Cisco Secure Access with Meraki MX

omshiv
New here

Cisco Secure Access with Meraki MX

Hello There,

I was wondering if anyone has integrated Meraki MX devices with Cisco Secure Access (VPNaaS)?

Looking to leverage the existing RA capabilities such as DUO/AD/Posture-Assessment, without replacing the hardware (MX) or software (Secure client). I understand that there would be associated cost(s) but looking to confirm the compatibility between MX and Cisco VPNaaS (Secure Access). Any help would be highly appreciated.

 

Thank you.

3 Replies 3
Tony-Sydney-AU
Meraki Employee
Meraki Employee

Hi @omshiv ,

 

I recommend reading this Design Guide first so you can have a better idea of what you need to design your solution.

 

After understanding the components and design, do a quick search for SASE here in the community; maybe your question was already discussed.

If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.

Thank you, Tony.

PhilipDAth
Kind of a big deal
Kind of a big deal

I have it set up in our test environment.  It works well.

 

There are two main licences types, "Foundation" and "Complete".  

https://www.cisco.com/c/en/us/products/collateral/plus-as-a-service/secure-connect-now-ds.html

Then there are two flavours.  "Essentials" is basically (not quite correct) for when you have 10 or less users.  Otherwise you need "Advantage".

 

The big difference is that "Complete" includes zero trust support.  This allows you to access an internal web page or service without the user having to do anything.  It users the zero trust module of Cisco Secure Client - which requires no user interacton.

 

It comes with Umbrella.  It integrates with Cisco Duo - so you need to still buy Cisco Duo if you want to use it for your SAML provider.  You can also authenticate against Entra ID.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.