URL Filtering only for a specific SSID / VLAN

Solved
Captain
Getting noticed

URL Filtering only for a specific SSID / VLAN

Dear Community,

 

We have a network with many SSID's each SSID has its own tag VLAN.

 

We are looking into a way to filter traffic on one specific vlan / ssid to achieve the following:

 

   * Block access to any URL except one or many specific URLs

 

 

How can it be done?

 

 

 

Thanks in advance,

 Ale.

1 Accepted Solution
jdsilva
Kind of a big deal

You can do this by configuring your content filtering rules in a Group Policy, and then applying that GP to a VLAN on an MX. 

 

image.png

image.png

View solution in original post

5 Replies 5
jdsilva
Kind of a big deal

You can do this by configuring your content filtering rules in a Group Policy, and then applying that GP to a VLAN on an MX. 

 

image.png

image.png

Captain
Getting noticed

Hi,

 

I've created a policy group and tested. 

 

Is it correct the rule "*" I've applied which is intended to block all URLs except google.com?

 

 

2019-10-07 16_15_06-Window.png

 

When testing and connecting with an iphone to the SSID with vlan 532:

 

1. i can't see any clients affected by the group policy... it shows 0

2. The connected client is able reach any URL so basically it doesn't work.

 

 

2019-10-07 16_12_28-Window.png

 

 

If I go to clients I can see the client is connected to vlan 532:

2019-10-07 16_17_12-Window.png

 

 

Any idea what's wrong?

 

 

 
Captain
Getting noticed

Sorry no need to reply... 

I had something wrong configured on my end and now your solution is working!

 

RaphaelL
Kind of a big deal
Kind of a big deal

Hi Captain ,

 

If I'm not mistaken , the best way could be by applying a group policy to our VLAN  : https://documentation.meraki.com/zGeneral_Administration/Cross-Platform_Content/Creating_and_Applyin...

jdsilva
Kind of a big deal

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels