EasyPSK for Cisco Networks overview
Give every apartment, room, or unit its own private Wi-Fi bubble on a shared SSID — no per-unit SSIDs, no 802.1X supplicants, just one Pre-Shared Key per Wireless Personal Network.
EasyPSK for Cisco Networks lets you run one building-wide SSID where every apartment, room, or unit gets its own private Wi-Fi bubble. The people sharing a unit share one Pre-Shared Key. Different units can’t see each other at the Wi-Fi layer. A resident you appoint as Group Administrator can rotate the key, invite roommates, and see which of their own devices are connected — all from the Self-Service portal, which feels like their home router.
It is designed for shared-space environments where one SSID, one key per unit (or per person) is the right shape: student housing, co-living, senior living, short-stay rentals, hotels-with-apartments, small-office buildings where every tenant gets a desk-cluster, and venues or fairs where every visitor gets a personal passphrase.
One Service, two delivery methods
Section titled “One Service, two delivery methods”EasyPSK is an umbrella for two ways of delivering the per-unit keys to your Cisco wireless network:
| Variant | Cisco platform | Key delivery | Status |
|---|---|---|---|
| EasyPSK via RADIUS | Cisco Meraki (MR) and Cisco Catalyst 9800 WLC | RADIUS — the platform is the SSID’s RADIUS server; keys resolve at connect time, 100,000+ keys and the service scales horizontally | Available |
| Meraki WPN | Cisco Meraki (MR) only | Dashboard API — Identity PSK without RADIUS, up to 5,000 keys per Meraki network | Available |
EasyPSK via RADIUS is the primary delivery method. It is platform-agnostic (one Context serves both Cisco Meraki and Catalyst 9800), scales past 100,000 keys, and carries the richest group controls. It is created and managed as an EntryPoint Context: start at EasyPSK via RADIUS. Meraki WPN remains available as the Dashboard-API delivery: proprietary to Cisco Meraki, attractive when you want a pure cloud-to-cloud integration with no RADIUS path, and bounded at 5,000 keys per Meraki network.
EasyPSK via RADIUS — the primary delivery
Section titled “EasyPSK via RADIUS — the primary delivery”The platform acts as your SSID’s RADIUS server. The key a device presents at connect time identifies its group, so nothing is pre-provisioned onto the wireless platform and there is no provisioning cap on key count. Groups carry one of three security flavours (Instant, Approved, Dedicated) and a set of group controls: a device cap, time-bound validity, a recurring schedule, and a device block list, plus four-eyes device approval on Approved groups and kiosk self-enrollment where a group creates itself at a resident’s first Self-Service login. The full chapter starts at EasyPSK via RADIUS.
Meraki WPN — the Dashboard API delivery
Section titled “Meraki WPN — the Dashboard API delivery”The Dashboard API delivery is labelled Meraki WPN in the admin. It talks directly to your Cisco Meraki dashboard: no RADIUS server and no on-site hardware.
EasyPSK provisions each unit's Pre-Shared Key directly on Cisco Meraki through the Dashboard API: Identity PSK without RADIUS, up to 5,000 keys per Meraki network. No on-site hardware and no RADIUS server is involved.
The core idea — a Wireless Personal Network per unit
Section titled “The core idea — a Wireless Personal Network per unit”A Wireless Personal Network (WPN) is a Wi-Fi bubble on a shared SSID, scoped to one group of people. In the RADIUS delivery the same concept is simply called a group. In a student-housing scenario, an apartment is one WPN. The roommates sharing it are its Self-Service Users. One of them is the Group Administrator — the resident who owns the passphrase on behalf of the unit.
- All apartments in the building broadcast the same SSID.
- Each apartment has its own Pre-Shared Key.
- Devices in apartment 301 can’t reach devices in apartment 302 at the Wi-Fi layer, even though they’re on the same SSID.
- The Group Administrator rotates the key for their own apartment from the Self-Service portal, without involving you.
Contrast this with a classic shared-PSK SSID (one key across the whole building, rotates for everyone at once) or a per-apartment SSID (airspace pollution, impossible to scale past a dozen units).
Who operates EasyPSK
Section titled “Who operates EasyPSK”Organization administrators configure the Meraki Dashboard integration, create the Wireless Personal Networks (often one per apartment), and invite each unit’s Group Administrator. From that point the Group Administrator manages their own bubble — inviting roommates, rotating the key if it leaks, looking at which devices have joined. You stay out of the per-unit details.
Prerequisites (Meraki WPN)
Section titled “Prerequisites (Meraki WPN)”The RADIUS delivery has its own, lighter prerequisites: see EasyPSK via RADIUS. The points below apply to the Meraki WPN delivery.
Warning
External DHCP required. Meraki WPN works with wireless networks that use an external DHCP service. It does not work with Meraki access-point-assigned DHCP (NAT mode). Confirm your Meraki network hands out leases from a DHCP service you control before onboarding.
You’ll also need:
- A Cisco Meraki dashboard with at least one wireless network running MR-series access points.
- A Meraki Dashboard API key with permission to manage SSIDs, networks, clients, and group policies in that dashboard.
- An SSID (or one you’re willing to convert) configured for Identity PSK without RADIUS in the Meraki dashboard.