> For the complete documentation index, see [llms.txt](https://docs.roamingiq.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.roamingiq.com/network-equipment/access-point-configuration-guides/cisco-meraki.md).

# Cisco Meraki

Please refer to [Cisco Meraki's documentation](https://documentation.meraki.com/MR/Encryption_and_Authentication/IPSK_with_RADIUS_Authentication) for additional information on how to configure VAULT with Cisco Meraki.

### **Configuration Steps Overview**

1. Configure SSID.
2. Configure Access Control.
3. Configure RADIUS.
4. Configure Client IP and VLAN.

### **Configure SSID**

1. Click on “Wireless.”
2. Click on “Configure -> SSID.”

<figure><img src="/files/ZUKwkAld63zUmtZsvQX3" alt=""><figcaption></figcaption></figure>

3. Under the SSID Slot select “Enabled.”
4. Click “Rename” to Enter SSID Name – VAULT.

<figure><img src="/files/BQw6MI35noo27INh7p0r" alt=""><figcaption></figcaption></figure>

5. Click "Save Changes."

### **Configure Access Control**

1. Click “edit settings" next to Access Control.

<figure><img src="/files/Mz7csFdNNGW6risBNUGG" alt=""><figcaption></figcaption></figure>

2. Under Security select “Identity PSK with RADIUS.”
3. Select “Easy PSK” from the drop-down list.

<figure><img src="/files/Z0rp83dmqRNmOP0sdRjU" alt=""><figcaption></figcaption></figure>

4. Wi-Fi Personal Network (WPN) – “Disabled.”
5. WPA encryption – “WPA2 only.”
6. 802.11r – “Disabled.”
7. 802.11w – “Disabled.”
8. Mandatory DHCP – “Disabled.”

<figure><img src="/files/kY8uMbCc4urHPZCZjAMO" alt=""><figcaption></figcaption></figure>

9. Splash page – “Non (direct Access).”

<figure><img src="/files/35srLH8g9Lb3mOAtqZR5" alt=""><figcaption></figcaption></figure>

### **Configure RADIUS**

1. Under RADIUS servers click “Add Server” and enter the following information.
   1. Host IP or FQDN – xx.xx.xx.x&#x20;
   2. Auth port – xxxx
   3. Secret – XXXXXXX
2. Click “Done.”
3. Click “Add Server” to add a Secondary RADIUS server and enter the following information.
   1. Host IP or FQDN – xx.xx.xx.x
   2. Auth port – xxxx&#x20;
   3. Secret – XXXXXXX
4. Click “Done.”
5. Under RADIUS accounting servers Click “Add Server” and enter the following information.
   1. Host IP or FQDN – xx.xx.xx.x
   2. Acct port – xxxx&#x20;
   3. Secret –XXXXXXX
6. Click “Done.”
7. Click “Add Server” to add a Secondary RADIUS server and enter the following information.
   1. Host IP or FQDN – xx.xx.xx.x
   2. Acct port – xxxx&#x20;
   3. Secret – XXXXXXX
8. Click “Done.”
9. Set Accounting interim interval to “30 Minutes.”
10. RADIUS testing – “Disabled.”
11. RADIUS CoA support – “Disabled.”
12. RADIUS CoA support – “Disabled.”
13. Dashboard RADIUS proxy – “Enabled.”
14. Click on “Advanced RADIUS Settings.”
15. Set NAS ID to “Custom.”
16. Enter “Custom” String for NAS ID.
17. All other settings may be left as default or set to Best Practices.

### **Configure** Client IP and VLAN

1. Under Client IP and VLAN select “External DHCP server assigned.”
2. Select “Bridged.”
3. Select “Override VLAN tag” next to RADIUS override.
4. Select “VLAN ID” as VLAN tagging option.
5. Set a DEFAULT VLAN ID (per best Practices).

<figure><img src="/files/HGlHokNOZTlTeeMFzc1X" alt=""><figcaption></figcaption></figure>

6. Click “Save” to complete all changes.
