GX50 Clients Cannot Get Out

Solved
Mendo54
Here to help

GX50 Clients Cannot Get Out

So I have a GX50 that is directly connected to my personal modem Arris sb8200 (ISP is Xfinity). I also have the Meraki GR12 AP connected to the LAN. At some point, I lost connectivity to the internet. My Meraki GX50 firewall can communicate out to the internet but no devices on the LAN can get out. I’ve even started over from scratch and factory reset everything so I’m back at the default vlan ID 1 with a flat 192.168.128.0/16. Laptop plugged into one of the ports gets assigned an IP, can communicate to other devices on the network, can resolve DNS for anything external but cannot reach anything external. 


I’ve quadruple checked all security settings on the firewall to the best of my knowledge and don’t see any setting that would block me from getting out.
 

Any and all thoughts appreciated. 

1 Accepted Solution
Mendo54
Here to help

Update: This issue is now resolved. 

Cause: Unknown

Solution: Create a new site

 

Details:

After many days of back and forth email correspondence with Meraki support, they finally asked that I create a new site and try adding the hardware on that new site within the app. While that was the solution, they could not tell me what the issue is with that original site. To be honest, I feel slightly dumb for not trying that myself. I did try to create a new company as suggested here but it appears that once you register hardware to a company, it’s forever locked to that company and cannot be used elsewhere. You cannot even request that hardware to be removed from the prior company even if you own both the company and hardware. Trust me, I tried.

 

I asked them probably close to a dozen times for them to remove the hardware configuration from my site as I believe the issue is a corrupt configuration that gets pulled down every time the devices connected to the internet. They avoided the request every time. This theory is further proven by the fact that a new site fixed the issue. My guess is that regardless of the hardware serial number or mac address, each site has its own configuration of the hardware stored. This also means that performing a factory reset and the existence of a factory reset button is for comical relief. 

 

One thing that they did say was that my case was very unique. I have to admit, this was one of the worst customer support experiences I’ve had in tech with a vendor. I tried my best to stay professional this whole ordeal but between their tier 1 troubleshooting and sub tier 1 communication skills, I cannot recommend this product to any small business let alone a consumer of any kind. I had more productive support from this community than their actual support. I get that this is not subscription level networking equipment but I feel better support is required when the product does not function at all, the issue lies behind their servers and the hardware is software locked to your company thus preventing resale… 

 

In summary, I’d like to thank everyone in this community for their help. I’m glad this issue is finally resolved but I fear the next time something goes wrong that requires support. 

View solution in original post

12 Replies 12
Xydocq
A model citizen

Hello @Mendo54 

 

It's sad you run into this type of problem with your GX50. You are 1 out of maybe 5 people, who run into this type of problem. Like I did with my GX20 on first setup. Here's my story: Solved: Re: General setup - The Meraki Community

 

I am sure the Meraki Go support team would like to investigate this problem. Please file a support-ticket in that matter.

 

First, I would like to ask you, to leave the settings on the Default VLAN1 as they are. Create a new VLAN on the GX50 as described here: Configuring VLANs in Meraki Go - Cisco Meraki

 

Then configure Port 4 on your GX50 to act in Access mode on the newly created VLAN and connect your laptop to port 4, description on how to do so can be found on the same linked page.

 

Switching Portsettings from Trunk to Access solved my problem, so I hope it will solve yours too.

 

Cheers and good luck

Xydocq
A model citizen

Hi @Mendo54 

 

I've seen your reply on the other topic:

response.png

 

I would like to answer your question here:

 

A Modem is a device, that connects you to the Internet. It modulates and de-modulates the digital signals used on the LAN to analog signals used on the internet.

 

IP adresses in general can be devided into public-IP-addresses and private-IP-addresses. This goes for IPv4 and IPv6, I am only talking about IPv4 here. Class A 10.0.0.0 to 10.255.255.255, Class B 172.16.0.0 to 172.31.255.255 or Class C 192.168.0.0 to 192.168.255.255. Those would be considered private IP ranges. Any other IP address range can be considered public.

 

I assume your ISP is handing out a random public IP and doesn't assign always the same IP to your internet-connection.

