Guys, did you already try to config meraki mr to have one ssid with multiple vlan assignment?
Hi @Ritchie, we try and its awesome,
To setup follow next
Click on "Add VLAN". Enter the AP tag that identifies the AP (or APs) you want to set for a specific VLAN tagging. Repeat this step for each AP tag group in which want to apply a specific VLAN tagging on their clients for this specific SSID. Here, AP tags are used to further customize your per-SSID VLAN configuration. Click on "Save".
For more information, take a look at this kb:
https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/VLAN_Tagging_on_MR_Access_Points
hope useful.
>Guys, did you already try to config meraki mr to have one ssid with multiple vlan assignment?
Why?
You can use layer 3 roaming for this - but it is seldom the right solution.
Yup. We're doing this for a specific use case and utilizing the RADIUS attribute method to get it done. I have also tested it via Group Policies in the lab and that works just fine as well if your needs allow you to do it that way.
Actually there is an instance that specific users need to associate with different vlan.
Once he/she login to there computer using there active directory account it will retrieve an IP address specifically what VLAN they were assigned of.
So i think that would be the integration between active directory, cisco ISE and meraki mr.
Hi,
I have the ISE integrated with MR and it works - VLAN change as well. I use only local users created on ISE (no AD). You can assign group-policy using ISE to wifi user as well, but if you do so then any configured Content filtering rules in group-policy won't take affect when group-policy is assign via radius to the client.
How did you do it Sir? Our current setup is using 1 SSID and have different vlans. depends on the AD configuration on NPS.
and here goes the ISE that we just purchased and my boss asked me to utilize the ISE and integrate meraki with ISE.
same as your example. how can i configure ISE to do this kind of setting?
my group policies in Meraki of course is already done.
thank you in advance
It's been awhile, but I set it up with rules under NPS and used RADIUS authentication to place it into the correct VLAN. If you'd like a more detailed description I'll have to look at my notes when I get into the office tomorrow. I had several different diagrams I had mapped out with a walled garden even. I cant recall which one I went with in the end though.
have you tried this to cisco ISE?