Yeah we could push a GP, but on a layer 2 switch would that be "honoured" at the switch ? or would that only be applied on the MX's layer 3 interface ? - We like port isolation because it blocks all the way down between clients on the same vlan.
We could of course have gone SGT's (Adaptive policy or whatever its called in a Meraki setup), but time and money.
And SGT's do not yet extend all the way across MX's and AutoVPN, so just for this small scenario it was kinda overkill, the day it does (extend across MX's and autovpn), it will be a super solution 🙂 .
- So our quick and dirty solution for now was port isolation, but then we "kinda" ran into this problem with some ports (devices) that might not "need" it.
We use dot1x for everything, so it would have been nice if we could have toggeled that port isolation switch using a radius response.
Thanks for all the suggestions and comments.