Hello everybody,
I tried to search if this had already been discussed somewhere but I can't find anything.
In our environment we use a Cisco ISE used to authenticate our WiFi clients. As you may know, before the authentification takes place, the device sending the RADIUS request has to be added as a "network device" on the ISE with a shared secret to make sure it is allowed to perform the RADIUS request.
In a traditional Cisco WiFi deplyoment with controllers all we had to do was add all our controllers to this list, which was manageable (<10). Now, is there any best practice on how to do this when we have potentially thousands of Meraki APs sending RADIUS requests to our ISE (since there is no controller anymore in the Meraki world) ?
- Is there any integration between the ISE and the Meraki dashboard to automatically trust and configure the Meraki APs on the ISE once they are added to the dashboard ?
- Should we configure a single network device (for instance with 10.0.0.0/8 range) that will cover all APs, but using the same shared secret ?
Any help would be appreciated !
Thanks.