I cannot ping gateway (interface vlan on MX) from cilent in same vlan

Tanin
Here to help

I cannot ping gateway (interface vlan on MX) from cilent in same vlan

Hi, I have created a vlan on my meraki MX and I have set up the subnet, MX IP, and vlan ID! The deployment mode is routed. Under security > Firewall, I have allowed "any" for ICMP (ping). The port where the switch is connected (downstream MX port) has the native vlan (which is not the vlan I have created) and then under allowed vlan I have "ALL VLANs"! 

 

I am unable to ping the MX IP (default gateway for the client)! Is there anything that I might miss on the configuration or maybe something else I should check? 

 

Thank you

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

 check if the mx port set to native vlan x, allow all

Check if the switchport connecting to the mx is set to native vlan x allow all.

Check if switchport connecting the client is a access port with vlan set to "your new vlan id"

 

Does the client now get a dhcp address in the subnet from the new vlan?

Brash
Kind of a big deal
Kind of a big deal

What @ww said is a great starting point.

Just to add, you said you enabled ping any under Security -> Firewall.
Was that under outbound rules or security appliance services?
The setting under security appliance services is to allow remote IP's to ping the MX via the upstream WAN interface. It doesn't impact downstream.

Traffic coming from downstream will adhere to L3 firewall rules and ACL's, so I suggest ensuring that they're setup correctly to allow ICMP.

Tanin
Here to help

Hi WW & Brash,

 

Thank you for your reply.

I have found the cause of issue is the wireless controller firewall rule. 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels