CIS Cisco Meraki Benchmark

Secure configuration guidelines for Cisco Meraki cloud-managed network infrastructure

v1.0.0 January 2025

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Cisco Meraki cloud-managed network devices. Recommendations cover dashboard administration, network configuration, wireless security, content filtering, VPN settings, and monitoring and alerting.

~90Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1DashboardOrg settings, admin accounts
2NetworkSwitching, routing
3WirelessSSID, rogue AP detection
4FilteringContent, threat protection
5VPNSite-to-site, client VPN
6MonitoringAlerts, syslog, SNMP

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Cisco Meraki deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — Dashboard Administration

▶

1.1 Organization Settings

▶
1.1.1 Ensure Organization Name Is Descriptive (Manual)
L1 Manual
Description

This recommendation verifies that Organization Name Is Descriptive on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Organization Name Is Descriptive. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Organization Name Is Descriptive. Save and apply the changes.

1.1.2 Ensure Two-Factor Authentication Is Required for All Admins (Automated)
L1 Auto
Description

This recommendation ensures that Two-Factor Authentication Is Required for All Admins on the Cisco Meraki cloud-managed network device. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Cisco Meraki cloud-managed network device may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Log in to the Meraki Dashboard and verify that Two-Factor Authentication Is Required for All Admins. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Two-Factor Authentication Is Required for All Admins. Save and apply the changes.

1.1.3 Ensure API Access Is Restricted (Automated)
L2 Auto
Description

This setting ensures that API Access Is Restricted on the Cisco Meraki cloud-managed network device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Cisco Meraki cloud-managed network device is essential for defense in depth.

Audit

Log in to the Meraki Dashboard and verify that API Access Is Restricted. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure API Access Is Restricted. Save and apply the changes.

1.1.4 Ensure Admin Roles Follow Least Privilege (Manual)
L1 Manual
Description

This recommendation verifies that Admin Roles Follow Least Privilege on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Admin Roles Follow Least Privilege. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Admin Roles Follow Least Privilege. Save and apply the changes.

1.2 Admin Account Management

▶
1.2.1 Ensure SAML SSO Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that SAML SSO Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that SAML SSO Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure SAML SSO Is Configured. Save and apply the changes.

1.2.2 Ensure Inactive Admin Accounts Are Removed (Manual)
L1 Manual
Description

This recommendation verifies that Inactive Admin Accounts Are Removed on the Cisco Meraki cloud-managed network device. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Cisco Meraki cloud-managed network device increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Log in to the Meraki Dashboard and verify that Inactive Admin Accounts Are Removed. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Inactive Admin Accounts Are Removed. Save and apply the changes.

1.2.3 Ensure Login IP Restrictions Are Configured (Automated)
L2 Auto
Description

This recommendation verifies that Login IP Restrictions Are Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Login IP Restrictions Are Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Login IP Restrictions Are Configured. Save and apply the changes.

2 — Network Configuration

▶

2.1 Switching

▶
2.1.1 Ensure VLANs Are Properly Segmented (Manual)
L1 Manual
Description

This recommendation verifies that VLANs Are Properly Segmented on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that VLANs Are Properly Segmented. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure VLANs Are Properly Segmented. Save and apply the changes.

2.1.2 Ensure Spanning Tree Protocol Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Spanning Tree Protocol Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Spanning Tree Protocol Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Spanning Tree Protocol Is Configured. Save and apply the changes.

2.1.3 Ensure Port Security Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Port Security Is Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Port Security Is Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Port Security Is Enabled. Save and apply the changes.

2.1.4 Ensure DHCP Snooping Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that DHCP Snooping Is Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that DHCP Snooping Is Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure DHCP Snooping Is Enabled. Save and apply the changes.

2.2 Routing & Addressing

▶
2.2.1 Ensure Static Routes Are Documented and Reviewed (Manual)
L1 Manual
Description

This recommendation verifies that Static Routes Are Documented and Reviewed on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Static Routes Are Documented and Reviewed. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Static Routes Are Documented and Reviewed. Save and apply the changes.

2.2.2 Ensure DHCP Server Scopes Are Properly Configured (Manual)
L1 Manual
Description

This recommendation verifies that DHCP Server Scopes Are Properly Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that DHCP Server Scopes Are Properly Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure DHCP Server Scopes Are Properly Configured. Save and apply the changes.

2.2.3 Ensure DNS Settings Point to Secure Resolvers (Automated)
L1 Auto
Description

This recommendation verifies that DNS Settings Point to Secure Resolvers on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that DNS Settings Point to Secure Resolvers. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure DNS Settings Point to Secure Resolvers. Save and apply the changes.

3 — Wireless Security

▶

3.1 SSID Configuration

▶
3.1.1 Ensure WPA3 or WPA2-Enterprise Is Required (Automated)
L1 Auto
Description

This recommendation ensures that WPA3 or WPA2-Enterprise Is Required on the Cisco Meraki cloud-managed network device. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Cisco Meraki cloud-managed network device may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Log in to the Meraki Dashboard and verify that WPA3 or WPA2-Enterprise Is Required. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure WPA3 or WPA2-Enterprise Is Required. Save and apply the changes.

3.1.2 Ensure Guest SSIDs Are Isolated from Corporate Networks (Automated)
L1 Auto
Description

This recommendation verifies that Guest SSIDs Are Isolated from Corporate Networks on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Guest SSIDs Are Isolated from Corporate Networks. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Guest SSIDs Are Isolated from Corporate Networks. Save and apply the changes.

3.1.3 Ensure SSID Broadcast Suppression Is Reviewed (Manual)
L2 Manual
Description

This recommendation verifies that SSID Broadcast Suppression Is Reviewed on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that SSID Broadcast Suppression Is Reviewed. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure SSID Broadcast Suppression Is Reviewed. Save and apply the changes.

