Best way to restrict a specific SSID to voice and messaging only

Solved
Chris_01
Conversationalist

Best way to restrict a specific SSID to voice and messaging only

I've been asked to set up a heavily restricted SSID, that only allows VOIP and instant messaging. 

 

Only way I can see to do it is by adding layer 7 rules to block everything except VOIP and video calls - but there doesn't appear to be a specific category for messaging.

 

Any other options that might work?

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

I'll be honest and say that using Meraki alone won't achieve your goal; ideally, you should integrate it with another tool like Cisco's own Umbrella.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

8 Replies 8
RaphaelL
Kind of a big deal
Kind of a big deal

That SSID is probably going to be unusable 

alemabrahao
Kind of a big deal
Kind of a big deal

Are you sure this would be a good idea?

And what about DNS and HTTPS?

You'll probably need to study all the resources that the applications you'll be using utilize to make this network functional.

I think first of all you should check if this is really feasible and worth the effort.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Chris_01
Conversationalist

No, I don't think this is a good idea! But it's what I've been asked to do... 🙂

 

Basically, we have a remote school location where there is no phone signal. So we want a system where collecting parents can connect to make calls / send messages - and that's it

 

alemabrahao
Kind of a big deal
Kind of a big deal

I'll be honest and say that using Meraki alone won't achieve your goal; ideally, you should integrate it with another tool like Cisco's own Umbrella.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Chris_01
Conversationalist

Thanks. That's my feeling about it too... though the actual solution would be more like treating adults like adults, perhaps!

mlefebvre1
Here to help

In the case of an SSID that is -that- restrictive with no cell service around, I would personally be very wary of accidentally blocking something that causes issues in an emergency (especially if it were to block access to 911 somehow). I doubt there's a perfect solution using just Meraki, but a bandwidth restriction to something like 128 kbps plus content filtering might get you 90% of the way there which might be acceptable, especially if there is no budget for anything else.

PhilipDAth
Kind of a big deal
Kind of a big deal

I think I would take a different tack.

 

Block everything, then allow only specific nominated services rather than a broad category like "VoIP".

TBHPTL
Head in the Cloud

Is this mobile phones in North America? If yes, then its easy. Use Cisco Spaces with MR-A licensing and do carrier offload via open roaming for that SSID that will get you ATT and T-Mobile.  no Verizon yet (no comment as to  why 🙄)  Or you could work with 3rd party aggregator like American Bandwidth's WI-DAS and manually config open roaming via MR-E licensing.  If you are talking about doing this for a desk phone. run the Ethernet cables. Even if you have Verizon sim devices, there are ways to install certificates to board them  all with WPA3 and RADSEC

Get notified when there are additional replies to this discussion.