How-To: Connect Your Cisco Meraki Network to Keytos Shield

Learn how to securely connect your Cisco Meraki network to Keytos Shield using Cloud RADIUS.

Overview - How to Protect Your Cisco Meraki Network with Cloud RADIUS

Having a single Wi-Fi password for your network is a security nightmare. It’s impossible to know who has access to your network, and it’s nearly impossible to change the password regularly without causing major outages. The best way to secure your Cisco Meraki network is to use WPA-Enterprise with either certificates or individual user accounts for authentication.

To protect your Cisco Meraki network using certificates or Entra ID accounts, you will need a RADIUS server to handle authentication requests. Keytos Shield includes a cloud-based RADIUS-as-a-Service that integrates directly with Entra ID to provide secure authentication for your Cisco Meraki network without needing to manage any RADIUS servers or infrastructure. Simply add Keytos Shield as a RADIUS server in your Cisco Meraki Controller, and your users can log in using either passwordless certificates or their Entra ID username and password.

Prerequisites for Connecting Your Cisco Meraki Network to Keytos Shield

Already completed the onboarding process? You can skip directly to the step-by-step guide

The first step to getting started with Keytos Shield is to create a subscription. This will allow you to access the Keytos Shield portal and begin onboarding your users and devices.

How to Install Keytos Shield and Create a Subscription

It's free to get started and there's no sales call or credit card required

Keytos Shield uses native Entra ID authentication to provide a seamless passwordless experience for your users. Begin by registering the Keytos Shield Entra ID application using the link below. Make sure to use your Global Administrator account (or forward the link to your Global Administrator) to complete the consent process.

Single Click

The easiest way to register the applications is to click the button below while logged in with your Global Administrator account:

Register Keytos Applications

Manual URL

Alternately, you can copy & paste the following URL into your browser. Make sure you are logged in with your Global Administrator account before accessing the link.

https://login.microsoftonline.com/organizations/adminconsent?client_id=2963e596-88f5-43a1-ab17-68b8026c6468&redirect_uri=https://portal.keytos.io/Welcome

You will see a consent screen similar to the one below. Click Accept to register the applications in your tenant.

Keytos Shield uses native Entra ID authentication as shown in the admin consent screen

Single Click

The easiest way to register the applications is to click the button below while logged in with your Global Administrator account:

Register Keytos Applications

Manual URL

Alternately, you can copy & paste the following URL into your browser. Make sure you are logged in with your Global Administrator account before accessing the link.

https://login.microsoftonline.us/organizations/adminconsent?client_id=2cf07322-0273-4052-bd9b-e38c1c433803&redirect_uri=https://portal.keytos.us/Welcome
Keytos Shield uses native Entra ID authentication as shown in the admin consent screen

For more information on these specific permissions and why they are needed, please refer to the Keytos Shield FAQs.

Collapses this section and completes the checkmark.

How to Create Your Keytos Shield Subscription

A Keytos Shield subscription handles permissions, billing, and central configuration for your organization. You can create a subscription directly with us, or through the Azure Marketplace. Both options provide a 1-month free trial, and you can cancel at any time.

To create a Keytos Shield subscription directly through the Shield portal, follow these steps:

  1. Open the Keytos Shield portal in your browser. (US Government Portal).

  2. Under Subscription Name, enter a friendly name for your subscription. (you can always change this later)

  3. Select a Deployment Location for your subscription. This will be your primary region where your Keytos Shield resources will be hosted.

  4. Optionally enter your credit card information. You can click Skip for now if you just want to try out Keytos Shield for free for 1 month and add a payment method later.

    • If you are managed by a MSP or reseller, the credit card form will not be shown, and you can proceed with creating your subscription without entering any payment information.
  5. Check the Terms & Conditions box to agree to the terms of service.

  6. Click Register to create your subscription. It should complete in just a few seconds.

    Get started with a Keytos Shield free trial subscription
  7. You should now see your newly created Keytos Shield subscription endpoint listed under Existing subscriptions:

    Keytos Global Get Endpoint in Existing Subscriptions

We are finishing up our Azure Marketplace review with Microsoft and will have our documentation available soon. In the meantime, please deploy your Keytos Shield subscription directly through the Shield portal.

Collapses this section and completes the checkmark.

Now that you have created a Keytos Shield subscription, you can proceed to onboard your environment to Shield using the onboarding guide.

How to Configure Shield via the Onboarding Guide

The Shield onboarding guide will walk you through the steps to onboard your environment to Shield

It’s easy to get started with the interactive onboarding guide within Keytos Shield. Follow these steps to onboard your environment and configure your network security settings.

  1. Open the Keytos Shield global portal in your browser. (US Government Portal). Make sure to sign in with the same account used to create your Keytos Shield subscription.

  2. Under Existing subscriptions you’ll see your region-specific Keytos Shield endpoint. Open it to access the onboarding guide and start configuring your network security settings.

    Keytos Global Get Endpoint
  3. You should automatically be redirected to the network security onboarding guide on first login. If not, you can manually navigate to it from the left-hand nav bar under Onboarding:

    Onboarding Section

Collapses this section and completes the checkmark.

How To Register the Keytos Entra ID Application (already completed)

Since you have already completed this earlier, the step should be marked as completed. If there was an issue with the consent, refer to Step 1 above to re-consent the application using your global administrator account.

Register the Keytos Entra ID Application

Collapses this section and completes the checkmark.

How To Configure Your Infrastructure and PKI Environment

In step 2, you’ll answer a few questions about your environment and how you want to configure your PKI and MDM settings.

How to Set Up Your PKI in Keytos Shield

Keytos Shield includes a Cloud PKI which will issue your SCEP certificates. If you only have cloud resources and no on-premises PKI, you can rely solely on the Cloud PKI for certificate issuance. If you have an existing on-premises PKI, you can integrate it with Keytos Shield to chain your Shield SCEP CA up to your existing Root CA.

  1. What type of environment do you have?

    • Select Hybrid infrastructure if you have an on-premises Active Directory environment and/or an existing PKI environment that you want to integrate with Keytos Shield.

    • Select Cloud only if you have a cloud-only environment and do not have an on-premises Active Directory or PKI infrastructure. You won’t be asked any further questions about on-premises PKI integration.

      Select Environment Type
  2. Will you use Windows Hello for Business for on-premises resources?

    • Select Yes if you have a hybrid environment and want to use Windows Hello for Business and certificates issued by Keytos Shield to authenticate to your on-premises resources.

    • Select No if you do not plan to use Windows Hello for Business for your on-premises resources.

      Windows Hello for Business
  3. Do you have an existing on-premises PKI?

    • Select Yes if you have an existing on-premises PKI environment and want to integrate it with Keytos Shield.

    • Select No if you do not have an existing on-premises PKI environment or do not want to integrate it with Keytos Shield.

      Existing PKI
  4. Will you use your existing Root CA as your Root CA?

    • Select Yes if you have an existing Root CA and want the certificates issued by Keytos Shield to chain up to it.

    • Select No if you want to use Shield’s Root CA instead of chaining up to your existing Root CA.

      Chain to Root CA
  5. Bring your own Root CA - If you selected Yes to the previous question, follow these steps to bring your own Root CA:

    1. Download the CSR from Keytos Shield.
    2. Submit the CSR to your existing Root CA to generate a certificate.
    3. Once you have the certificate, upload it to Keytos Shield, along with the Root CA certificate.
    Chain to On-Prem Root CA
  6. Which MDMs do you use to manage your devices?

    • Select any Mobile Device Management (MDM) solutions that you use to manage your devices. This will help Keytos Shield configure your SCEP CA correctly to be able to issue certificates via your MDM. You can always add more MDMs later if needed from the Network profiles page.

      Select Your MDMs
  7. Mark as Complete

    • Click Mark as Complete to save your settings and continue to the next step.

Collapses this section and completes the checkmark.

How to Configure Your Shield Network Profile

A Shield network profile defines how your network connects to Shield via RADIUS and/or RadSec. In this step you’ll configure how you plan to connect your network to Keytos Shield.

How to Configure Your Network Profile Basics
  1. Under Network profile name, enter a friendly name for your network profile, such as “Office Network” or “Headquarters”.

    Network Profile Name
  2. Select if you want to use RADIUS or RadSec for network authentication.

How to Configure RADIUS or RadSec

Based on your choice of RADIUS or RadSec, you will need to follow the specific configuration steps for that authentication method. Use the tabs below to view the instructions for each option.

Classic RADIUS is a great option if you want a straightforward and widely supported method for network authentication and you plan to do certificate-based authentication or Entra ID username & password authentication.

  1. Under Add IP addresses, click My IP or manually enter the public IP address for your network that will be sending RADIUS requests to Keytos Shield.

  2. Click Add to save the IP address to your network profile.

  3. Repeat for all your public IP addresses, including any backup IP addresses you may have for redundancy.

    Enter Classic RADIUS IPs

While RadSec is more complex to configure than Classic RADIUS, it is compatible with dynamic IP addresses and offers better security for legacy authentication protocols like PAP, PEAP, and MS-CHAPv2 if you plan to use them on your network.

Note: Make sure your network equipment supports RadSec. If it does not, you will need to use Classic RADIUS instead, or run a local proxy within your network that protects your RADIUS traffic inside an encrypted tunnel (useful if you’re using unencrypted protocols like PAP or MS-CHAPv2).

  1. Under Authorized certificate authorities > Certificate source, select where the certificate authority for your RadSec connection is located. Some APs, such as Meraki, come pre-configured with their own certificate authorities, while others like Unifi require you to provide your own certificate authority.

    • Shield: Select this option if you want to use the certificate authority provided by Keytos Shield to issue RadSec certificates for your network.

    • EZCA: Select this option if you want to use an existing EZCA certificate authority for your RadSec certificates.

    • Local CA: Select this option if you want to use a 3rd party certificate authority for your RadSec certificates.

      Select RadSec Trusted Certificate Authority
  2. (optional) Authorized certificate thumbprints: If you want to trust individual RadSec certificates based on their thumbprints, expand this section and upload your self-signed or third-party certificates.

    Network Profile RadSec Trusted Certificate

Want to protect your legacy authentication protocols like PAP, PEAP, and MS-CHAPv2 but can’t use RadSec? Or want to increase availability + reduce latency for your authentication requests? Running a local server within your network can help achieve these goals.

Keytos Shield comes with a free local RADIUS/RadSec server that you can optionally run within your network to handle authentication requests locally, providing an additional layer of security and control over your network authentication.

To set up a local RADIUS server, first set up RADIUS or RadSec as your primary authentication here in the onboarding flow, and then visit our guide on adding a local Shield RADIUS server to complete the setup.

How to Configure Network Profile Assignment and Optional Settings

Now that you have configured RADIUS or RadSec, the final steps are to choose what users and/or devices will be assigned to this network profile and configure any optional settings.

  1. For Authentication type, select the appropriate option for your network.

    • Device: Select this option if you want to authenticate individual devices on your network.

    • User: Select this option if you want to authenticate users on your network.

      Authentication Certificate Type

    Note: Want to use both? Select your primary authentication type here and complete the onboarding guide, and you can add additional authentication types in the Network profiles page later.

  2. For Profile assignment, either keep Assign to all licenses users selected, or uncheck it and choose the Entra ID user(s) and/or group(s) that you want to assign this network profile to.

    Network Profile Assign Profile
  3. Optionally enable Enable MAC authentication bypass if you want devices to bypass authentication based on their MAC address.

    • If you have a small set of MAC addresses, manually enter them and click Add.

    • If you have a large set of MAC addresses, check the box for Bulk upload addresses and upload a CSV file containing the MAC addresses.

      Network Profile MAC Authentication Bypass
  4. Click Save RADIUS Server to save your network profile and proceed with the configuration.

Collapses this section and completes the checkmark.

How To Add Your Wi-Fi Networks

Now that you have configured your RADIUS server, the next step is to add your Wi-Fi networks to Keytos Shield.

  1. Enter your Wi-Fi network basics:

    • Wi-Fi network name (SSID) - Add your SSID name here. This is case sensitive, so make sure to enter it exactly as it is configured on your network.

    • Wi-Fi encryption - Select the encryption type that matches your Wi-Fi network configuration.

    • Hidden SSID - If your SSID is hidden, enable this option.

    • Connect automatically when in range - Choose if you want your device to connect automatically when in range or not.

      Wi-Fi Network Basics
  2. Select if you want to Enable Keytos Connect for BYOD devices. This allows BYOD devices to connect via the Keytos Connect app without the need for an MDM solution. If you centrally managing your devices via an MDM solution, you can leave this option disabled.

