Milrose (all) – Meraki Cisco Secure Client VPN Setup with Entra ID (SAML) & Split Tunneling
SOP #: | 015 |
| Prepared by: | Kwayne James |
Revision Date: | May 12, 2026 |
| Approved by: | Allwyn Griffith |
Purpose/Summary Statement:
This Standard Operating Procedure (SOP) provides instructions for configuring a secure split-tunnel VPN using the Cisco Secure Client on Cisco Meraki firewalls with Microsoft Entra ID (Azure AD) SAML authentication and Multi-Factor Authentication (MFA).
The purpose of this configuration is to allow remote users secure access to internal corporate resources while ensuring general internet traffic remains outside of the corporate VPN tunnel to optimize bandwidth usage and improve user performance.
Scope
IT Infrastructure and Network Administration teams
• Cisco Meraki MX security appliances
• Cisco Secure Client VPN deployments
• Microsoft Entra ID (Azure AD) authentication environments
• Remote users requiring secure access to corporate resources
This SOP covers:
• Cisco Meraki Client VPN configuration
• Cisco Secure Client settings
• Split tunneling configuration
• SAML integration with Microsoft Entra ID
• VPN routing and DNS configuration
Procedure:
Phase 1:Meraki Firewall Configuration
- Log in to the Meraki Dashboard
- Open the Cisco Meraki Dashboard.
- Authenticate using administrator credentials.
2. Navigate to Client VPN Settings
- Navigate to, Security & SD-WAN → Configure → Client VPN
3. Configure Cisco Secure Client Settings
- Under the Cisco Secure Client Settings tab:
- Enable: Enable Cisco Secure Client settings
Client Connection Details
Setting Value
Cisco Secure Client Port 443
Profile Update Enabled
Server Certificate
Setting Value
Server Certificate Generation Method Auto-generated
Note: If using a custom domain such as vpn.milrose.com, configure a custom SSL certificate to prevent browser and client security warnings.
________________________________________
4. Addressing & Routing Configuration
Cisco Secure Client VPN Subnet
• Configure an unused /24 subnet.
• Example: 10.1.20.0/24
⚠️ Important: Do not leave a trailing space after the subnet entry. Meraki will generate a CIDR format validation error.
Custom Nameservers
To optimize split-tunnel internet browsing for remote users, configure public DNS servers:
• 8.8.8.8
• 1.1.1.1
Note: Use internal Domain Controller DNS servers only if internal hostname resolution is required and alternative methods are unavailable.
Client Routing
Configure:
Setting Value
Client Routing Only send traffic going to these destinations
Dynamic Client Routing Disabled
This enables Split Tunneling.
Destination Networks
Enter internal network ranges in CIDR notation, one entry per line.
Example:
• 10.0.0.0/8
• 192.168.0.0/16
________________________________________
Authentication & Policy Configuration
Setting Value
Authentication Type SAML
Session Timeout None
________________________________________
Phase 2: Microsoft Entra ID (SAML) Integration
Important Note
Each Meraki firewall or site should have its own dedicated Enterprise Application within Microsoft Entra ID to ensure authentication requests are routed correctly using the appropriate Reply URL.
________________________________________
1. Access Microsoft Entra ID
Navigate to:
https://entra.microsoft.com
Authenticate with an administrator account.
________________________________________
2. Create Enterprise Application
Navigate to:
Applications → Enterprise Applications → New Application → Create your own application
Select:
• Non-gallery Application
Application Naming
Example:
• Meraki VPN - Miami
Assign the required users and groups to the application.
________________________________________
3. Configure SAML Authentication
Navigate to:
Single sign-on → SAML
Basic SAML Configuration
Setting Example
Identifier (Entity ID) https://vpn.yourdomain.com
Reply URL (ACS URL) https://vpn.yourdomain.com/saml/login
________________________________________
4. Download Federation Metadata XML
• Download the Federation Metadata XML file from Entra ID.
________________________________________
5. Upload Metadata to Meraki
Return to:
Meraki Dashboard → Client VPN
Under the SAML Metadata section:
• Click Upload
• Upload the Federation Metadata XML file
________________________________________
6. Save Configuration
• Click Save Changes at the bottom of the Meraki configuration page.
Accounts / Access:
To perform the steps in this SOP you need:
The following administrative access may be required:
Cisco Meraki Dashboard
Organization or Network Administrator
Microsoft Entra ID
Global Administrator or Application Administrator
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article