Cisco Meraki ClientVPN calling-station-ID change?

Solved
Jacob13
New here

Cisco Meraki ClientVPN calling-station-ID change?

I have an MX configured to use radius authentication for the client VPN and right now it sends "CLIENTVPN" as the calling-station-id. Is there a way to have it send something useful, like the client's IP address instead?

 

Trying to get IP Whitelisting setup via our Radius server for our clientVPN connection but the only external IP that appears to be passed in 'CLIENTVPN'.

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

There is no way to change the Calling-Station-Id in the L2TP/IPsec Client VPN.
The recommendation is to migrate to AnyConnect, which sends more useful information and does not use "CLIENTVPN".

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

4 Replies 4
alemabrahao
Kind of a big deal
Kind of a big deal

Take a look at this.

 

Solved: Modify the Client VPN's CallingStationId to the Client's IP - The Meraki Community

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Jacob13
New here

I see, thanks. I have a ticket open to meraki support to see maybe another field that is passed would contain the info I need. Hopefully we don't have to swap to AnyConnect for this functionality. 

alemabrahao
Kind of a big deal
Kind of a big deal

There is no way to change the Calling-Station-Id in the L2TP/IPsec Client VPN.
The recommendation is to migrate to AnyConnect, which sends more useful information and does not use "CLIENTVPN".

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Jacob13
New here

Ok thanks. Anyconnect isn't a valid option for us at the moment so we will look elsewhere.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels