Hi there,
I have a challenge I am sure someone here can help with! I have a customer with about 50 multi-tenanted sites. Each site can have between 20-30 tenant groups and so this becomes a problem with the 15 SSID limit in Meraki.
One idea I have to get around this limit is to publish one SSID for all tenants and then assign them into VLANs based on tenant identity. This may be one shared identity between all tenants in one tenant group and then using a RADIUS-based solution ( such as ISE, Packetfence, MS NPS) to assign the tenant users into their correct VLAN.
There are a few constraints though. The solution must be easy to manage as the customer does not have a large technical staff and might rely on non-technical staff to provision new tenants.
The other is that customers will need to be set up in a new directory scheme, so there is no LDAP or AD to integrate with, unless we set up new users on there.
We also need to deploy the authentication solution either in the cloud, for example Azure or the main HQ site, which will be connected via VPN.
Then we ideally need to have a default fallback position if the local site cannot talk to the authentication solution, for example if the VPN goes down.
I hope this makes sense and apologies it this is a bit of a ramble! Thanks in advance for all replies.