I am looking for a recent design guide or implementation info to convert our WPA-PSK wireless to WPA-Enterprise. Documentation I have seen says an intermediate RADIUS server is required, has this not changed yet?
We have given out our PSK so many times we may have posted it on Facebook. Adding more control and linking to userID on Office365 is the objective. We are completely cloud based so do not have the infra or facilities to host a RADIUS server.
What are the options?
We can do SSO for Meraki dashboard login, what are the options for WPA2-Ent for the wireless connections? Our source of truth for user accounts is EntraID. I would like to link to that.
Ideas?
Yes, you still need an intermediate server, but you don't need to install this server on your on-prem infrastructure, you can simply create a new machine in your cloud environment (AWS, Azure, etc.).
Other than that, you can use Meraki's own base for authentication and/or authentication with iPSK without radius.
Configuring WPA2-Enterprise with Meraki Authentication - Cisco Meraki Documentation
Enabling WPA2-Enterprise in Windows - Cisco Meraki Documentation
https://documentation.meraki.com/MR/Encryption_and_Authentication/IPSK_Authentication_without_RADIUS
I have found that there are public RADIUS services (https://idblender.com/pricing) which can backend to O365. So that might be an option.
We don't have AWS / Azure facilities as we are a non-technical events company - So that option is out.
Using Meraki auth might be OK, if we could import or sync the user accounts from O365. The point is password and user tied to a single source of truth. If they leave, we only have to switch off one thing.
It seems Meraki are soooo close but just missing the last piece.
In this case, a third-party Radius solution that integrates with O365 is the best option considering that you cannot import these user accounts into Meraki.
https://jumpcloud.com/blog/radius-authentication-microsoft-office-365
In this case, a third-party Radius solution that integrates with O365 is the best option considering that you cannot import these user accounts into Meraki.
A while back, there was an article abount integrating Meraki Wireless with Azure Cloud PKI, using Cloud Authentication on the SSID.
I haven't tried it myself, but try taking a look at
Interesting idea and seems to fit most scenarios. One issue for me is we don't use / license Intune. We are also a Apple client house. All the references are for WIN clients so not sure how this would apply for MacOS and iOS.
Maybe I will test it and see what happens.
Thanks for the guidance
Without holding me against it, I don't neccesarily think this only applies to Intune/EntraID.
Perhaps it would be possible to do something along the lines similar to what's being done on Entra Cloud PKI. From what I can read, essentially you need to have the Meraki RootCA in your CA chain, and ensure this is present in the certificate chain.
But like I said, don't hold it against me.
You could also look at using Trusted Access (additional licence needed). It deploys certificates onto devices and uses that to authenticate.
802.1x gives me two options - certs or userID.
I was thinking that UserID might be simpler as the onus is on the user to log in and uses a single source - Office365/EntraID. Certs has a complicated, additional management overhead to distribute and revoke. I will take a look as the project progresses.
Thanks for the advice.