Meraki
Meraki
Hal connects to Cisco Meraki to read each client’s network reality: which IPs are theirs, how their sites connect, and what’s a VPN peer versus a stranger.
What Hal reads:
- Network topology and per-site WAN IPs
- Site-to-site VPN peers
- VLAN structure and device inventory
Why it matters: an “impossible travel” or “unfamiliar IP” alert is only meaningful if you know the client’s real network. Cross-referenced against Meraki, Hal can say this IP is the client’s branch office (close it) or this IP belongs to no site of theirs (escalate it) — instead of guessing.
The event logs, too
Topology is only half of it. Hal reads Meraki’s logs directly — appliance events (DHCP, 802.1X, VPN connectivity), the configuration-change audit trail (who changed what, with old and new values), and IDS/IPS security events — alongside live telemetry like WAN uplink loss and latency, wireless health, and rogue-AP detection. Ask what he can pull for a client and he lays it out.

