Dear Experts, Soliciting some opinions: SSID setup: We basically have a set of two groups, Student and Staff. Students do not need access to anything else other than the Internet throughout the campus. Is it recommended to go with two separate SSIDS in this scenario? School-staff, school-students Using RADIUS Separate VLAN for students OR, if we are going the RADIUS and VLAN route anyways, maybe just do group based VLAN assignments and keep SSID to one? Readin through this, it seems it's always better to reduce SSIDs? https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/Multi-SSID_Deployment_Considerations BYOD: What is the best approach. We want everyone to use their unique credentials (AD/RADIUS) Is it possible to get the login prompt (windows/Mac) when they connect their perosnal machines (non-domain joined) to ethernet (Meraki switches) What about their routers (if any) and other devices such as Apple watch etc.? Machine Auth: For domain joined machines, I see here that it's possible to do machine authentication because we don't want any login prompts https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_with_WPA2-Enterprise I couldn't find any detailed documentation for Machine auth in Meraki docs, any recommendations? Lastly, if I want to achieve RADIUS failover, according to this: https://documentation.meraki.com/MR/MR_Splash_Page/RADIUS_Failover_and_Retry_Details All I need to do is setup two RADIUS server with identical configuration, and then add servers>strict policy? Thanks!
... View more