@robby_barnes wrote:
@Mr_IT_Guy wrote:
On almost all home routers, you can set up your network to allow only specified MAC addresses to connect. With Meraki, the device has to been seen first before you can deny it. Engineers I've talked to have confirmed this and we've put in several tickets on the matter. I'd like to be able to setup a Z1 so that it blocks all MAC addresses except for those that we specific without having to have seen the device first.
Absolutely yes. It would also be really awesome if you could set this at an organization level (or at least a template level) so that you can apply it across large networks very quickly.
Hey @robby_barnes,
Hey @Mr_IT_Guy,
I have good news for you. The behavior you describe can be achieved by using the Dashboard 'Clients' page (Network-wide > Clients).
If you look in the top right-hand corner of the Clients page, you will see an 'Add client' button ( image attached below ). Using this button, you can add clients using their mac address, individually or multiple at a time, and specify what policy you would like applied to those devices.
If what you are looking to do is have all traffic denied by default and only allow traffic for any pre-added device all you need to do is the following:
- Set your layer 3 firewall to Deny all traffic
- Add the list of trusted MAC addresses to the client's page and set their desired policy to 'Whitelist' (if you don't want them restricted in any way) or to a specific group policy.
Hope this helps!