Skip to content
Deployment

Cisco Meraki

Cisco Meraki is the one integration path where Sign In needs no equipment at the site. There is no Service Gateway to install: the Meraki access points authenticate against the platform over RADIUS, and the captive portal is served from the cloud.

Guest & BYOD devices
Cisco Meraki MR access points · Dashboard
Netgraph Sign In cloud · captive portal

Both deployment types use plain RADIUS with a splash page in front of the guest. Neither uses the Meraki Dashboard API, and neither uses RadSec.

The integration is configured as one of two types, chosen per Sign-In context. They differ in how the guest reaches the portal and in what Meraki has to be told.

MAC-based Access ControlSplash Page via RADIUS Server
Meraki settingMAC-based access controlSign-on with my RADIUS server
How the guest arrivesMeraki authenticates the device by MAC against the platform, and the guest lands on a Cisco ISE-style splash pageMeraki redirects to a Custom Splash URL pointing at the platform
Change of AuthorizationNot usedUsed, to move the session to its granted access after sign-in
Encrypted SSIDOptional Managed Pre-Shared Key, giving the SSID a venue-wide keyNot applicable
SuitsThe shorter path, and venues that want the SSID encryptedVenues that want the portal experience driven from the platform, including Meraki MX deployments

For the Splash Page type, the platform also asks how the venue is built: only Meraki access points, only Meraki MX security appliances, or a mixed deployment with both. The answer changes what has to be configured in the Meraki Dashboard.

MAC authentication for devices without a user

Section titled “MAC authentication for devices without a user”

MAC-based Access Control is not only a guest path. A device’s MAC address can be associated with a policy in the platform so it is authenticated with no user interaction at all, which is what IoT equipment, printers and other headless gear need. The same RADIUS integration carries it, so a venue does not need a second SSID or a second integration for its devices.

ItemRequirement
Meraki organisationAdmin access to the Meraki network Sign In will serve, and at least one SSID available for guest traffic
HardwareMR-series access points, plus Meraki MX security appliances where the deployment includes them
RADIUSReachability from Meraki to the platform’s RADIUS authentication and accounting endpoints, with the context’s RADIUS client secret
Walled gardenThe captive portal address ranges allowed through before the guest has signed in
Context settingThe Sign-In context’s network integration set to Cisco Meraki, either when the context is created or afterwards

It does not use the Meraki Dashboard API, so it is not the same mechanism as EasyPSK for Cisco Networks in its Wireless Personal Network form, which does.

It does not use RadSec. The RADIUS path is plain RADIUS, and where a private path is required it runs over a Service Connector rather than over the public internet.

It does not place equipment at the site. If the venue needs local DHCP, DNS or routing served by the integration, that is the Cisco Service Gateway path instead.

Next