cmr, I have a similar setup to you. Full Meraki stack. Two MX250s security appliances in HA connected to two MS425 switches stacked. I initially set client tracking to "Unique client identifier" which didn't work well. I wasn't able to find clients I knew were online. So, I have switched to "MAC address" tracking. This is working better, but I am still getting duplicate client entries. Typically one off-line client entry showing connected to the MS425 stack and one on-line entry showing connected to the actual downstream switch port. Are you seeing the same? I am wonder if this is do to where I am doing routing. Where are you doing routing? On the MX, MS, or both? I am currently doing routing on both. I have VLANs that require special group policies and firewall rules on the MX250 HA and all other VLANs on the MS425 stack. My thinking is the MS425 stack would be faster at routing internal traffic. Hopefully Meraki can get client tracking working better with the recommended campus design.
... View more