Skip to main content

Configure your Cisco Meraki MX

Configuration guide for Cisco Meraki MX devices.

S
Written by Stephanie Desveaux
Updated over a month ago

The following document explains how to configure the Wireless Social captive portal service when using a Meraki MX device.

If you do not have a Guest VLAN created, the below instructions explain how to configure this. If you already have this configured, you can skip to Access Control set up steps.

VLAN Configuration

πŸ“Œ Note: This section is to be used when non-Meraki access points are in use to create the Guest Only WiFi network.

⚠️ Important: You must match the SSID VLAN with the VLAN set up in this section.

  1. Go to Security & SD-WAN.

  2. Configure the Deployment Settings with the following:

    • Mode: Routed.

    • Client Tracking: MAC Address.

  3. Now, under the Routing section, click Add VLAN. Configure with the following:

    • VLAN name: e.g. Guest.

    • VLAN ID: your preferred VLAN ID.

    • Group Policy: New Group Policy.

    • New Group: e.g. Guest Group.

  4. Click Next.

  5. Configure the IPv4 Config settings with your chosen IP subnet.

  6. Disable IPv6 set up.

  7. Click Preview to view the settings. If correct, click Update to apply.

Now that your VLAN is created, you can trunk the MX ports to allow traffic with your Guest VLAN through. To do this, follow the below steps:

  1. Click the ports you wish to trunk and then click edit.

  2. Add your Guest VLAN into the Allowed VLANs box.

  3. Click Update to apply.


Access Control

To configure the guest WiFi, please follow the steps below:

  1. Go to Security & SD-WAN and click Access Control under the Configure section.

  2. Choose the VLAN you wish to edit and configure with the following:

    • Under the Network Access section, set the Splash page to Sign-on with my RADIUS server.

    • Enter the following RADIUS for Splash Page settings:

      • Host:

        • Europe: radius1-eu.wireless-social.com

        • Americas: radius1-us.wireless-social.com

          • πŸ“Œ Note: Choose the relevant server for your location.

      • Port: 1812.

      • Secret: Please contact Support.

        • ⚠️ Important: Ensure that there are no spaces before and after the secret.

    • Click Add a Server again and add:

      • Host:

        • Europe: radius2-eu.wireless-social.com

        • Americas: radius2-us.wireless-social.com

          • πŸ“Œ Note: Choose the relevant server for your location.

      • Port: 1812

      • Secret: Please contact Support.

        • ⚠️ Important: Ensure that there are no spaces before and after the secret.

    • Failover policy: Deny Access.

    • Captive portal strength: Block all access until sign-on is complete.

    • Walled Garden: Walled Garden is enabled.

    • Walled Garden ranges: Add all of the following walled garden domains. There may also be other relevant regional accounts if your venue is outside of the UK or US that you will need to add.

Splash Page Configuration

To configure the splash page, please follow the below steps:

  1. Go to Security & SD-WAN and under the Configure section click Splash Page.

  2. Choose the relevant VLAN from the dropdown and then configure with the following settings:

  3. Click Save changes to finish.

πŸ€“ Tip: If you would like to change the frequency of how often your customers see the splash page, you can amend the Splash Frequency setting.

Did this answer your question?