Possibility to restrict access to my.meraki.net

Solved
Moonlight
Conversationalist

Possibility to restrict access to my.meraki.net

Hi! 

 

I would like to resitrict access to the local webpage of my.meraki.net from specific VLANS. However, I could not find any possibility to do so. Does anyone know if this is possible or another workaround besides disabling the page completly? 

 

 

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

It's not possible as far as I know, either you restrict it to the entire network or you don't restrict it.
 
You can try blocking the URL via Group Policy, but I'm almost 100% sure it won't work.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

It's not possible as far as I know, either you restrict it to the entire network or you don't restrict it.
 
You can try blocking the URL via Group Policy, but I'm almost 100% sure it won't work.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
FeliA
Meraki Employee
Meraki Employee

Hi @Moonlight,

alemabrahao is correct. At this time, blocking access / disabling the Local Status Page is a global network-wide feature that will apply to the entire network. The feature is enabled/disabled under Network-wide > General > Device configuration and will affect the entire network instead of individualized VLANs.

However, similar interests have been expressed regarding managing Local Status Page access on a per-VLAN basis. It's highly encouraged to submit this feedback request for future considerations via the Give your feedback” button in dashboard -- located at the bottom right corner of each dashboard page.

TNAComputers
Getting noticed

My understanding is that the Meraki device is listening for that DNS request. If you have a DNS server running like AD DNS on your network, you could create a forward lookup zone for my.meraki.com, or mx.meraki.com etc. and point to the clients to that DNS server which will fail to load anything. Thinking outside of the box, but have done this in the past as a quick way (without web filtering) to block entire domains. This obviously only works if you restrict the clients DNS to your DNS server. Otherwise they can just change it to something else and would work globally.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels