You are trying to apply a WLC design philosophy to Meraki - and it is going to cause you grief. The MX does not support DNS re-write. On the whole you can not do policy routing. However, as long as the traffic is going out a WAN interface, you can specify a flow preference like this: On the whole, I see no point in using Cisco ISE for guest portal processing. The built in capabilities of Meraki kit is very powerful, and Cisco ISE does nothing but add additional complexity. If you want to do things the easy way, configure the guest portal completely inside of Meraki; drop the guests into a VLAN (don't use the VPN option) and then transport that VPN to the Internet.
... View more