 

Now the modem/router from ISP1, I am using at my office, has a small built in router. The public IP gets assigned to the modem/router and is translated to a sigle port when I activate passtrough. The modem/router I use at my house is from another ISP and works differently, this one acts just as a modem and the public IP is directly assigned to the router connected to it.

 

On ISP1 I have to use a static connection because the IP of the modem/router never changes, on ISP2 I am using DHCP-connection because this ISP assignes the IP directly to my router.

 

Your problem might be that GX50 drops untaged traffic.

Xydocq
A model citizen

So let's talk about the VLAN settings and how Access and Trunk are different:

VLAN Configuration.png

Access is used to connect a device that does not depend or doesn't use a VLAN tag to connect to the GX-device.

 

Trunk allows connections for devices that use VLAN like the Meraki Go Switches or Access Points to connect to the GX-device. This allows you to connect a switch with just one LAN cable to the GX but still using different VLANs on the switch or the Access Points.

 

Now in some cases if a Port is set to Trunk mode it drops traffic because the device connected to it, isn't using VLAN tag. So the GX thinks it's a faulty connection, even it is not.

 

This setting can be found at Hardware -> device (GX50) -> SEE ALL PORTS -> Port x -> Settings -> Advanced Settings -> VLAN Configuration

 

The use of different VLANs allowes you to devide your network into different segments. On GX devices VLAN-routing is enabled. This means you can access a device on VLAN2 from VLAN1 or the other way around. You are not able to explore the other VLAN, you have to know the IP-address of the other device. Here you can set Level3 firewall-rules to block or allow traffic between VLANs.  

 

 

Xydocq
A model citizen

Your GX50 is connected to the Internet. So it seems you're spot on on the WAN-setup and you don't have to change anything there.

 

The problem has widely to do, with how you run your local network. Usualy the default Port-Setting (Trunk) runs smoothly, but very very rarely it causes troubles.

 

Once I switched from Trunk to Access it solved all connection problems I had. It became a bit weird after the problem was fixed, because it didn't matter if a port was set to Trunk or Access, it just kept working. The problem is not reblicable. Once fixed it's gone.

 

I am sorry you got confused with my first answer to your post. I should have just told you, to change the port settings on the connections you had trouble with. 

 

 

So after reading your replies, I believe i have the correct settings but still no internet connection. 

firewall gx “internet” configuration is DHCP no vlan tagging - tagging it to any vlan causes it to go into an alerting status. 

I’ve created a new wired network, vlan 2. 192.168.2.0/28

 

I’ve configured port 2 as access and assigned it to vlan 2.

 

my laptop is plugged into port to. It gets assigned an ip address of 192.168.2.2. Flushed dns and can confirm it’s resolving dns but cannot reach the internet

 

IMG_4072.jpeg

IMG_4075.png

IMG_4079.png

IMG_4073.jpeg

Xydocq
A model citizen

From what I can tell, it looks good.

 

Here's one or two things I want you to try.

 

- use ipconfig /all on comand promt, you don't have to post the results but check what it shows as dns

- try to ping 8.8.8.8 from comand promt, does it fail or work?

- also try tracert 8.8.8.8 , does it go thru or does it timeout? 

- kinda last go to the settings page of the new vlan and change dns-servers for the vlan from Upstream to Google DNS

 

repeat the tests and see if there's any difference

 

Keep in mind if you share info, make public ip address, mac-address and other things you don't want people to know unreadable

hidden0
Meraki Alumni (Retired)
Meraki Alumni (Retired)

@Mendo54 I'd love to hear the end of this saga, everything looks good here.

 

Definitely set DNS to "Google DNS" and not to proxy to upstream. After that change to the DHCP settings, be sure to do an ipconfig /release and ipconfig /renew to get the new DNS settings. I'd be personally interested in not only seeing the ping results being successful, but also a dig/nslookup command showing proper name resolution. For example:

nslookup cnn.com

 

This should return the IP address for cnn.com if DNS is working.

 

If ping and DNS is working, but you still can't get to the internet - huh. I wonder if IPv6 is causing an unexpected hard time, you could always try disabling IPv6 outright on your client device to rule out IPv6 (or I guess rule it "in").

