Traffic Shaping based op AP tag

JeroenVercoulen
Getting noticed

Traffic Shaping based op AP tag

We have several stores in our environment that use Guest Wi-Fi. We want the limit the per client bandwith usage if the bandwith in the store is not sufficient. At the moment we create at the MX level 6 vlans with local routed subnets. Each of those subnets has specific client bandwith limit applied at the MX level. We Use the Guest SSID with VLAN tagging based op AP tag. Based on the tag of the store AP the client in placed in 1 of the vlans with the bandwith limit applied.

 

I hate to create six subnets to accommodate this. I would say it works as we expect it to, but I would like to know and think there would be a better solution. Preferably only 1 subnet and based on the AP tag for example the correct limits are applied.

 

I could also imagine to create 6 identical SSID's with Availability enabled based on the AP tag and then create per SSID the bandwith limitations. What are you're thoughts about this? 

3 Replies 3
JeroenVercoulen
Getting noticed

I can also imagine configuring it with Meraki Workflows based on a specific tag somewhere

alemabrahao
Kind of a big deal
Kind of a big deal

MR doesn’t have per AP tag bandwidth limits for a single SSID. If you must keep a single subnet and apply different per client caps based on AP tag, you’d need a policy engine that can evaluate AP location and apply per client limits accordingly.

MR supports per user bandwidth via RADIUS attributes. If your guest flow uses RADIUS, you can return a bandwidth profile per user. That’s not per AP tag, but you could combine AP group logic in the RADIUS policy to assign different caps based on where they associate.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

Personally, I would configure per-user and SSID bandwidth limits on the Guest SSID on the MRs, and not on the MX.  It won't be perfect, but MUCH easier to manage.

https://documentation.meraki.com/Wireless/Operate_and_Maintain/How_Tos/Firewall_and_Traffic_Shaping/...

 

 

For example, let's say you have a 100Mb/s connection.  Limit the guest Wi-Fi to a total of 50 MB/s of bandwidth, and apply a per-user limit of 10 MB/s.

PhilipDAth_0-1768161199830.png

 

 

 

Get notified when there are additional replies to this discussion.