    • If enabled, you can select if all licensed users can connect to this network, or only specific users/groups.

      Enable Keytos Connect
  3. Click Save Wi-Fi network to save your Wi-Fi network configuration and continue to the next step.

Collapses this section and completes the checkmark.

Here is where you will connect your Cisco Meraki to Keytos Shield. Follow the instructions below to complete the network connection process.

Collapses this section and completes the checkmark.

Step-by-Step Guide - How to Connect Your Cisco Meraki Network to Keytos Shield

The following steps will guide you through the process of setting up Cloud RADIUS for your Cisco Meraki network using Keytos Shield.

How to Add Keytos Shield as a RADIUS Server in Cisco Meraki

Now that you have your Keytos Shield subscription and access policy set up, you can add Keytos Shield as a RADIUS server in your Cisco Meraki Controller.

How to Add a Cloud RADIUS Server to a Cisco Meraki Wi-Fi Network

  1. Go to your Meraki Network Controller.

  2. Click on Wireless on the left menu and Select SSIDs.

    How To Enable Cloud RADIUS Meraki Network Settings
  3. If you already have an existing network, click the network name you want to add RADIUS authentication to. (If you don’t have a network yet, click “Show all SSIDs” and click on a disabled network name to edit it. From there, click the “Enabled” button in the SSID Status.)

    How To Enable Cloud RADIUS Meraki Network Settings
  4. Under the Security menu select Enterprise with > my RADIUS server.

    How to Setup Cloud RADIUS Profile in Meraki Network
  5. Scroll down to the RADIUS section. You can keep the default settings for all the other sections or change them to your liking.

    How to Setup Cloud RADIUS Profile in Meraki Network
  6. Now click on the Add server link.

    How to Setup Cloud RADIUS Profile in Meraki Network

How to Get Your RADIUS Server IP Addresses in Keytos Shield for Cisco Meraki RADIUS

The Keytos Shield RADIUS IP addresses are needed for your network controller to communicate with Keytos Shield. You can get them from the onboarding guide or from the network policies page.

If you’re currently going through the onboarding guide, you can find the Keytos Shield RADIUS IP addresses in step 5, Connect your network. Copy one IP from each region, starting with the closest to you.

Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

If you’ve already gone through the onboarding guide previously, you can find the Keytos Shield RADIUS IP addresses directly from the network profiles page.

  1. Navigate to the Keytos Shield Network Policies page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. Copy one of the IP address from the region closest to your network controller (you’ll add the others later).

    Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

How to Add RADIUS Server IP Addresses to Cisco Meraki

Now that you have your RADIUS server IP addresses from Keytos Shield, you can add them to your Cisco Meraki network.

  1. Back in the Meraki Network Network Controller paste the IP address in the Host IP or FQDN field.

  2. In the Auth port field, enter 1812.

    How to Setup Cloud RADIUS Profile in Meraki Network

How to Get Your RADIUS Shared Secret for Cisco Meraki RADIUS

When you added your public IP address to your Keytos Shield policy, a shared secret was automatically generated for you. This shared secret is used to authenticate your network controller (RADIUS client) to the Keytos Shield server.

In step 5, Connect your network, of the Keytos Shield network security onboarding guide the Keytos Shield shared secrets are listed for each IP. Reveal and copy the value from your IP address.

Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted
  1. In the Keytos Shield portal, navigate to the Keytos Shield Network Profiles page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. For your public IP addresses, click the Copy button under the Shared secret column.

    Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted

How to Add the RADIUS Shared Secret to Cisco Meraki

  1. Back in the Meraki Network Controller paste the Shared Secret in the Secret field.

    How to Setup Cloud RADIUS Profile in Meraki Network
  2. If you click Test and enter any username and password, the test will fail because Meraki uses legacy authentication (PEAP-MSCHAPV2) to do the test. However, running the test will tell you whether your Meraki network can connect to Keytos Shield and Meraki can reach Keytos Shield. If Keytos Shield does not respond you may have a firewall rule blocking access to ports 1812 and 1813 or the wrong public IP address is added to Keytos Shield.

    How to Add RADIUS Server for Entra ID in Meraki VPN
  3. Click on Done.

    How to Setup Cloud RADIUS Profile in Meraki Network
  4. Repeat the above steps for one IP address from each region in your Keytos Shield instance for higher availability.

How To Enable RADIUS Testing in Cisco Meraki

  1. Enable Radius testing. This will ensure Meraki tests the connection to the RADIUS servers and selects the best one available.

    How to Setup Cloud RADIUS Profile in Meraki Network

How to Enable RADIUS Accounting in Cisco Meraki

RADIUS Accounting gives you detailed information about each session such as data used, connection time, etc. You can enable RADIUS Accounting in your Meraki Network Controller to send accounting logs to Keytos Shield. From there Keytos Shield can forward the logs to your SIEM and make them available in Audit Logs.

  1. Within the RADIUS Accounting section, add the same Keytos Shield server IP addresses and Shared Secret as you did for the RADIUS Authentication section.
  2. Make sure to use port 1813 for RADIUS Accounting instead of 1812.

How to Configure RADIUS Timeout and Retries in Cisco Meraki

A cloud-based RADIUS server introduces some additional latency compared to an on-premises RADIUS server. To ensure a stable connection with Keytos Shield, we recommend adjusting the advanced RADIUS settings in your Meraki Network Controller as follows:

  1. Scroll down to the Advanced RADIUS section and click on the arrow expand the section.

    How to Setup Cloud RADIUS Profile in Meraki Network
  2. Enter the following settings (these settings are recommended to ensure a stable connection with Keytos Shield):

    • Server timeout to 10 seconds.

    • Retry count to 3 times.

    • RADIUS fallback to Active.

    • EAP Timeout to 30 seconds.

    • EAP max retries to 5 times.

    • EAP identity timeout to 30 seconds.

    • EAP identity retries to 5 times.

    • EAPOL key timeout to 2000 milliseconds.

    • EAPOL key retries to 4 times.

      How to Setup Cloud RADIUS Profile in Meraki Network
  3. If you have setup your Keytos Shield with Filter-ID or VLANs, you can setup the filter ID or VLAN in their respective fields.

  4. Scroll to the bottom and click on Save.

    How to Add RADIUS Server for Entra ID in Meraki Network
  5. Done!

How to Add a Cloud RadSec Server to a Cisco Meraki Wi-Fi Network

  1. Go to your Meraki Network Controller.

  2. Click on Wireless on the left menu and Select SSIDs.

    How To Enable Cloud RADIUS Meraki Network Settings
  3. If you already have an existing network, click the network name you want to add RADIUS authentication to. (If you don’t have a network yet, click “Show all SSIDs” and click on a disabled network name to edit it. From there, click the “Enabled” button in the SSID Status.)

    How To Enable Cloud RADIUS Meraki Network Settings
  4. Under the Security menu select Enterprise with > my RADIUS server.

    How to Setup Cloud RADIUS Profile in Meraki Network
  5. Scroll down to the RADIUS section. You can keep the default settings for all the other sections or change them to your liking.

    How to Setup Cloud RADIUS Profile in Meraki Network
  6. Now click on the Add server link.

    How to Setup Cloud RADIUS Profile in Meraki Network

How to Get Your RADIUS Server IP Addresses in Keytos Shield for Cisco Meraki RadSec

The Keytos Shield RADIUS IP addresses are needed for your network controller to communicate with Keytos Shield. You can get them from the onboarding guide or from the network policies page.

If you’re currently going through the onboarding guide, you can find the Keytos Shield RADIUS IP addresses in step 5, Connect your network. Copy one IP from each region, starting with the closest to you.

Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

If you’ve already gone through the onboarding guide previously, you can find the Keytos Shield RADIUS IP addresses directly from the network profiles page.

  1. Navigate to the Keytos Shield Network Policies page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. Copy one of the IP address from the region closest to your network controller (you’ll add the others later).

    Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

How to Add RADIUS Server IP Addresses to Cisco Meraki for RadSec

  1. Now we will go back to the Meraki Network Network Controller and paste:

    • In the Host IP or FQDN field, enter the copied Server IP address from Keytos Shield.

    • In the Auth port field, enter 2083.

    • In the Secret field, enter radsec.

    • Check the box for RadSec

      How to Setup Cloud RADIUS Profile in Meraki Network
  2. Click on Done.

    How to Setup Cloud RADIUS Profile in Meraki Network
  3. Repeat the above steps for one IP address from each region in your Keytos Shield instance for higher availability.

How to Enable RADIUS Accounting in Cisco Meraki for RadSec

RADIUS Accounting gives you detailed information about each session such as data used, connection time, etc. You can enable RADIUS Accounting in your Meraki Network Controller to send accounting logs to Keytos Shield. From there Keytos Shield can forward the logs to your SIEM and make them available in Audit Logs.

  1. Fill out the RADIUS accounting servers section with:

    • In the Host IP or FQDN field, enter the copied Server IP address from Keytos Shield.

    • In the Auth port field, enter 2083.

    • In the Secret field, enter radsec.

    • Check the box for RadSec

      How to Setup Cloud RADIUS Profile in Meraki Network
  2. Click on Done.

    How to Setup Cloud RADIUS Profile in Meraki Network

How to Enable RADIUS Testing in Cisco Meraki for RadSec

  1. Enable Radius testing. This will ensure Meraki tests the connection to the RADIUS servers and selects the best one available.

    How to Setup Cloud RADIUS Profile in Meraki Network

How to Configure RADIUS Timeout and Retries in Cisco Meraki for RadSec

A cloud-based RADIUS server introduces some additional latency compared to an on-premises RADIUS server. To ensure a stable connection with Keytos Shield, we recommend adjusting the advanced RADIUS settings in your Meraki Network Controller as follows:

  1. Scroll down to the Advanced RADIUS section and click on the arrow expand the section.

    How to Setup Cloud RADIUS Profile in Meraki Network
  2. Enter the following settings (these settings are recommended to ensure a stable connection with Keytos Shield):

    • Server timeout to 10 seconds.

    • Retry count to 3 times.

    • RADIUS fallback to Active.

    • EAP Timeout to 30 seconds.

    • EAP max retries to 5 times.

    • EAP identity timeout to 30 seconds.

    • EAP identity retries to 5 times.

    • EAPOL key timeout to 2000 milliseconds.

    • EAPOL key retries to 4 times.

      How to Setup Cloud RADIUS Profile in Meraki Network
  3. If you have setup your Keytos Shield with Filter-ID or VLANs, you can setup the filter ID or VLAN in their respective fields.

  4. Scroll to the bottom and click on Save.

    How to Add RADIUS Server for Entra ID in Meraki Network
  5. Done!

How to Create the RadSec Trust in Meraki

Now that we have configured the RADIUS server, the next step is to get the certificate from Meraki for our cloud RADIUS to trust your device and add the server certificate so Meraki trusts the cloud RADIUS.

  1. Navigate to the Organization menu and click on Certificates.

    How to Add RADIUS Server for Entra ID in Meraki Network
  2. Navigate to the Certificate tabs and click on RADSEC.

    How to Add RADIUS Server for Entra ID in Meraki Network

How to Get the RadSec CA Certificate from Keytos Shield

The RadSec CA Certificate is used by your network controller to verify the identity of the Keytos Shield RADIUS server when establishing a secure TLS connection. You can download the RadSec CA Certificate directly from the Keytos Shield dashboard.

  1. Navigate to the Keytos Shield Network Profiles page from the left-hand menu.

  2. Click on the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand Network Equipment section.

  4. Click the Download button next the RadSec CA certificate. It should be named something like radsec-ca.cer.

    Keytos Shield Network Policies with the RadSec CA Certificate Download button highlighted

How to Upload the RadSec CA Certificate to Meraki

  1. Go back to the Meraki tab and click on Upload CA Certificate.

    How to Add RADIUS Server for Entra ID in Meraki Network

How to Download the Meraki RadSec CA Certificate

Now that we have uploaded the CA Certificate, we need to download the CA Certificate from Meraki. This is automatically created and lasts 100 years. Don’t worry they are expecting we die before we have to renew it.

  1. Click on Download CA and save the certificate to your computer. Ensure the status is Trusted.

    How to Add RADIUS Server for Entra ID in Meraki Network

How to Upload the Meraki RadSec CA Certificate to Keytos Shield

  1. Go back to the Keytos Shield tab.

  2. At the top of the page, select the Network Profiles tab.

    Keytos Shield Network Policies with the Network Profiles tab highlighted
  3. Navigate to the RadSec (RADIUS TLS) Client Configuration section.

  4. Switch the Certificate Source to Local CA and click on Upload Certificate and select the CA Certificate you downloaded from Meraki.

    How to Add RADIUS Server for Entra ID in Meraki Network
  5. Scroll to the bottom of the policy and click on Save Network Profiles.

  6. Done! Now we have setup the RadSec trust between Meraki and Keytos Shield, you can now connect your devices to the network using certificate authentication.

How to Add a RADIUS Server to a Cisco Meraki Wired Network

  1. Go to your Meraki Network Controller

  2. Click on Security & SD-WAN on the menu and the select Addressing & VLANs

    How to setup RADIUS authentication for wired ethernet authentication in Meraki network
  3. Scroll down to the Per-port VLAN Settings and select the port for which you want to enable authentication. When you click on it a new menu will appear.

    How to setup RADIUS authentication for specific port in Meraki network
  4. In the Configure MX LAN ports change the type to Access and set the Access Policy to 802.1x.

    How to setup RADIUS authentication for specific port in Meraki network

How to Get Your RADIUS Server IP Addresses in Keytos Shield for Cisco Meraki RADIUS

The Keytos Shield RADIUS IP addresses are needed for your network controller to communicate with Keytos Shield. You can get them from the onboarding guide or from the network policies page.

If you’re currently going through the onboarding guide, you can find the Keytos Shield RADIUS IP addresses in step 5, Connect your network. Copy one IP from each region, starting with the closest to you.

Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

If you’ve already gone through the onboarding guide previously, you can find the Keytos Shield RADIUS IP addresses directly from the network profiles page.

  1. Navigate to the Keytos Shield Network Policies page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. Copy one of the IP address from the region closest to your network controller (you’ll add the others later).

    Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

How to Get Your RADIUS Shared Secret for Cisco Meraki RADIUS

When you added your public IP address to your Keytos Shield policy, a shared secret was automatically generated for you. This shared secret is used to authenticate your network controller (RADIUS client) to the Keytos Shield server.

In step 5, Connect your network, of the Keytos Shield network security onboarding guide the Keytos Shield shared secrets are listed for each IP. Reveal and copy the value from your IP address.

Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted
  1. In the Keytos Shield portal, navigate to the Keytos Shield Network Profiles page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. For your public IP addresses, click the Copy button under the Shared secret column.

    Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted

How to Configure a RADIUS Server in a Cisco Meraki Wired Network

  1. Back in the Meraki Network Controller click add radius server.

  2. Enter the RADIUS Server IP in the host field.

  3. In the port field, enter 1812.

  4. In the secret field, enter the Shared Secret you got from Keytos Shield.

    How to setup RADIUS authentication for specific wired port in Meraki network
  5. Repeat the above steps for one IP address from each region in your Keytos Shield instance for higher availability.

    How to setup RADIUS authentication for specific wired port in Meraki network
  6. Click Update to save the RADIUS server settings.

    How to setup RADIUS authentication for specific wired port in Meraki network
  7. Click on Save at the bottom of the page to apply the changes.

    How to setup RADIUS authentication for specific wired port in Meraki network
  8. Done!

How to Configure Cloud RADIUS for Cisco Meraki VPN

  1. Go to your Meraki VPN Controller.

  2. Click on Security & SD-Wan on the left menu and Select Client VPN.

    How To Enable Meraki Client VPN Settings
  3. Make sure that the Client VPN Server is Enabled.

    How To Enable Meraki Client VPN Settings
  4. Enter the Subnet you want to use for your VPN clients.

  5. In the DNS server field, enter the DNS server you want to use for your VPN clients.

  6. In the Shared secret field, enter a shared secret that you will use for your VPN clients.

  7. In the Authentication dropdown, select RADIUS.

    How To Enable Meraki Client VPN Settings
  8. Click on Add a RADIUS server.

    How To Enable Meraki Client VPN Settings

How to Get Your RADIUS Server IP Addresses in Keytos Shield for Cisco Meraki RADIUS

The Keytos Shield RADIUS IP addresses are needed for your network controller to communicate with Keytos Shield. You can get them from the onboarding guide or from the network policies page.

If you’re currently going through the onboarding guide, you can find the Keytos Shield RADIUS IP addresses in step 5, Connect your network. Copy one IP from each region, starting with the closest to you.

Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

If you’ve already gone through the onboarding guide previously, you can find the Keytos Shield RADIUS IP addresses directly from the network profiles page.

  1. Navigate to the Keytos Shield Network Policies page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. Copy one of the IP address from the region closest to your network controller (you’ll add the others later).

    Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

How to Add Keytos Shield RADIUS Server IP Addresses to Cisco Meraki VPN

  1. Navigate back to the Meraki VPN Network Controller

  2. Paste the RADIUS Server IP in the Host field.

  3. In the Port field, enter 1812.

    How to Setup Cloud RADIUS Profile in Meraki VPN

How to Get Your RADIUS Shared Secret to Cisco Meraki VPN

When you added your public IP address to your Keytos Shield policy, a shared secret was automatically generated for you. This shared secret is used to authenticate your network controller (RADIUS client) to the Keytos Shield server.

In step 5, Connect your network, of the Keytos Shield network security onboarding guide the Keytos Shield shared secrets are listed for each IP. Reveal and copy the value from your IP address.

Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted
  1. In the Keytos Shield portal, navigate to the Keytos Shield Network Profiles page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. For your public IP addresses, click the Copy button under the Shared secret column.

    Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted

How to Add the RADIUS Shared Secret to Cisco Meraki VPN

  1. Navigate back to the Meraki VPN Network Controller

  2. In the Secret (not “Shared secret”) field, paste the Shared Secret you copied from Keytos Shield.

    How to Setup Cloud RADIUS Profile in Meraki VPN
  3. Repeat the above steps for one IP address from each region in your Keytos Shield instance for higher availability.

How to Configure RADIUS Timeout in Cisco Meraki VPN

  1. Set the RADIUS timeout to 30 seconds.

  2. Set the Retry Count to 4 times.

  3. Click on Save Changes at the bottom of the page.

    How to Setup Cloud RADIUS Profile in Meraki VPN
  4. Done!

How to Connect Devices to Meraki VPN with Entra ID Authentication

Now that we have setup your Meraki VPN with RADIUS authentication, now your users can follow this guide to create their network password and then use their username and created password to authenticate to the VPN.

Note: These steps show how to configure a VPN manually in Windows but we recommend using an MDM to distribute the VPN settings and make it easier for your users.

  1. Go to your Windows device.

  2. Click on the network icon on the bottom right.

  3. Click on VPN.

  4. Click on More VPN Settings on the bottom left.

  5. Click on Add a VPN.

    How to Add CISCO Meraki VPN in Windows
  6. In the VPN Provider dropdown, select Windows (built-in).

  7. In the Connection Name field, enter a name for your VPN connection.

  8. In the Server Name or Address field, enter the hostname from your Meraki Dashboard or the public IP address of your Meraki VPN.

  9. In the VPN Type dropdown, select L2TP/IPsec with pre-shared key.

  10. In the Pre-shared key field, enter the shared secret you setup in your Meraki VPN.

  11. In the Type of sign-in info dropdown, select Username and password.

  12. Click on Save.

    How to Add CISCO Meraki VPN in Windows for Entra ID Authentication
  13. When you click on Connect, you will be prompted to enter your username and password. Make sure to use a local user account created using the self-service portal as explained above.

    How to Add CISCO Meraki VPN in Windows for Entra ID Authentication
  14. Click on Connect and you will be connected to your Meraki VPN.

Cisco Meraki RADIUS FAQs

Below are some common questions and tips for setting up RADIUS authentication in Cisco Meraki networks.

When setting up RADIUS in Meraki and testing the connection to the RADIUS server, what credentials should I use?

The credentials you use doesn’t really matter, as the authentication will fail anyway since Meraki uses legacy authentication (PEAP-MSCHAPV2) to do the test.

However, running the test will tell you whether your Meraki network can connect to Keytos Shield and if Keytos Shield responds. If Keytos Shield does not respond it is usually caused by two different reasons:

  1. You have a firewall rule blocking access to ports 1812 and 1813.
  2. The wrong public IP address is added to Keytos Shield. Check if the public IP address of your Meraki network is correctly added to the Keytos Shield allowed IP addresses list, and validate you aren’t running a VPN or other advanced network configuration that might change the public IP address.