I found the problem. On the template, SSID record, Firewall & traffic shaping, the "Allow Bonjour forwarding exception" must be enabled when Layer 2 LAN isolation is enabled... In order for that to be enabled, in the Access Control page for the SSID (in the template), Bonjour forwarding must be enabled, which requires at least one forwarding rule. (This forwarding rule doesn't have to match the one on the Group Policy.) As long as those two things are setup, the Group Policy Bonjour forwarding rules will apply for users authenticated to the Wi-Fi (802.1X). (The RADIUS server must be configured to send a Filter-Id (or similar) with the matching name of the group policy.) If anyone else is struggling with this, please feel free to DM me and I'll try to lend a hand.
... View more