Skip to content

Meraki

Meraki

Hal connects to Cisco Meraki to read each client’s network reality: which IPs are theirs, how their sites connect, and what’s a VPN peer versus a stranger.

What Hal reads:

  • Network topology and per-site WAN IPs
  • Site-to-site VPN peers
  • VLAN structure and device inventory

Why it matters: an “impossible travel” or “unfamiliar IP” alert is only meaningful if you know the client’s real network. Cross-referenced against Meraki, Hal can say this IP is the client’s branch office (close it) or this IP belongs to no site of theirs (escalate it) — instead of guessing.

Hal checking whether a flagged IP is one of a client’s known Meraki sites before escalating

The event logs, too

Topology is only half of it. Hal reads Meraki’s logs directly — appliance events (DHCP, 802.1X, VPN connectivity), the configuration-change audit trail (who changed what, with old and new values), and IDS/IPS security events — alongside live telemetry like WAN uplink loss and latency, wireless health, and rogue-AP detection. Ask what he can pull for a client and he lays it out.

Hal listing the Meraki event logs and telemetry he can read: appliance events, the configuration-change audit, IDS/IPS security events, uplink health, wireless health, and the Dashboard API request log