Home Blog Cisco Secure Access Integration-Design Best Practices

Cisco Secure Access Integration-Design Best Practices

 2026/06/09   IT & Cyber-Security Solutions   7 visit(s)  3 min to read

Ctelecoms_Character    
 By:Ctelecoms

 Ctelecoms

Ctelecoms-Cisco-Secure-Access-Integration-KSA-Blog

This blog outlines options for deploying Meraki MX SD-WAN with Secure Access to deliver a comprehensive SASE solution. Following these recommended designs will help ensure your network achieves optimal performance and security.

 

Overview 

Today's remote and hybrid workforce, widespread cloud adoption, and increased internet-bound traffic require organizations to deliver secure, optimized access to applications anywhere, on any device. Traditional network models struggle to keep pace, prompting organizations to embrace Secure Access Service Edge (SASE) architectures. By integrating Cisco Meraki SD-WAN with Cisco Secure Access, businesses benefit from unified, cloud-native networking and security, ensuring consistent protection, simplified operations, and a scalable user experience across all locations.

Cisco Meraki and Secure Access stand out with their centralized, cloud-based dashboards, enabling IT teams to deploy, monitor, and manage networks from anywhere—eliminating the need to build more on-premises controllers. The platform integration prioritizes simplicity, scalability, and automation, while offering built-in analytics and security for both enterprise and distributed environments. Managed through the Cisco Meraki dashboard, Meraki MX SD-WAN leverages AutoVPN technology to seamlessly orchestrate and provision Secure Access cloud hubs and tunnels between sites in a spoke-and-hub network.

Dual Fabric Terminology

For clearer guidance, the following special terms describe devices and traffic paths within two SD-WAN fabrics: Traditional Cisco Meraki MX SD-WAN and Cisco SSE Secure Access.

Term

Definition

Cloud Fabric

Transport via cloud hubs using Cisco Secure Access; cloud path or cloud transport

Cloud Spoke

Cisco Meraki spoke connected (enrolled) exclusively to the cloud

Cloud Hub

Cisco Secure Access-enhanced head-ends that provide cloud transport; designated with the CPSC-HUB platform type in Cisco Meraki MX Dashboard

MX (Local) Fabric

Transport via MX hubs, using traditional Cisco Meraki MX SD-WAN tunnels and routing; also referred to as the MX path or MX transport

Local Spoke

MX in spoke mode operating solely in the MX fabric, listing local or enrolled hubs

Local Hub

MX in hub mode that appears in a spoke's hub priority list

Hybrid Spoke

MX spoke that uses both cloud fabric and MX fabric for traffic transport

Hybrid (Enrolled) Hub

MX hub that forms a mesh with other MX hubs while enrolled in the cloud fabric and route peering (hub-to-hub) with the region's pair of cloud hubs

 

 

Cisco SASE Supported Topologies for Meraki

Spoke-Spoke Communication Without Secure Access

In a traditional SD-WAN topology without Secure Access, spokes communicate directly with each other via the MX Hub using AutoVPN tunnels. Traffic between Spoke 1 and Spoke 2 flows through Hub.

Spoke-Spoke Communication With Secure Access (SSE)

When Secure Access SIA is enabled, the topology changes significantly:

  • Spokes connect to Secure Access cloud hubs (e.g., US West 1, US East 1) via Cloud AutoVPN tunnels
  • Direct spoke-spoke communication via MX Hub is disabled by default (path #2)
  • Site-to-site via Cloud Hub is enabled by default (path #1)
  • Support must take action to re-enable site-to-site via MX Hub if needed

 

Why These Changes Occur

When deploying a SASE architecture, it is recommended to inspect East-West traffic between sites to maximize security efficacy. Secure Access integration with Meraki org disables direct Spoke-Spoke communication via MX Hub to ensure all traffic is inspected and policy is applied as intended.

 

Platform Optimization

To improve platform stability and resiliency, the following optimizations are adopted at onboarding for all organizations that enable Meraki Secure Access integration:

  • Dashboard installed routes are removed from all Spokes and Hubs
  • BGP protocol is used as the sole method of providing routes to sites
  • Meraki Hubs are prevented from sharing Spoke routes they learned toward other Spokes
  • Cloud Spokes traffic to any other sites prefers the cloud path

 

Connectivity Path Matrix

Connectivity Path

Cloud Spoke

Hybrid Spoke

Local Spoke

Hybrid Hub

Local Hub

Cloud Spoke

Cloud

Cloud

X

Cloud

X

Hybrid Spoke

Cloud

Cloud

X

Local *

Local *

Local Spoke

X

X

Local *

Local *

Local *

* MX Hub (Hybrid or Local) must be configured on a Spoke to enable direct local-path access to its prefixes.

Note: Meraki Hubs form a mesh and communicate using their Local connectivity path.

 

Scale of Sites and Routes

Metric

Standard

Reduced Routing

Max Enrolled Sites

1,000

2,500

Max Routing Prefixes per Site

10

28

Configuration

Full iBGP routes

Default route only


  • For quicker convergence with Cloud Hubs, Spoke sites can be configured to receive only a default route, bypassing specific iBGP route prefixes
  • MX-advertised prefixes encompass local subnets, eBGP-learned routes, and defined static routes
  • Cloud and Hybrid Spokes will receive a default route and specific routes known by the Cloud Hubs

 

Early Access Limitations

  • Organizations deploying Design B (Hybrid Spokes with Hybrid and Cloud Hubs) can accommodate a maximum of 2 MX Hybrid Hubs
  • For organizations using a small number of Sites, up to 10 MX Hybrid Hubs can be enrolled
  • The Sites UI displays a warning if 2-10 hubs are enrolled and will prevent enrollment of more than 10 MX hubs

 

The integration fundamentally changes traffic flow by forcing East-West traffic through Secure Access cloud hubs for inspection, while disabling traditional direct spoke-to-spoke paths via MX hubs by default. This ensures consistent security policy enforcement across all site-to-site communications.






Search the Blog

Subscribe Blog

Solutions

capling-icon

Computing & Hyper-converged Infrastructure Solutions

Upgrade your IT to be as agile and efficient ...

security-icon

IT & Cyber-Security Solutions

Best-in-class cyber security solutions to ...

microsoft-icon

Microsoft Cloud Solutions

Explore Ctelecoms extensive selection of ...

capling-icon

Datacenter Solutions

Solve issues, streamline operations, promote ...

backup-icon

Cloud Backup & Disaster Recovery Solutions

Keep your data, apps, emails and operations ...

networking-icon

Unified Communications & Networking Solutions

Ensure you are securely connected with all ...

meraki-icon

Meraki Networking Solutions

Quickly deploy a reliable, secure, cloud-managed ...