Hi, I have got a task to provide a solution to customer to detect (and possibly block) rogue devices that are connected to the network involving Meraki switches? Customer has several ports that are internet only, which we could ignore. But for production ports, how do we lock those down or at least alert when a rogue device is connected? As far as I know, we have the following options available on Meraki switch to enhance port security - - Port schedule - disables/enable port based on a schedule - Access policy which involves Open, MAC allow list, Sticky MAC allow list and User-defined access policy - includes 802.1x authentication(looks like the best option) - STP Guard which involves Root guard, BPDU guard and Loop guard - Trusted DAI - protects networks against man-in-the-middle ARP spoofing attacks - UDLD Need expert guidance on this.
... View more