(And the new administrative MAC addresses make the MAC cookie even much less valuable). By making use of RADIUS authentication within the wifi association we reduce the connection amongst the Radius login and the Portal user login and boundaries.I feel the confusion is everyone seems to be assuming your drop rule is in filter not nat, as that is of