Learn how to onboard Cisco Meraki MX Devices for Cisco Meraki environments so the device or service is available for management.
This chapter provides steps to onboard Cisco Meraki MX device.
Cisco Security Cloud Control: Cisco Meraki Management
Learn how to onboard Cisco Meraki MX Devices for Cisco Meraki environments so the device or service is available for management.
This chapter provides steps to onboard Cisco Meraki MX device.
MX devices can be managed by both Security Cloud Control and the Meraki dashboard. Security Cloud Control deploys configuration changes to the Meraki dashboard. The dashboard then securely deploys the configuration to the device.
For information about connecting Security Cloud Control to your managed devices, refer to Allow inbound access for direct cloud connectivity.
You must first register the Meraki MX in the Meraki dashboard. Without access to the Meraki dashboard, your organization will not be recognized by the Meraki cloud. As a result, you will not be able to generate an API token to onboard your device.
Security Cloud Control converts invalid CIDR prefix notation IP addresses and IP address ranges to valid form by setting all bits associated with the host to zero.
Onboarding Meraki MX devices or templates no longer requires a connection through a Secure Device Connector (SDC). If you have Meraki MX devices that were previously onboarded and connect to Security Cloud Control using an SDC, their connection will continue to work. If you remove and re-onboard the device or update its connection credentials, the connection will stop working.
MX devices do not need to be connected to the Meraki cloud to be managed by Security Cloud Control. If an MX device has never connected to the cloud, the device connectivity is listed as unreachable. This status is normal and does not affect your ability to manage the device or deploy policies to the device.
When you onboard a Meraki MX device, you must generate a Meraki API key. This key lets the dashboard authenticate your request so you can securely onboard the device. For more information on generating and retrieving a Meraki API key, refer to Generate and Retrieve Meraki API Key.
Onboard a Meraki device to Security Cloud Control using the API key.
Use this procedure to enable Security Cloud Control access to the Meraki dashboard with API access:
Use this procedure to onboard a Cisco Meraki device.
Meraki templates help manage multiple locations or networks using a single policy. You can manage these templates using both Security Cloud Control and the Meraki dashboard. Security Cloud Control deploys configuration changes to the Meraki dashboard, and the dashboard then securely deploys the configuration to the template. For more information about how Security Cloud Control communicates with Meraki.
To onboard a template to Security Cloud Control, you must first create a template in the Meraki dashboard. Without access to the Meraki dashboard, the Meraki cloud will not recognize your organization, and you will not be able to generate an API token for your device. In the Meraki dashboard, click . For more information, refer to Managing Multiple Networks with Configuration Templates.
You must complete these three steps to onboard a Meraki template.
Create a template network in the Meraki dashboard. For more information about Meraki template best practices, refer to Meraki Templates Best Practices.
Generate and Retrieve Meraki API Key. When you onboard a Meraki template, you must generate a Meraki API key. Use the key to authenticate the dashboard and securely onboard a device.
Onboard a Meraki Template to Security Cloud Control using the key.
Use this procedure to enable Security Cloud Control access to the Meraki dashboard with API access:
Use this procedure to onboard a Meraki template.
If you generate a new API key from the Meraki dashboard, you must update the connection credentials in Security Cloud Control Firewall Management.
Security Cloud Control Firewall Management does not allow you to update the connection credentials for the device itself. If necessary, manually refresh the API key in the Meraki dashboard. You must manually update the API key in the Security Cloud Control Firewall Management UI to update the credentials and restore communication.
If Security Cloud Control fails to sync the device, the connectivity status in Security Cloud Control may show "Invalid Credentials." In this situation, you may have tried to use an API key. Confirm the API key for the selected Meraki MX is correct.
Use this procedure to update the credentials for a Meraki MX device:
From the Security Cloud Control Home page, click Firewall.
Choose .
Click the Devices tab and then click the Meraki tab.
Select the Meraki MX whose connection credentials you want to update.
In the Device Actions pane, click Update Credentials.
Enter the API key Security Cloud Control Firewall Management uses to log into the device, and click Update. This API key matches the credential that you used to onboard the Meraki MX unless you changed it. These changes do not require deployment to the device.
Follow these steps to delete a device from Security Cloud Control Firewall Management: