Contact sales
Details

Meraki provides cloud-managed IT solutions, from networking appliances to endpoint management.

This Integration enables the following:

  1. One (or more) Meraki Dashboard(s) can be integrated with a single Cisco XDR tenant using single-click OAuth workflow. This enables the following:

a) XDR Incident Manager view gets mirrored in Meraki Dashboard under Organization -> Security Center -> XDR Incidents

b) Meraki Organization admin can assign and change status of an XDR incident from within the Meraki dashboard, and can pivot to a specific incident in XDR

c) Meraki System Manager networks connect to XDR Asset Insights for providing device attributes

d) XDR Automation workflows support response actions to MX appliances by issuing L3 firewall block rules

  1. Agentless flow on NetFlow records from Meraki MX appliances to Cisco XDR for producing network-based security detections. This agentless path requires MX to be running firmware 19.1 or higher.
Capabilities
Automation
Automatic target creation for Cisco XDR automation
Regions
North America
Europe
Asia-Pacific, Japan & China
Installable workflows

These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.

Cisco Managed
This workflow can be added to your incident response playbook and allows you to get a summary of network splash login attempts for your Cisco Meraki organization's networks.
Cisco Managed
This workflow can be added to your incident response playbook and allows you to get a summary of top appliances by utilization for your Cisco Meraki organization.
Cisco Managed
This workflow can be added to your incident response playbook and allows you to get a summary of top clients by usage for your Cisco Meraki organization.
Cisco Managed
This workflow appears in the pivot menu and allows a user to block an IP address on a Cisco Meraki MX L3 outbound firewall.
Cisco Managed
This workflow can be added to your incident response playbook and allows you to block IP addresses using the L3 outbound firewall on Cisco Meraki MX appliances.
Cisco Managed
This workflow appears in the pivot menu and allows a user to block an IP address on a Cisco Meraki MX L3 outbound firewall (using the selected observable as the rule's destination).
Cisco Managed
This workflow fetches the URLs from a Cisco XDR feed and compares them to the blocked URLs in the Cisco Meraki appliance content filtering configuration.
Configuration details