normal - the connection will not be blocked by the router. But other than that, the router shows my device a view of the world in which it is the only thing connected to the LAN.
Enumerating the private IP space and trying to connect to all of the possible addresses might reveal the actual stuff though? But the multicast protocols I assume use a smarter and more efficient approach which gets blocked by client isolation.