Hi and thanks for your reply.
I am restarting this thread up again, as I still have the same issue, and have tested a few more scenarios
default vlan 1 for all infrastructure, mx64 dhcp
Lan on vlan10 dhcp via windows server
wireless ssid 1 , L3 roaming, access to lan and internet
filtered by the normal content filter, can be overridden by group policy
wireless ssid 2, Meraki DHCP, no access to lan, access to internet
filtered by the normal content filter, cannot be overridden by group policy OR client whitelisting.
I have tried windows laptop and android clients, same effect, it seems that the Meraki DHCP ssid which is perfect for our staff to use their personal phones, where they have no access to the LAN or each other but would like unfettered access to internet. Unfortunately the content filter is always applied.
The content filter is used on the LAN and other SSID's with L3 roaming to restrict approved devices (i.e. non personal phones) yet I can apply whitelisting or group policies on various clients which can easily bypass the content filter.
However, I think I found the answer
Created a new VLAN with group policy attached to override the content filter
Created a new staff SSID, used L3 Roaming, tagged to the VLAN and denied access to LAN
seems to have fixed it.
Steve