apply policy group to a vlan that does not live in MX

EnriquePeSa
Here to help

apply policy group to a vlan that does not live in MX

hello community!

 

I have a meraki MX where the SVIs of my LAN live and without problem I can create and assign a policy group per VLAN, now I need to download all the vlans to a switch core (meraki) but I cannot assign the policy group to the vlan, it exists any settings to fix it?

5 Replies 5
alemabrahao
Kind of a big deal
Kind of a big deal

You can apply group policy per VLAN using a Radius server.

 

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Creating_and_Applying...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

If you mean, you need to make a Meraki switch the layer 3 core - then no you can't do group policy on the switch per VLAN.  In fact, most group policy functionality is lost in this case.

Maumarti
Meraki Employee
Meraki Employee

Thinking you may be speaking of this topology, and if you set the client tracking by IP in that MX-only network, it should be possible for you to manually assign group policies by client IP

 

Alternative that is more automated could be MX Active Directory integration.

PhilipDAth
Kind of a big deal
Kind of a big deal

>if you set the client tracking by IP in that MX-only network, it should be possible for you to manually assign group policies by client IP

 

Negative.  "tracking by IP" only affects reporting (such as the clients page) and nothing else.  You can only attach group policies to a client when the client uses the MX as its default gateway (it must be layer 2 adjacent).

 

Group policies are always attached to a MAC address.

AH, it was kind of the back of my mind, but completely forgot. Thanks for the reminder, PhilipDAth! The power of the community! I stand corrected.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels