Skip to content
Service Integration

Cisco Meraki

Connect a Sign-In Context to Cisco Meraki. Pick a Meraki Deployment Type (MAC-based Access Control, optionally with a managed pre-shared key, or Splash Page via RADIUS Server), then mirror the exact Meraki-Dashboard steps shown inline in the Netgraph admin.

The Cisco Meraki integration lets the Sign In Captive Portal work on Meraki wireless networks without any additional hardware. The two sides meet over RADIUS: Netgraph is the RADIUS server, Meraki is the client. How the two are wired together depends on the Meraki Deployment Type you pick on the Context:

  • MAC-based Access Control (MAB) — Meraki performs MAC authentication against Netgraph’s RADIUS service, and the guest lands on a Cisco ISE-style splash page. Optionally, you can layer a Managed Pre-Shared Key on top so the SSID is encrypted with a venue-wide PSK.
  • Splash Page via RADIUS Server (CoA) — Meraki uses “Sign-on with my RADIUS server”, a Custom Splash URL that points at Netgraph, and (optionally) the Meraki Location and Scanning Integration.
Guest & BYOD devices
Cisco Meraki MR access points · Dashboard
Netgraph Sign In cloud · captive portal

In both deployment types Meraki authenticates against Netgraph's RADIUS service with a splash page in front of the guest: plain RADIUS, with Change of Authorization (CoA) in the Splash Page deployment. No on-site gateway is required.

Configure everything under Service Integration → Meraki in the Sign-In Context admin.

Meraki integration settings
Meraki integration settings.
  • A Cisco Meraki organisation with admin access to the Meraki Network you want Sign In to serve, and at least one SSID available for guest traffic.
  • MR-series Access Points (and Meraki MX security appliances for CoA deployments that include them).
  • The Sign-In Context’s Network Integration includes Cisco Meraki (chosen at Context creation or under Network Settings afterwards).

Open Service Integration → Enabled integrations in the Sign-In Context admin and turn on Meraki Integration Enabled. Save with Update Settings. A new Meraki entry appears in the left nav with Settings and Access Points under it.

Note

If only Meraki integration is used on this Context, leave Service Gateway Enabled off.

Open Service Integration → Meraki → Settings. The Meraki Basic Settings card has one dropdown:

  • MAC-based Access Control — the MAB flow. Cards below the dropdown show the Meraki-Dashboard steps for this deployment and an optional Managed Pre-Shared Key card.
  • Splash Page via RADIUS Server — the CoA flow. A second dropdown (Meraki CoA setup) asks whether the venue has Only Meraki AP, Only Meraki MX, or a Mixed Deployment (both AP and MX).

Save with Update Settings. The cards below change to match.

The MAB flow is the shorter path: Meraki does MAC authentication against Netgraph’s RADIUS service and the guest lands on an ISE Authentication splash page. The Netgraph admin shows you exactly what to configure in the Meraki Dashboard — mirror each value from the Meraki Dashboard configuration card on the right.

  1. Pick MAC-based Access Control

    Under Meraki Basic Settings, pick MAC-based Access Control and save.

  2. Set the RADIUS client secret

    In the Meraki Dashboard configuration card, enter a strong RADIUS client secret and click Update RADIUS client secret. This is the shared credential Meraki will use to reach Netgraph.

  3. Read the generated values

    The same card now shows the RADIUS servers and RADIUS accounting servers tables (host, port, secret per row) and a walled-garden entry. Keep these in view — you’ll paste each into the Meraki Dashboard next.

Navigate to Wireless → Configure → Access control and pick the guest SSID, then:

  1. Security

    Set Security to MAC-based access control (no encryption). Ensure Mandatory DHCP is Enabled.

    The Meraki Access control Security section with MAC-based access control (no encryption) outlined in red
    Set Security to MAC-based access control (no encryption).
    The Mandatory DHCP toggle set to Enabled, outlined in red
    Set Mandatory DHCP to Enabled.
  2. Splash page

    Set Splash page to Cisco Identity Services Engine (ISE) Authentication.

    Netgraph uses the same implementation as Cisco ISE to handle the authentication.

    The Meraki splash page options with Cisco Identity Services Engine (ISE) Authentication outlined in red
    Set Splash page to Cisco Identity Services Engine (ISE) Authentication.
  3. Walled garden

    Open Advanced splash settings, enable Walled garden, and add the domain shown in the Netgraph admin. Select Block all access until sign-on is complete.

    The Walled garden enabled with the captive portal ranges, outlined in red
    Enable the Walled garden and add the captive portal ranges from the settings page.
  4. RADIUS and RADIUS accounting

    Under RADIUS, add each row from the Netgraph admin’s RADIUS servers and RADIUS accounting servers tables — host, port, and secret. Ensure RadSec is disabled, and set an Accounting interim interval (Netgraph recommends ~10 minutes).

    Tip

    If the Accounting Server row is not visible on the Meraki Access Control page, contact Meraki support to enable it on the Organization.

    The Meraki RADIUS servers table with the server row outlined in red
    Add the platform as the RADIUS server: host, port, and the shared secret from the settings page.
    The Meraki RADIUS accounting servers table with the server row outlined in red
    Fill in the RADIUS accounting server too: same host, accounting port, and secret.
  5. Device profiling

    Enable RADIUS Accounting Device Profiling support. Meraki then includes device-profiling information in the RADIUS Accounting-Request messages it sends to the accounting server, which Sign In uses to recognise and classify connected devices.

    The RADIUS Accounting Device Profiling support checkbox enabled, outlined in red
    Enable RADIUS Accounting Device Profiling support.
  6. Called-station-ID

    Under Advanced RADIUS settings, add AP Name to the Called-station-ID category list. Sign In uses this value to identify which Access Point a guest is connected to.

