Remember that, in many instances (bridged SSIDs) an AP is not routing; traffic from each client will appear with it's own MAC address. Each of those MACs must be in the allow table, in order to work. I'd recommend looking into SecurePort instead, in relation to APs connecting to the LAN: https://documentation.meraki.com/MS/Access_Control/Secure-Port
... View more