Hi@ster
As user isolation across VAPs does not take effect, the following modifications need to be made
AP groups that require user isolation and AP groups that do not need to use different service VLANs are changed to different VLANs.
At the same time, you can configure Layer 3 user isolation for the AP group to be isolated.
Configure Layer 3 isolation:
[AC6605-wlan-view] traffic-profile name p1
[AC6605-wlan-traffic-prof-p1] user-isolate all