Thanks for the reply. I've just posted an update directly to the main post so see what I've done recently.

Mendo54
Here to help

Hey everyone. I just wanted to post a reply to let you know this thread isn’t dead and that the issue still persists. I’ve just been busy with other items. I’ve seen a couple of your recommendations on things to test and respond back with so I will do so when I get back to it which should be sometime next week. I still have an open case with Meraki Support but that’s been significantly less help than this thread. 

Mendo54
Here to help

Update

 

So I’ve been testing and troubleshooting on my side and I think I’ve narrowed down the issue but am unsure of the fix - Jump to final question at the bottom.
 
It seems that when I add the Firewall GX as a hardware to my mobile app, all devices connected to it (wireless AP & laptop) lose access to the internet. I’m able to replicate this consistently. When I remove the hardware device from the mobile app, the firewall cycles and my connected devices regain access to the internet. 
 
Furthermore, when the firewall GX device is not added, my wireless AP (GR12) changes from “alerting” status to “online” status. Before I removed the firewall GX from the app, I configured port 2 to leverage vlan 3 (192.168.3.1/30). Port 2 is where the Wireless AP is plugged into. The wireless AP (GR12) WAS set to vlan 3 DCHP but was not getting an IP so I statically set it to 192.168.3.2 and it came online. 
 
My laptop is also able to reach out to the internet and gets a DHCP address of 192.168.2.2 (this is accurate because the port it's plugged into, port 4, is set to vlan 2 - 192.168.2.1/28)
 
Question: Why would adding my my firewall GX to the mobile app cause my connected devices to lose connectivity to the internet? My theory is that configurations for these devices are stored on Meraki's servers and every time I add the device to the app, it's downloading a corrupt config. I think that because I've already factory reset this thing several times so no configurations are coming from the device itself. 
 
Also, as side note about myself, I'm a Senior Systems Engineer by day so these networking and troubleshooting concepts are very straight forward to me. The only thing that racks my brain is why this Meraki Go solution works the way it does. I guess the fact that the Go is Meraki's cheaper, non-subscription based solution explains why so much of this seems to be managed through their servers but that's also where it seems the shortcomings are. This is for my home setup so I'm not under a whole lot of pressure to get it fixed immediately but I would like to get it resolved since I spent money on it.
Xydocq
A model citizen

This is truly some strange behaviour.

 

There have been a couple of people reporting connection issues with AccessPoints and Switches lately. There might be an issue only Meraki Go support can fix.

 

Not sure if starting from zero with a new account will fix this problem.

 

 

Mendo54
Here to help

Update: This issue is now resolved. 

Cause: Unknown

Solution: Create a new site

 

Details:

After many days of back and forth email correspondence with Meraki support, they finally asked that I create a new site and try adding the hardware on that new site within the app. While that was the solution, they could not tell me what the issue is with that original site. To be honest, I feel slightly dumb for not trying that myself. I did try to create a new company as suggested here but it appears that once you register hardware to a company, it’s forever locked to that company and cannot be used elsewhere. You cannot even request that hardware to be removed from the prior company even if you own both the company and hardware. Trust me, I tried.

 

I asked them probably close to a dozen times for them to remove the hardware configuration from my site as I believe the issue is a corrupt configuration that gets pulled down every time the devices connected to the internet. They avoided the request every time. This theory is further proven by the fact that a new site fixed the issue. My guess is that regardless of the hardware serial number or mac address, each site has its own configuration of the hardware stored. This also means that performing a factory reset and the existence of a factory reset button is for comical relief. 

 

One thing that they did say was that my case was very unique. I have to admit, this was one of the worst customer support experiences I’ve had in tech with a vendor. I tried my best to stay professional this whole ordeal but between their tier 1 troubleshooting and sub tier 1 communication skills, I cannot recommend this product to any small business let alone a consumer of any kind. I had more productive support from this community than their actual support. I get that this is not subscription level networking equipment but I feel better support is required when the product does not function at all, the issue lies behind their servers and the hardware is software locked to your company thus preventing resale… 

 

In summary, I’d like to thank everyone in this community for their help. I’m glad this issue is finally resolved but I fear the next time something goes wrong that requires support. 

Get notified when there are additional replies to this discussion.