Actually block a client from SSID

RichardRostron
New here

Actually block a client from SSID

good morning!

 

we have multiple SSIDs on our meraki wifi system.

i need to block specific devices from accessing specific ssids.

 

i have found some settings which allow to you to block devices from SSIDs but this does not function as expected.

 

If i am blocking devices to specific SSIDs,  these devices can still connect to the SSID but internet access is disabled.   i find this an odd way of blocking devices,   i would expect blocking devices to actually block the device from connecting/associating to that SSID.

 

is there actually any way to block devices from connecting/associating to the SSIDs?

4 Replies 4
Brash
Kind of a big deal
Kind of a big deal

There's no simple way to do this.

To prevent association, you would need to change the access control on the SSID to MAC address based auth or another RADIUS auth method.

It's far easier blocking the device from network access after association using group policies.

alemabrahao
Kind of a big deal
Kind of a big deal

You can select the specifc client and block like this:

 

alemabrahao_0-1681817625147.png

 

https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Block_Listing_and_All...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

This will depend on how authentication is done on the SSID.

 

Typically this kind of requirement is solved using RADIUS, and you create a RADIUS policy that only allows the user to connect to the SSIDs they are authorised for.

TBHPTL
A model citizen

In this day and age of locally administered MACs you are going to drive yourself mad trying to block anything from the air.

 

How are you granting access to the network? What is your Meraki hardware? MX and MRs, MRs only? etc... Your answer will determine what's available "canned" from the Meraki ecosystem for controlling access.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels