Access-policy - Can you return a "Filter-id" (Group policy name) on access-reject + guest ?

Head in the Cloud

Access-policy - Can you return a "Filter-id" (Group policy name) on access-reject + guest ?

Behind the subject is the thought: If I return a group policy (filter-id) in the access-reject message from my radius server will the switch honor this, and apply the GP to the client ?


The thought is to apply a GP, with additional ACLs, to clients being placed in the guest network for an access-policy.






5 Replies 5
Meraki Employee
Meraki Employee

Reject or accept? On accept yes it can apply a GP by using filter-ID

Ryan / Meraki Solutions Engineer

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Head in the Cloud

So the answer is no. It can only apply GP on accept.

It does not make any sense but ok.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Meraki Employee
Meraki Employee

If an access-reject is sent, the switch won't permit access, so I'm not sure how applying a group policy would help?

Well the though was that when you utilize Guest VLAN, then the client would be put into that VLAN on an access-reject. And I would just like to return some more config to that Guest access.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.