3.1.4 Ensure Band Steering Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that Band Steering Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Band Steering Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Band Steering Is Configured. Save and apply the changes.

3.2 Radio & RF Settings

▶
3.2.1 Ensure Rogue AP Detection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Rogue AP Detection Is Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Rogue AP Detection Is Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Rogue AP Detection Is Enabled. Save and apply the changes.

3.2.2 Ensure Air Marshal Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Air Marshal Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Air Marshal Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Air Marshal Is Configured. Save and apply the changes.

3.2.3 Ensure Wireless Client Isolation Is Enabled for Guest Networks (Automated)
L1 Auto
Description

This recommendation verifies that Wireless Client Isolation Is Enabled for Guest Networks on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Wireless Client Isolation Is Enabled for Guest Networks. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Wireless Client Isolation Is Enabled for Guest Networks. Save and apply the changes.

4 — Content & Threat Filtering

▶

4.1 Content Filtering

▶
4.1.1 Ensure Content Filtering Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Content Filtering Is Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Content Filtering Is Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Content Filtering Is Enabled. Save and apply the changes.

4.1.2 Ensure URL Categorization Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that URL Categorization Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that URL Categorization Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure URL Categorization Is Configured. Save and apply the changes.

4.1.3 Ensure Blocked URL Patterns Are Defined (Manual)
L1 Manual
Description

This setting ensures that Blocked URL Patterns Are Defined on the Cisco Meraki cloud-managed network device. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Cisco Meraki cloud-managed network device is essential for defense in depth.

Audit

Log in to the Meraki Dashboard and verify that Blocked URL Patterns Are Defined. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Blocked URL Patterns Are Defined. Save and apply the changes.

4.2 Threat Protection

▶
4.2.1 Ensure Advanced Malware Protection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Advanced Malware Protection Is Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Advanced Malware Protection Is Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Advanced Malware Protection Is Enabled. Save and apply the changes.

4.2.2 Ensure Intrusion Detection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Intrusion Detection Is Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Intrusion Detection Is Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Intrusion Detection Is Enabled. Save and apply the changes.

4.2.3 Ensure Geo-IP Blocking Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that Geo-IP Blocking Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Geo-IP Blocking Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Geo-IP Blocking Is Configured. Save and apply the changes.

5 — VPN Configuration

▶

5.1 Site-to-Site VPN

▶
5.1.1 Ensure VPN Peers Use Strong Encryption (Automated)
L1 Auto
Description

This recommendation verifies that VPN Peers Use Strong Encryption on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that VPN Peers Use Strong Encryption. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure VPN Peers Use Strong Encryption. Save and apply the changes.

5.1.2 Ensure VPN Subnets Are Properly Defined (Manual)
L1 Manual
Description

This recommendation verifies that VPN Subnets Are Properly Defined on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that VPN Subnets Are Properly Defined. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure VPN Subnets Are Properly Defined. Save and apply the changes.

5.1.3 Ensure Split Tunnel Configuration Is Reviewed (Manual)
L1 Manual
Description

This recommendation verifies that Split Tunnel Configuration Is Reviewed on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Split Tunnel Configuration Is Reviewed. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Split Tunnel Configuration Is Reviewed. Save and apply the changes.

5.2 Client VPN

▶
5.2.1 Ensure Client VPN Uses RADIUS or AD Authentication (Automated)
L1 Auto
Description

This recommendation verifies that Client VPN Uses RADIUS or AD Authentication on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Client VPN Uses RADIUS or AD Authentication. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Client VPN Uses RADIUS or AD Authentication. Save and apply the changes.

5.2.2 Ensure Client VPN Uses AES Encryption (Automated)
L1 Auto
Description

This recommendation verifies that Client VPN Uses AES Encryption on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Client VPN Uses AES Encryption. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Client VPN Uses AES Encryption. Save and apply the changes.

5.2.3 Ensure Client VPN DNS Settings Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Client VPN DNS Settings Are Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Client VPN DNS Settings Are Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Client VPN DNS Settings Are Configured. Save and apply the changes.

6 — Monitoring & Alerting

▶

6.1 Alerts & Notifications

▶
6.1.1 Ensure Alert Profiles Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Alert Profiles Are Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Alert Profiles Are Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Alert Profiles Are Configured. Save and apply the changes.

6.1.2 Ensure Configuration Change Alerts Are Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Configuration Change Alerts Are Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Configuration Change Alerts Are Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Configuration Change Alerts Are Enabled. Save and apply the changes.

6.1.3 Ensure Connectivity Alerts Are Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Connectivity Alerts Are Enabled on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Connectivity Alerts Are Enabled. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Connectivity Alerts Are Enabled. Save and apply the changes.

6.2 Logging & Reporting

▶
6.2.1 Ensure Syslog Server Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Syslog Server Is Configured on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Syslog Server Is Configured. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Syslog Server Is Configured. Save and apply the changes.

6.2.2 Ensure SNMP Is Configured with SNMPv3 (Automated)
L2 Auto
Description

This recommendation verifies that SNMP Is Configured with SNMPv3 on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that SNMP Is Configured with SNMPv3. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure SNMP Is Configured with SNMPv3. Save and apply the changes.

6.2.3 Ensure Change Log Is Reviewed Periodically (Manual)
L1 Manual
Description

This recommendation verifies that Change Log Is Reviewed Periodically on the Cisco Meraki cloud-managed network device. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Cisco Meraki cloud-managed network device vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Meraki Dashboard and verify that Change Log Is Reviewed Periodically. Navigate to the appropriate configuration page and confirm the setting is applied.

Remediation

In the Meraki Dashboard, navigate to the appropriate settings page and configure Change Log Is Reviewed Periodically. Save and apply the changes.