Skip to main content

 

Cisco Meraki Documentation

Secure Router Ports Tab and Port Profiles Configuration Guide

Overview and Purpose

The Secure Router Ports tab and Port Profiles provide a centralized, streamlined way to configure and Monitor appliance ports and manage port settings consistently across networks.   

The new Ports tab displays both LAN and WAN ports in a single view and is available under Security & SD-WAN > Appliance status. Administrators can review port statuses, configuration details, edit individual LAN ports, or select multiple LAN ports to bulk assign profiles. 

Port profiles enable administrators to create standardized LAN port configurations, including port type, VLAN assignments, and PoE settings, and apply them to multiple ports from a single point. This simplifies deployment, reduces repetitive configuration, and helps ensure consistent policy enforcement across networks.   

Together, the Ports tab and Port profiles improve operational efficiency and support scalable port management while preserving the flexibility to configure ports individually when needed. 

Prerequisites and Limitations

The Secure Router Ports tab and Port Profiles have the following prerequisites and limitations: 

Licensing Requirements

Secure Router Ports tab and Port Profiles are available to customers with the base MX License Level:  

  • Subscription: Essentials 

  • Co-Termination Licensing: Enterprise  

Hardware Requirements

Only Cisco 8000-G2-MX Secure Router models running MX OS 26.2.2 and above can utilize the Ports tab and Port Profiles 

Firmware Requirements

The Ports Tab and Port Profiles are available on C8000-G2-MX variants above with the following firmware versions:  

  • MX OS 26.2.2+  

Limitations

Port Profiles on the Secure Routers will have the following limitations the initial Beta release: 

  • Port Profiles is not available in Single LAN or Passthrough mode. VLAN mode is required. 

  • Port Profiles is not supported on network’s that are bound to a template 

  • Access Policies will not be available in Port Profiles 

  • Ports Tab: Access Policies are not supported in Rack mounted C8000-G2-MX models

Configuring Ports on the Ports Tab

The following section will go through the Ports Tab available on the Security & SD-WAN > Appliance status page. The Ports tab re-locates the configuration of MX LAN ports to the Appliance Status page. This tab can also be used to monitor the status of all ports.  

To edit a port's configuration, go through the following steps:  

  1. Click the Number (#) of the LAN port you want to configure 

     

  2. This will bring you to the LAN Port configuration, to change the configuration click "Edit" in the top right corner

     

  3. From the Edit Port window, you can change the configuration of the port or assign a profile as desired
     
     

  1. Click Save and the Ports tab will reflect the newly assigned settings

Be aware that VLANs and their related settings are still configured on the Security & SD-WAN > Addressing and VLANs page.  

Port Profiles Configuration

The steps below will walk you through how to configure and use Port Profiles. In your organization:  

  1. Proceed to the Organization > SmartPorts page  

  1. Click Add Profile in the top right corner of the page 

     

  1. Give your new profile a name. To make your profile available to the Secure Router, check the Organization Wide option. Proceed with the configuration of your desired settings and save when complete: 

  • Port Type: Trunk

    • Native VLAN

    • Allowed VLANs 

If you do not wish to assign a VLAN and “Drop Untagged traffic” instead, leave this setting blank.

VLANs on Port Profiles are not restricted to those configured on the Addressing and VLANs page of your networks. If you assign a profile to a port in a network without the Native or Access VLAN present, the profile will fail to apply. See MX Addressing and VLANs for more information.

  • Peer SGT Enable or Disable 

  • Adaptive Policy group 

  • PoE Enable or Disable 

 

 

  1. Once Saved, the new profile will show on the Port Profiles page. Proceed to the Security & SD-WAN > Appliance status page, and proceed to the Ports Tab

    clipboard_ee42a08cea15d1b40e514abf9bad4a273.png

  2. Select one or more LAN ports you wish to assign a profile and click Assign Profile

     

  3. Select the Port Profile you wish to assign to the ports and click Save

 
 

  1. Once saved, the Ports tab will reflect that the Profile assigned to each port
     

Additional Resources

Supporting Documentation: 

  • Was this article helpful?