You could create a group policy on the z3 vlan with a deny any any. Then you can add the mac of the avaya phone to a whitelist/allow list. https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Block_Listing_and_Allow_Listing_Clients Or assign a second group policy to that client without or with restricted firewall rules. https://documentation.meraki.com/General_Administration/Tools_and_Troubleshooting/Troubleshooting_Group_Policies#What_is_the_order_of_priority_for_Group_Policies.3F Other option is using port authentication https://documentation.meraki.com/MX/Access_Control_and_Splash_Page/MX_Access_Policies_(802.1X)
... View more