Professional Documents
Culture Documents
Meraki Wireless
Under the hood
Seppi Dittli
Consulting Systems Engineer
Meraki – Alpine Region
#158 #5724
You’re in the right session
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
What this session is NOT about!
• No comparisons between Meraki and Aironet Wireless will be made
• Roadmap topics are not going to part of this session
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Agenda
• Introduction
• MX Wireless
• MV Wireless
• MR Product Overview
• MR Wireless
• Location Features
• Packet Captures
• RF Profiles
• Guest Integration with ISE CWA
• MR Firmware Release 26
-
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Wireless on MX / Z
(Security Appliances)
For Your
Reference
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Demo
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
For Your
Reference
MX Wireless Configuration
Up to 4 SSIDs are possible
On / Off
SSID
Where to bridge the traffic
Security Level
Hidden or not
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
For Your
Reference
MX – Open SSID
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
For Your
Reference
MX – WEP SSID
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
For Your
Reference
MX – PSK SSID
Recommended to use
“WPA2 only”
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
For Your
Reference
MX – 802.1x SSID
Meraki Authentication
or
your own Radius server
Recommended to use
“WPA2 only”
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
MR33
MX65W
J L
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
MR33
MX65W
Don’t do it!
J K
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
For Your
Reference
Product Homepage:
https://meraki.cisco.com/products/appliances
MX Sizing Guide:
https://meraki.cisco.com/lib/pdf/meraki_whitepaper_mx_sizing_guide.pdf
Documentation MX Wireless Settings:
https://documentation.meraki.com/MX/Wireless/MX_and_Z1_Wireless_Settings
Combine MX with other Wireless (like MR):
https://documentation.meraki.com/MX/Wireless/Adding_a_Z1_or_Wireless_MX_t
o_a_Wireless_Network_or_Mesh
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Wireless on MV
(Smart Cameras)
For Your
Reference
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Demo
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
For Your
Reference
MV Wireless Configuration
3 2
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
For Your
Reference
MV Wireless Configuration
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
For Your
Reference
MV Wireless Configuration
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
For Your
Reference
MV Wireless Configuration
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
For Your
Reference
MV Wireless Configuration
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
MV Powering Option
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
For Your
Reference
Product Homepage:
https://meraki.cisco.com/products/security-cameras
MV Wireless Configuration Guide:
https://documentation.meraki.com/MV/Installation_Guides/MV_Wireless_Configu
ration_Guide
Low Voltage Power Adapter Datasheet:
https://meraki.cisco.com/lib/pdf/meraki_datasheet_low-voltage-power-adapter.pdf
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
MR Hardware Overview
Meraki Wireless Access Points Overview
= Integrated BLE
MR84
MR53E
4 SS
MR52 MR53
MR42E
3 SS
MR42
MR74
MR70
2 SS
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
MR E Series Smart Antennas
A Series Dipole B Series Dipole C Series Panel Omni
Omni
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
For Your
Reference
Product Homepage:
https://meraki.cisco.com/products/wireless
MR Best Pratices:
https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Mer
aki_Best_Practice_Design/Best_Practice_Design_-_MR_Wireless
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Guest Access
Meraki Wireless Guest Access
Many options possible – too many?
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Meraki Wireless Guest Access
Many options possible – too many?
Authentication-Methods
Captive Portals
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Guest Access
• Popular
I anyhow don’t like it.
• If you do it, you should at least
show a “click-through” splash
page with an AUP
• Very easy to configure
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Change PSK via API
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Demo
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Guest Access
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Built-In Meraki Wireless Guest Access
Options
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Built-In Meraki Wireless Guest Access
Options
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Guest Access
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Guest Access
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
ISE Central Web Access
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Meraki – ISE Integration
https://community.cisco.com/t5/security-
documents/how-to-integrate-meraki-
networks-with-ise/ta-p/3618650
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Other options
Other options include authentication via
• Active Directory
• Facebook
• LDAP
• 3rd Party Credentials (Google)
• SMS (Twilio)
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
For Your
Reference
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Location Features
How we do location with WiFi
RSSI-Radius
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Demo
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
For Your
Reference
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
For Your
Reference
Colors Dots
Dark red areas mean either These are wireless clients.
- there were lots of devices detected Grey = not associated
or Blue = associated
- few devices stayed for a long time
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Background Location Analytics
Connected - yes, this are Wireless Users
Passersby - not connected, but seen at least once
Visitors - not connected, but seen more
x = RSSI of 15 or more to be
considered visitor;
RSSI of 10 or more to maintain it
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
AP Location Scanning Synchronization
New method in MR 26
Software Release < MR 26
Ch2
Ch1
Ch3
Ch1
Ch2
Ch3
Ch1
Ch2
Ch3
lll lll lll
AP1
Ch3
Ch2
Ch1
Ch2
Ch1
Ch3
lll lll
AP2
Ch3
Ch1
Ch2
Ch3
Ch1
Ch2
Ch3
lll lll lll
AP1
Ch2
Ch1
Ch3
Ch1
Ch2
Ch3
Ch1
Ch2
Ch3
lll lll lll
AP2
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
You want more than what Meraki has?
Use APIs!
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
For Your
Reference
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
RF Profiles
More control over your RF environment
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Demo
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
RX-SOP
Receive Start of Packet
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
RX-SOP
Receive Start of Packet
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
For Your
Reference
RF Profiles Documentation:
https://documentation.meraki.com/MR/Radio_Settings/RF_Profiles
RX-SOP Documentation:
https://documentation.meraki.com/MR/Radio_Settings/Receive_Start_of_Packet
_(RX-SOP)
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Wireless Health
Wireless Health
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
For Your
Reference
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Umbrella Integration
The technology behind the integration
Meraki MR Umbrella
Secure internet gateway that
100% cloud-managed wireless
provides the first line of defense
access points
against threats on the internet
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Benefits
• Simplest way to deploy Umbrella
across a wireless network.
• Conveniently enable Umbrella
policies directly in the Meraki
dashboard. +
• Create granular policies on a per-
SSID basis or by using Meraki
group policies.
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Demo
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
For Your
Reference
How it works
Step 1 (Umbrella dashboard) Step 2 (Meraki dashboard)
Copy API key and Secret. Input API key and secret.
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
For Your
Reference
How it works
Step 3 (Meraki dashboard) Step 4
Apply Umbrella policy. That’s it. Seriously, it’s that easy.
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
For Your
Reference
Mandatory DHCP
For Your
Reference
Mandatory DHCP
Enforce clients to use DHCP - disconnect any offending clients
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
For Your
Reference
Protected Ports
For Your
Reference
MS
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Closing
Cisco Webex Teams
Questions?
Use Cisco Webex Teams (formerly Cisco Spark)
to chat with the speaker after the session
How
1 Find this session in the Cisco Events Mobile App
2 Click “Join the Discussion”
3 Install Webex Teams or go directly to the team space
4 Enter messages/questions in the team space
cs.co/ciscolivebot#BRKEWN-2028
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Complete your online
session survey
• Please complete your Online Session
Survey after each session
• Complete 4 Session Surveys & the Overall
Conference Survey (available from
Thursday) to receive your Cisco Live T-
shirt
• All surveys can be completed via the Cisco
Events Mobile App or the Communication
Stations
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Continue Your Education
BRKEWN-2028 © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Thank you