We are currently planning a deployment of Umbrella SIG and are looking at the best options for applying Umbrella Policies to un-managed devices. We will be using the Umbrella Secure Client for managed / roaming devices.
We currently use a Guest WiFi network with Meraki AP assigned (NAT mode). Is there a best practice for applying Umbrella to this? We are thinking of going down an IPSEC / SDWAN tunnel route for this however Meraki AP assigned doesn't support VLAN Tagging.
Does applying the SDWAN policies or IPSEC Tunnel to the Native VLAN that the AP's also inherit that to the Guest Wifi? I believe the Meraki AP Assigned will use the Native VLAN.
Or are we just overcomplicating it and should migrate a away from Meraki AP assigned and try replicate the isolation within a bridged SSID for better control. If so is there any guidance out there on replication the inbuilt Meraki Isolation that comes with the AP Assigned mode.