Since Meraki documentation recommend to have up to 3 SSIDs by AP, I would like to know how I can get devices linked to particular VLANs using a common SSID?
For example, SSID Sample1 links devices with VLAN10, VLAN20 and VLAN30 as shown below:
I hope that make sense.
When using 1 SSID look into this: "Per-User VLAN Tagging"
I agree with @ww that using RADIUS based VLAN tagging is the most common. I have never done it myself, but you can also attach a group policy to individual machines to override the VLAN they drop into - which you might want to consider if you are not using a RADIUS server.
Thank you very much for your answer.
Unfortunately I should not have more than 3 SSIDs on an AP. If I tag each SSID with a single VLAN I will end up having approximately 14 SSIDs.
The option of tagging AP with different vlans as shown in your example will force me to buy more APs since I have devices running everywhere in the building and will not be able to use current APs for multi-propose.
Let me give you a bit more information.
I have segmented the network into several vlans with devices placed everywhere in the building. Some of these vlans require to be accessed wireless via AP. For sure, more than 3 vlans.
Another thing is that there are plenty of devices that are not managed in AD so I cannot use RADIUS for tagging vlans with devices. Therefore, devices managed in AD are only those used by internal staff such as PCs, laptops, etc. These devices will not be a problem since I could have a SSID tagging the Internal Staff vlan and there is no need of using RADIUS as vlans are not segmented by users but devices.
I hope this make sense and you can help me finding a way for better designing my WLAN.
Thanks for your answer.
It looks like the solution for sharing a common SSIDs will be using Group Policy / Per-Device Type VLAN Tagging as explained in the link you passed.
The disadvantage to that will be that I will have to link manually each device to the GP.
@Ricardo_Bagnoli The easy way around manually setting group policies is to let a RADIUS server do it for you based on group membership (Active Directory usually). This way the Meraki group policies are auto assigned which then allows you to do the VLAN grouping as you desire along with any other restrictions you want placed on the devices.