I'm note sure Meraki supports monitor-mode or partial acces mode like catalysts do. However if you're using MS210 or higher and running beta you could get access to the new support for filter-ID attribute. Then you could allow the client before DHCP profiling but apply an ACL through filter-ID (uses a Meraki group policy) that only allows UDP/67 and 68. Then trigger a CoA with a new authorization allowing full access.
... View more