Hi,
I´d like to ask you some questions about the following solution scenario:
the requisition is, to setup a Guest-WiFi with some MR`s where the SSIDs would be configured in Bridge-Mode where the DHCP-Server is located on an Upstream Router...
To get some Content/URL-Filtering I think of using the Cisco Umbrella Solution which could be integrated in/with the Merkai Dashboard.
In that typical network level Umbrella deployment, pointing DNS to Umbrella alone may not be sufficient to enforce Umbrella protections. Savvy users may attempt to bypass Umbrella by changing the DNS settings on their machines, so the question for me is, if it`s possible to use the integrated MR Firewall configuration to lock down the users on the Guest-Network to prevent any other DNS service from being used to bypass Umbrella settings and protection (e.g. with an ACL-entry "deny udp any any eq 53")?
I`ve read through the following documentation -> https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/SSID_Modes_for_Client_IP_Assignme...
but I don`t understand the marked area... how can/does the MR restrict that traffic, if it`s send to the Clients LAN Standard-Gateway (which would be the Upstream Router)?
probably someone has already done a deployment which is similar or could tell me if the design approach is suggested at all 🙂