Meraki integration with umbrella and active directory

LeoAri
Comes here often

Meraki integration with umbrella and active directory

Hi friends

I am doing a Meraki integration where Cisco Umbrella security policies must be applied to Active Directory users. I am having problems with where to start. I read the following links:

 

Meraki integration link with Umbrella

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Manually_Integrating_... 

 

Meraki AD integration link

https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Configuring_Active_Direc... 

 

I think I need to do the following:

1: Integrate Meraki with Active Directory, to view user groups

2: Use API to integrate umbrella with meraki

3: Create the group policy in meraki MX (with the sec license)

4: Link the group policy with the umbrella policy

5: Link an AD user group with the group policy

Could someone tell me if I'm right?

Could you suggest tutorials?

Regards

6 Replies 6
PhilipDAth
Kind of a big deal
Kind of a big deal

There are multiple ways to do this.

 

If you are happy to manage this in Umbrella (rather than the Meraki Dashboard) , the way I would do this is to:

 

* Deploy the Cisco Security Client (with the umbrella module) onto every machine.

https://docs.umbrella.com/deployment-umbrella/docs/5-connect-active-directory-to-umbrella

* Sync Umbrella with Active Directory.

https://docs.umbrella.com/deployment-umbrella/docs/5-connect-active-directory-to-umbrella

 

LeoAri
Comes here often

hi

Wouldn't it be necessary to integrate Meraki with Active Directory? Would only umbrella integrate with Active Directory?
Could I apply umbrella policies to AD user groups in Meraki?
the links you provided are the same

PhilipDAth
Kind of a big deal
Kind of a big deal

If you have the Cisco Security Client on every machine, you can apply Umbrella policies inside of Umbrella to whatever users and groups you like.

 

The bonus of this method is it works even when they are out of the office.

VivekT
Getting noticed

Hi ,

 

 

Are there specific reasons you want to integrate AD with Meraki?

If you have the Umbrella dashboard, you can integrate Umbrella with AD. Once integrated, you can apply policies directly within the Umbrella dashboard.

 

if you dont have any bandwith concern , you can use cloud on ramp. If that is not the case ,you can do via individual S2S tunnel.

LeoAri
Comes here often

hi,

I want to apply policies based on specific users in Meraki MX. And I would understand that I must integrate the AD groups previously in Meraki.
I would appreciate it if you could provide me with information or a tutorial on how to achieve this without needing AD, I could not find much information.

VivekT
Getting noticed

Please give me me more high level details to help you in better way. 

 

Here is my observation : 

You can apply policies based on specific users in Meraki MX without requiring Active Directory (AD) integration by using Meraki's built-in user authentication capabilities, such as Layer 7 traffic shaping and group policies.

 

  1. Meraki User Authentication: You can set up authentication to identify users on your network. This can be done via:

    • Meraki Authentication (Local Users): You can use Meraki's built-in user database or integrate with a RADIUS server for external authentication.
    • Splash Page: If users connect to a wireless network, they can authenticate via a splash page that requires credentials (even if you don’t use AD or any directory service).
  2. Group Policies: Once users are authenticated, you can apply group policies. These allow you to apply network usage rules (such as bandwidth limits, content filtering, etc.) based on specific users or groups.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels