Hi @BrianChambers, The KB you linked is actually a very good step-by-step guide to get you started! @PhilipDAth is correct that you do not need multiple subnets for this to work, just as long as you have the matching subnets configured on the AD side. For the certificate, we would recommend that you use a Certificate Authority (CA) signed certificate as it is more secure and is considered best practice. Self-signed certificate can also easily be configured via IIS if a CA signed certificate is not available. I would also recommend reach out to Meraki Support (via Help > Get Help on dashboard) if you run into any specific issue or have specific question about the setup, they will be able to help you validate any configuration from the dashboard side. Cheers, -Alex
... View more