SOP 015 - Milrose (all) – Meraki Cisco Secure Client VPN Setup with Entra ID (SAML) & Split Tunneling

Created by Allwyn, Modified on Fri, 18 Sep at 9:35 AM by Allwyn

Milrose (all) – Meraki Cisco Secure Client VPN Setup with Entra ID (SAML) & Split Tunneling

SOP #:

015

 

Prepared by:

Kwayne James

Revision Date:

May 12, 2026

 

Approved by:

Allwyn Griffith

 

 

Purpose/Summary Statement:

This Standard Operating Procedure (SOP) provides instructions for configuring a secure split-tunnel VPN using the Cisco Secure Client on Cisco Meraki firewalls with Microsoft Entra ID (Azure AD) SAML authentication and Multi-Factor Authentication (MFA).

The purpose of this configuration is to allow remote users secure access to internal corporate resources while ensuring general internet traffic remains outside of the corporate VPN tunnel to optimize bandwidth usage and improve user performance.

 

 

Scope

IT Infrastructure and Network Administration teams

•              Cisco Meraki MX security appliances

•              Cisco Secure Client VPN deployments

•              Microsoft Entra ID (Azure AD) authentication environments

•              Remote users requiring secure access to corporate resources

This SOP covers:

•              Cisco Meraki Client VPN configuration

•              Cisco Secure Client settings

•              Split tunneling configuration

•              SAML integration with Microsoft Entra ID

•              VPN routing and DNS configuration

 

 

Procedure: 

Phase 1:Meraki Firewall Configuration

  • Log in to the Meraki Dashboard
  • Open the Cisco Meraki Dashboard.
  • Authenticate using administrator credentials.

2. Navigate to Client VPN Settings

  • Navigate to, Security & SD-WAN → Configure → Client VPN

3. Configure Cisco Secure Client Settings

  • Under the Cisco Secure Client Settings tab:
  • Enable: Enable Cisco Secure Client settings

Client Connection Details

Setting Value

Cisco Secure Client Port             443

Profile Update  Enabled

Server Certificate

Setting Value

Server Certificate Generation Method Auto-generated

Note: If using a custom domain such as vpn.milrose.com, configure a custom SSL certificate to prevent browser and client security warnings.

________________________________________

4. Addressing & Routing Configuration

Cisco Secure Client VPN Subnet

•              Configure an unused /24 subnet.

•              Example: 10.1.20.0/24

⚠️ Important: Do not leave a trailing space after the subnet entry. Meraki will generate a CIDR format validation error.

Custom Nameservers

To optimize split-tunnel internet browsing for remote users, configure public DNS servers:

•              8.8.8.8

•              1.1.1.1

Note: Use internal Domain Controller DNS servers only if internal hostname resolution is required and alternative methods are unavailable.

Client Routing

Configure:

Setting Value

Client Routing  Only send traffic going to these destinations

Dynamic Client Routing              Disabled

This enables Split Tunneling.

Destination Networks

Enter internal network ranges in CIDR notation, one entry per line.

Example:

•              10.0.0.0/8

•              192.168.0.0/16

________________________________________

Authentication & Policy Configuration

Setting Value

Authentication Type     SAML

Session Timeout             None

________________________________________

Phase 2: Microsoft Entra ID (SAML) Integration

Important Note

Each Meraki firewall or site should have its own dedicated Enterprise Application within Microsoft Entra ID to ensure authentication requests are routed correctly using the appropriate Reply URL.

________________________________________

1. Access Microsoft Entra ID

Navigate to:

https://entra.microsoft.com

Authenticate with an administrator account.

________________________________________

2. Create Enterprise Application

Navigate to:

Applications → Enterprise Applications → New Application → Create your own application

Select:

•              Non-gallery Application

Application Naming

Example:

•              Meraki VPN - Miami

Assign the required users and groups to the application.

________________________________________

3. Configure SAML Authentication

Navigate to:

Single sign-on → SAML

Basic SAML Configuration

Setting Example

Identifier (Entity ID)        https://vpn.yourdomain.com

Reply URL (ACS URL)    https://vpn.yourdomain.com/saml/login

________________________________________

4. Download Federation Metadata XML

•              Download the Federation Metadata XML file from Entra ID.

________________________________________

5. Upload Metadata to Meraki

Return to:

Meraki Dashboard → Client VPN

Under the SAML Metadata section:

•              Click Upload

•              Upload the Federation Metadata XML file

________________________________________

6. Save Configuration

•              Click Save Changes at the bottom of the Meraki configuration page.

 

Accounts / Access:

To perform the steps in this SOP you need:

The following administrative access may be required:

Cisco Meraki Dashboard            

Organization or Network Administrator

Microsoft Entra ID          

Global Administrator or Application Administrator

 

 

 

 

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article