@GreenMan wrote:
If splash page is your particular ask, then this will apply: https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Splash_Page#MX_Splash...
Yes, i know.
Splash page depends from access control page: if i set Network access > Sign on with "my radius server" i can setup a Radius IP.
But the main questions is:
- could be a NPS server inside my network and not public exposed or must be public?
- If i do a port forward of 1812/UDP from Meraki Cloud IPs to the NPS private IP, it works?
That page says that:
IP addresses The Meraki cloud must be able to communicate with your RADIUS servers via the Internet.
Please make sure that:
Your RADIUS servers have public IP addresses (i.e., they are reachable on the Internet).
Your firewall, if any, allows incoming traffic to your RADIUS servers.
You whitelist IP addresses as clients on your RADIUS server as per the firewall information page.
@GreenMan wrote:
I see you found that already, in Dashboard - and that the multi-client recommendation puts it out for you (😕). It's worth knowing that the authorisation, on that basis - if you did adopt it - is an on/off switch. Assuming the VLANs on your site are all routed by your MX, by default authenticated clients would be able to access all those. You could limit any access between them (and to the Internet, of course) using the MX Firewall features.
Note that, if you're also using VPN, you would need to control any access to remote subnets over VPN tunnels separately, using VPN firewall rules under Security & SD-WAN > Configure > Site-to-site VPN
Right