I guess I know the answer to the question I'm going to ask, but I'll ask it anyway, because there is a lot of experience out there and someone may have managed to do what I want to do:
I have an existing Dell switch network. Tht is non-negotiable, it's not old enough to just right off and replace. It has L3-capable Core and Data centre switches, but the access switches are all N2048, which don't do vrf, don't do GRE, don't do any L3.
I want to run SSIDs for Guest and card payment, so in any other environment, using Meraki APs I would have put those SSIDs into VLANs that were in vrfs and thus secure from the other traffic/users....but I can't build vrfs. I could, at a push, use GRE tunnels, but the access switches don't support GRE, either.
I can't mix traffic from secure and insecure VLANs in the same L3 environment ("VLANs aren't a security tool") so it appears I can't use Meraki, but will have to use a controller-based solution, so the APs will pass all SSIDs to a WLC via CAPWAP (Cisco, etc) or IPSec (Aruba, etc) tunnels, then break them out in the core, where the switches DO handle vrfs and I can get them across to the firewall safely.
So here's the question: is there another way? I want to use Meraki, the user wants to use Meraki, but the Ethernet network appears to be a blocker unless I can work some magic....
Thanks
Roo