Converting a Cisco ISE dACL to be used with Meraki Managed Catalyst switch

dropped_packetz
New here

Converting a Cisco ISE dACL to be used with Meraki Managed Catalyst switch

We only use ISE for wired users, we have no wireless.  We have a limited-access dACL in ISE set up for workstations sitting at the login screen (pre-login) that is connected to our Authenticated Machine-Only AuthZ policy.  And we also have a very similar limited-access dACL for unauthenticated user post-login that do not yet have a cert from our CA server to have access to just the services needed to be able to obtain their user cert and then re-authenticate and get the intended access they should have.  We are about to start upgrading our 2960X branch switches to Catalyst 9200L switches which will be managed through Meraki dashboard, so are now trying to learn about Meraki.  I know Meraki managed Catalyst switch can not do dACL, but I have found bits and pieces that I can accomplish this by utilizing  the same ACL in a Group Policy with a Filer-ID and maybe attached to a Access Policy?  WE already have a switch set up that is doing our NAC with our ISE enviroment, I just need to figure out how to implement this dACL in Meraki language.  Everything I find seems to be missing something I am not picking up because i'm not being able to connect all the pieces.  Any guidance would be greatly appreciated.

2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

Take a look at this discussion.

 

https://community.meraki.com/t5/Switching/Meraki-MS-with-ISE-and-DACLs/m-p/194496

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
dropped_packetz
New here

Yeah, I found that when I first got on and did a search.  I have that page up and the page that is in the link at the bottom of that page and still not seeing the full picture.    I'll read through them all and and see if I can pinpoint what I am missing or try to get a better description of the missing puzzle piece I'm not understanding.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels