Definitly :
PORT SECURITY like CISCO CLI. (Possibilty to allow 1 Mac adress with dynamic mac adress table)
This kind of configuration could prevent installation of unwanted Dumb switch or router by customers
Example of configuration in CLI I really would like to have in Meraki :
interface FastEthernet0/1
switchport mode access
switchport access vlan 601
switchport port-security maximum 1 vlan access
switchport port-security violation restrict
switchport port-security
Actually no feature purposed by meraki could help us to prevent unwanted network devices
- Stiky mac address : Not an option, to many change, no time to manage that
- 802.1x : not an option, we don't use computer in domain
- Mac address whitelist : not an option (same as the first)
So actually anyone who plug a dumb switch or router in meraki switch with minimum of knowledge with IP adress broke the security