    The Called-station-ID list with AP name added as the third entry, outlined in red
    Add AP name to the Called-station-ID list (it is not there by default).
  7. Save and test

    Save the Meraki Access Control page and connect a test device to the SSID. The Captive Portal should render and a login should appear on the Sign-In Dashboard after sign-in.

    Everything above is what Sign In needs. The customer is free to configure the rest of the SSID (VLAN, bandwidth, IP assignment, scheduling, and so on) however they want their network to behave.

3b. MAB with a Managed Pre-Shared Key (optional)

Section titled “3b. MAB with a Managed Pre-Shared Key (optional)”

When you want the SSID encrypted but still want MAC-based authentication through Netgraph, layer a Managed PSK on top of the MAB flow.

The Setting Up Meraki with Pre-Shared Key and MAC-Based Access Control (optional) card appears below the main settings when Meraki Deployment Type is set to MAC-based Access Control.

  1. Enter the Managed Pre-Shared Key

    Type the PSK into Managed Pre-Shared Key (PSK). The field is masked by default; click the eye icon to reveal while typing.

  2. Save

    Click Update Managed Key. This PSK is what Meraki will provide to guests on the SSID.

Follow the same steps as the plain MAB flow above, with one change:

  • Security: select Identity PSK with RADIUS instead of MAC-based access control (no encryption). Mandatory DHCP stays on.

The rest — ISE Authentication splash, walled garden, RADIUS servers, Called-station-ID — is identical to the plain MAB flow.

The CoA flow uses Meraki’s “Sign-on with my RADIUS server” splash option and a Custom Splash URL that points at Netgraph. The guest sees the Sign In Captive Portal rendered by Netgraph (rather than the ISE-style splash).

  1. Pick Splash Page via RADIUS Server

    Under Meraki Basic Settings, pick Splash Page via RADIUS Server.

  2. Pick the Meraki CoA setup

    Under Meraki CoA setup, pick Only Meraki AP, Only Meraki MX, or Mixed Deployment (both AP and MX) — the Meraki-Dashboard steps shown below adjust to match.

  3. Read the generated values

    Note the values the card now shows: RADIUS servers and accounting servers, walled-garden domain, and the Custom Splash URL value.

  1. Sign-on with my RADIUS server

    Under Wireless → Access control → Splash page, pick my RADIUS server from the Sign-on with dropdown.

  2. Add RADIUS servers

    Under Wireless → Access control → Radius, add the servers and accounting servers from the Netgraph admin. Set Enable data-carrier detect to DCD is disabled.

  3. Enable the walled garden

    Under Wireless → Access control → Walled Garden, add the walled-garden domain the Netgraph admin shows.

  4. Custom Splash URL

    Under Wireless → Splash Page → Custom Splash URL, paste in the Custom Splash URL value from Netgraph.

  5. (Optional) Location and Scanning

    Optional but recommended — see the next section.

Optional: Location and Scanning Integration (CoA only)

Section titled “Optional: Location and Scanning Integration (CoA only)”

Meraki’s Location and Scanning Integration lets Netgraph see which clients are active on which SSID. It is configurable from the Meraki Location and Scanning Integration card on the same Settings page.

  1. Turn on the toggle

    Flip Enable Location and Scanning Integration on in the Netgraph admin.

  2. Activate scanning in the Meraki Dashboard

    Under Network-wide → General → Location and scanning, set Analytics to Analytics enabled and Scanning API to Scanning API enabled.

  3. Exchange the Validator

    Copy the Validator value from the Meraki Dashboard and paste it into Your Meraki Organisation Validator Key in the Netgraph admin.

  4. Add a Post URL in Meraki

    Back in the Meraki Dashboard, Add a Post URL with:

    • POST URL — the value shown in the Netgraph admin.
    • Secret — the scanning secret shown in the Netgraph admin (regeneratable from the button next to it).
    • API VersionV3.
    • Radio TypeWifi.
  5. Set the scanning SSID

    Back in the Netgraph admin, enter the Guest Network Meraki SSID — clients are counted as online when they appear on this SSID.

  6. Save in both places

    Click Update Settings in the Netgraph admin and save the Meraki Dashboard page.

The Meraki Location and Scanning Integration Status card below reports the pipeline state — Waiting for first Meraki Cloud POST while Meraki hasn’t sent anything yet, OK once scanning data is flowing, Warning if posts stop.

Under Service Integration → Meraki → Access Points, the admin shows the Meraki APs registered to this Sign-In Context, a trend chart of Registered Access Points and Access Point License counts, and a Batch Upload button for bulk onboarding.

The Meraki Access Point license registration card on the Settings page has an Enable automatic registration of Access Points toggle — when on, APs register (and claim a license) automatically as they appear. Turn it off to maintain the Access Points list manually.

Access Points are identified by MAC address. That MAC is also what Site-based redirects match on for CoA deployments — assign APs to a Site to steer guests to venue-specific landing pages.

AspectCisco MerakiCisco Service Gateway
HardwareNone extra (Meraki APs already in place)Cisco Catalyst / IOS-XE / SD-WAN router
Who hands out IPsMerakiThe Netgraph cloud (DHCP relayed by the Service Gateway)
How the Captive Portal is reachedMeraki Custom Splash URL (CoA) or ISE splash page (MAB)DHCP Option 114 / probe redirect via the Service Gateway
Deep-packet inspectionNot availableAvailable (Application Visibility)
Best forMeraki-only venuesVenues standardised on Cisco routing

Next