Event Log or Syslog - Group Policies

Daniel24
Here to help

Event Log or Syslog - Group Policies

What is the best way to identify what policy a client is associated to within Meraki? Especially if that is a policy set at the VLAN level? Is there something in the logs that I am missing that identifies the Group Policy assigned to that client? I haven't found it as well when looking into a Syslogs server.

2 Replies 2
PhilipDAth
Kind of a big deal
Kind of a big deal

If it is at the VLAN level, you can see it applied under "Addressing & VLANS".  It isn't applied to the client when you do it this way, but it will affect the client if their traffic passes through the VLAN.

alemabrahao
Kind of a big deal
Kind of a big deal

As I said on the another topic.

 

When a group policy is applied to a VLAN, that policy becomes the new "network default" for any other group policies applied to clients in that VLAN. Since this policy is the new "network default," the client devices will still show a "normal" policy applied under Network-wide > Monitor > Clients.

For example, a group policy named "Guest Network" with more restrictive layer 3 firewall rules than the network-wide configuration is applied to the guest VLAN, and a second group policy "Low Bandwidth" has a custom bandwidth limit, but is set to Use network firewall & shaping rules. If the Low Bandwidth group policy is applied to a client on the guest VLAN, the client will use the layer 3 firewall rules configured on the Guest Network group policy, not the network-wide layer 3 firewall rules configured on the Security & SD-WAN > Configure > Firewall page.

 

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Creating_and_Applying...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels