Cisco Meraki MR52

RomeriF
New here

Cisco Meraki MR52

Hello,

 

My client is requesting that "the WLAN controller should be able to integrate into intrusion detectors defined by them to automatically dissociate users who are generating malicious traffic”.


¿Can Cisco Meraki APs have the ability to automatically disassociate users who are generating malicious traffic?

 

If it is not possible to do it with Meraki, with the traditional solution of Cisco (with physical controller) can do automatic disassociations of the users that are generating malicious traffic?

 

Thank u so much!! 

1 Reply 1
PhilipDAth
Kind of a big deal
Kind of a big deal

There is no such way you could do this with Meraki WiFi kit.  Meraki WiFi kit has integrated IDS that runs on the AP itself.  Decentralising this back to something central would weaken the whole solution.

 

Even if you could do this - and you disconnected the customer from the WiFi - the client will just automatically try and reconnect (standard WiFi client behaviour).  You will end up putting your authentication system under load as the client and the authentication platform try as fast as they can to authenticate/disconnect the client.  It will be a race.  You will also burn a bunch of RF spectrum on these WiFi authentication/disconnect attempts.

 

The best solution would be to run the WiFi traffic through their IDS - and have their IDS block the traffic coming from the client.  This will at least preserve your RF spectrum for other legitimate users.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.