Clients showing incorrect public IP

DeweyL
Comes here often

Clients showing incorrect public IP

Hi, I'm fairly new to the meraki environment.

 

I have a very basic network setup for testing, 1 MX68, 1 24p MS210, and 1 MR33.  Have basic routing setup with addressing mode set to Routed with a single LAN configured.  Static IPs are all setup correctly.  We have not cofigured any VPN's or anything other than a basic network.

 

The issue that I'm having is no matter what settings I change and any number of appliance reboots, my public ip shows incorrect and always on a Paradise Network in either Los Angeles or Houston (we are in Colorado).

 

Is there a setting that I'm missing?

9 Replies 9
jdsilva
Kind of a big deal

What are you using to determine the location? 

 

What are you looking at to determine that your IP is incorrect?

DeweyL
Comes here often

Google "whats my ip".  We also use Azure AD/Intune with Conditional access (based on public IP).  When I attempt to connect to any O365 or Azure products the MFA server and risk assessment of my account go haywire due to the unrecognized IP addresses and the "impossible travel" that is taking place.

jdsilva
Kind of a big deal

I agree with @NolanHerring in that all the MX is going to do is DHCP an IP, and use whatever its given. The fact that you have Internet access at all would indicate that the DHCP between the MX and your ISP is working correctly. 


As for the IP itself, you can contact your ISP and ask them why the address you're receiving is listed as a different geographic region, but I suspect they'll tell you to go pound sand. As long as they're using their IP space they can use it however they like, and Internet services that attempt to locate you geographically are the responsibility of those service owners, not of your ISP. 

 

An interesting question is does the IP that Google says you are using match the IP on your MX WAN port? If those don't match then you're being NAT'd somewhere. That could also be a question to your ISP.

DeweyL
Comes here often

We decided to reboot all devices sequentially down the line. After they all came back up, the public IP was showing correctly.  However the issue presented itself again (and was noticed) by switching from our production network to the meraki test network. If we reboot the computers and they come back up with the primary network as Meraki, they get the correct addressing.  However if we switch to a different network and then switch back to our Meraki network, we get the issue stated above.

 

To answer your last question, the google ip vs the MX WAN port do not match up when this occurs. 

 

Not exactly sure why thats occurring but definitely something I'll have to watch for.

BrechtSchamp
Kind of a big deal

I wonder if this is a proxy issue.

 

What may be happening is that on your Meraki network, you're using direct internet access and thus get the correct behavior. The other network you're using may be using a proxy that's located elsewhere. Maybe for some reason when switching back to the Meraki network it sticks to the proxy?

 

Just thinking out loud here.

Nash
Kind of a big deal


@BrechtSchamp wrote:

I wonder if this is a proxy issue.


Same - it's why I asked about it before. People stop 'seeing' web proxies and forget they're there after a while. We used to have a fun time of that when we used a Forcepoint cloud-based web proxy.

DeweyL
Comes here often

I have rechecked and there is no proxy setup for either network.

Nash
Kind of a big deal

What's your public IP show on your MX itself? Is it the one you expect it to be?

 

If the MX has the correct public IP, do you have any form of cloud-based web proxy running on your PC? That can cause 'whats my ip' to give you a different IP than what your firewall has, as your PC is proxying all of your web traffic to someone else's computer.

NolanHerring
Kind of a big deal

The public IP your getting is coming from your ISP, nothing on the Meraki side that I am aware of other than the ability to configure a static or use DHCP for the WAN1 port.
Nolan Herring | nolanwifi.com
TwitterLinkedIn
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels