We have got ISE for our wireless.
This is the SSID for Active-Directory Users, the ISE decides if the device has an certificate or not.
If certificate is ok: user has internal access
if no certificate: the user gets an Internet access only f.e. for his mobile devices, cell phones, iPads and so on.
It´s a two factor check: Active-Directory account + certificate on the device. And a easy to use with only one SSID for the employees. Guests have an own SSID.
Meraki SSID config:
![Bildschirmfoto 2019-04-02 um 14.10.33.png Bildschirmfoto 2019-04-02 um 14.10.33.png](https://community.meraki.com/t5/image/serverpage/image-id/6612i241247DCE9836C7A/image-size/large?v=v2&px=999)
![Bildschirmfoto 2019-04-02 um 14.12.57.png Bildschirmfoto 2019-04-02 um 14.12.57.png](https://community.meraki.com/t5/image/serverpage/image-id/6613iAA5341C73A4F1047/image-size/large?v=v2&px=999)
You need to set up the rules on the ISE correctly.
And this is important:
You need to put in every Accesspoint with it´s IP-Address as allowed network address:
![Bildschirmfoto 2019-04-02 um 14.16.55.png Bildschirmfoto 2019-04-02 um 14.16.55.png](https://community.meraki.com/t5/image/serverpage/image-id/6614i4E28E72FA883D7BF/image-size/large?v=v2&px=999)