cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Setting up WiFi access for staff - restricting access to members of an AD security group - how to?

HML
Conversationalist

Setting up WiFi access for staff - restricting access to members of an AD security group - how to?

Hello all,

 

We are using the Cisco Meraki Wireless access points across our offices to provide a staff WiFi. We are now planning to implement a guest WiFi network (using Meraki authentication with short term passwords etc.) but when proposing this I have been asked to see if we can integrate WiFi access on the staff network with Active Directory, specifically only allowing staff who are a member of a particular security group.

 

I have created a test security group in Active Directory, I have set our Meraki security appliance to connect to Active Directory and it finds the security group, however, I am stuck at creating a 'Meraki' Group policy which simply allows access to the newly created 'Staff' WiFi SSID.

 

Has anybody else set up something similar? If so, how did you overcome these hurdles?

 

I'm also a bit apprehensive about turning on Active Directory authentication on our main security device - if I do this, will it still work as normal? We have a lot of satellite homeworkers who hang off our MX100 as their hub.

 

Any help or suggestions appreciated!

 

Thanks.

5 REPLIES 5
A model citizen

Re: Setting up WiFi access for staff - restricting access to members of an AD security group - how t

We've used AD authentication and it works fine. Keep in mind, however, that this will be hitting your AD server hard with WMI traffic so if you have any sensors, it may set them off.  

Found this helpful? Give me some Kudos! (click on the little up-arrow below)
HML
Conversationalist

Re: Setting up WiFi access for staff - restricting access to members of an AD security group - how t

Hi,

 

Yeah, we have tested the AD authentication and that works just fine, however, I am looking to lock it down to grant WiFi access to members of a particular security group in AD. I have found that I can link AD security groups to Meraki groups, however, I cannot see an option there to block access using it (unless it's something as simple as switching off scheduling)?

 

Did you achieve something like the above or are you just allowing all AD users access to the WiFi?

 

Thanks,

 

Andy

Getting noticed

Re: Setting up WiFi access for staff - restricting access to members of an AD security group - how t

i dont have a MX device used like you do to replicate your issue but i have accomplished the same thing with Radius Authentication using 802.1x for wifi,

 

i have our guest SSID open and blocked connection to local lan and have the wifi use its own DHCP to handle that

 

For the Staff wifi i have the 802.1x authentication that looks ad specific AD security groups to authenticate.with the Radius server which is a windows 2012 R2 running the NPS role and IIS role to push the certificate. Also i have a group policy for windows 7 devices for the wifi that automatically inputs the wifi settings. Windows 10 you don't need to do this it just works but windows 7 group policy is highly recommended.

https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_...

 

i think this will solve your issue even though it has a bit more steps

 

Highlighted
Getting noticed

Re: Setting up WiFi access for staff - restricting access to members of an AD security group - how t

Meraki's scoping AD article is where you need to look.  I tested this initially and can confirm it works well.  I chose to go a different route in order to limit the number of SSID's that were being broadcasted.

 

https://documentation.meraki.com/MR/Splash_Page/Scoping_Active_Directory_per_SSID

HML
Conversationalist

Re: Setting up WiFi access for staff - restricting access to members of an AD security group - how t

Thanks for your reply, and everyone else's replies, very helpful!

 

Thanks,

 

Andy

Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.