- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MX and MS connection issue
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi MX-2020,
Sounds like you are moving in the right direction.
Here are couple more pointers.
- You can configure the MX to have as many IP addresses as you want (within reason). Each VLAN you create on the MX has an IP address which is ‘on’ the MX. Don’t think of these as management IP addresses as the MX (like all Meraki devices) is cloud-managed, so they’re actually managed via the internet facing interface. If you want the MX to have 10.10.80.50 on it, then assuming this is on VLAN80, the IP address for VLAN80 should be 10.10.80.50.
- I can’t see why the ME router needs to connect to the switch, why not connect it directly to the MX WAN2? Having an interface on VLAN99 on the MS is just going to complicate things and add no value that I can see. You could use VLAN99 on the MS without an IP address, but in that case why not just connect the MX WAN2 to the ME router?
- You can setup DHCP relay on either the MX or MS, but if the DHCP server is in VLAN80 then you don’t need a relay for any devices connecting to VLAN80 the sever will respond to them anyway, you will need to configure DHCP relay for other VLANs though to direct them to the DHCP server.
You shouldn’t need to set any specific NAT, the MX will do PAT of the local IP addresses to the respective WAN IP address without any additional configuration.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @MX-2020 , so what you’re saying is that your MXs are registered but your Switches and MRs aren’t getting out to the cloud?
Not sure which each of your VLANs are enabled for but try creating a third for Meraki Device Management.
99 10.10.99.0/24 10.10.99.1
The uplink from the MS to your MX set this as a Trunk with Native VLAN 99
On your MS set the management IP to something in the .99 range or just enable DHCP on the MX and let that set the IP
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
1. Yes, MS Switch and MRs aren't go to internet from MX.
Hi @MX-2020 , so what you’re saying is that your MXs are registered but your Switches and MRs aren’t getting out to the cloud?
2. Vlan 88 Access point and User data
Vlan 80 Server, Printer UPS and Management
Vlan 99 Trunk Link, and ME router (Metro E connect to other Site and backup link)
Not sure which each of your VLANs are enabled for but try creating a third for Meraki Device Management.
Vlan 99 10.10.99.0/24 10.10.99.1
Before our Old firewall abled to set management IP as 10.10.80.50 and Lan port to connect to MS switch.
3. Before I set MS Port 19 as native 80 to connect to MX port 3
MS Port 21 as Vlan 99 Trunk connect to MX Uplink Wan 2.
4. OK we have already set on it on port 21 from MS
99 10.10.99.0/24 10.10.99.1
The uplink from the MS to your MX set this as a Trunk with Native VLAN 99
5. The MS switch has relayed to other Window server (10.10.80.20) for DHCP.
Will it cause the duplicate IP if I enable DHCP on MX or MS on .99 range?
On your MS set the management IP to something in the .99 range or just enable DHCP on the MX and let that set the IP
MX-2020
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @MX-2020 , just to clarify this isn’t the official Meraki support help desk. I’m a user of Meraki eqpt just like yourself but jump in and out of the forum to help others.
Lets focus on getting your switch online.
So VLAN 80 is being used for Management also. What happens if you set the Native vlan on both sides of the Trunk uplink between the MX and MS?
Does the MS get an IP address. What are you using for DNS? Can your DNS server see the internet?
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To add further: it'd be very helpful (even for yourself) having the design drawn. It would help us all (including you) better understanding the issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@MX-2020 you have both WAN2 and LAN (labelled as management?) both going back to the MS. Why do you have that setup?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi cmr,
MX
Wan 2 is not the management.
uplink Wan 2 --> MS --> ME Router
Lan port (MX management) --> MS --> MR
Lan Port is the management.
Mainly MS switch is used for main routing and relay from other DHCP server and it's default route through MX to go internet. Other than that, it also set the route with Lan port to connect to ME router through backup Wan which bridge to our other site for remote server and network devices.
It is a little bit complicated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is a little bit complicated 😀, and I can’t see why it should be.
There are a couple of things to consider...
- The MS can really only have one default route (i.e.0.0.0.0/0) so all internet traffic from the MS will be sent the same way, either to the MX or your ME service - there isn’t really an option for using one as the backup to the other from the MS210 as the routing is static.
- Why not connect the ME router directly to the MX WAN2 (i.e. not via the MS) and disable load balancing. With WAN1 configured as the primary, internet traffic should go out WAN1, unless it fails in which case it will go via WAN2 to your ME service. Your Flow Preference will ensure that all ‘internal WAN’ traffic uses WAN2 (unless it fails) - although note that it will be NATed to the WAN2 IP address. Note that you may be limited by the throughput of the MX.
- Have a single link between the MX and MS, connected to one of the MX LAN ports. This will have two VLANs on it. I’d have the native VLAN as your management VLAN, and a tagged VLAN as a transit VLAN between the MS and MX for all non-management traffic. Keep all the management interfaces, MS and MR, on this management VLAN (will mean you probably need to switch the MRs to use bridge mode and assign a VLAN tag to all traffic from the SSID).
Hope these, along with everyone else’s suggestions may help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi MX-2020,
Sounds like you are moving in the right direction.
Here are couple more pointers.
- You can configure the MX to have as many IP addresses as you want (within reason). Each VLAN you create on the MX has an IP address which is ‘on’ the MX. Don’t think of these as management IP addresses as the MX (like all Meraki devices) is cloud-managed, so they’re actually managed via the internet facing interface. If you want the MX to have 10.10.80.50 on it, then assuming this is on VLAN80, the IP address for VLAN80 should be 10.10.80.50.
- I can’t see why the ME router needs to connect to the switch, why not connect it directly to the MX WAN2? Having an interface on VLAN99 on the MS is just going to complicate things and add no value that I can see. You could use VLAN99 on the MS without an IP address, but in that case why not just connect the MX WAN2 to the ME router?
- You can setup DHCP relay on either the MX or MS, but if the DHCP server is in VLAN80 then you don’t need a relay for any devices connecting to VLAN80 the sever will respond to them anyway, you will need to configure DHCP relay for other VLANs though to direct them to the DHCP server.
You shouldn’t need to set any specific NAT, the MX will do PAT of the local IP addresses to the respective WAN IP address without any additional configuration.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi UCcert,
Thanks for the advise.
Yes, Vlan 80 used for management too, I only able to set this setting on Meraki first and I will see what happen this weekend because I fall back to use the temporality setting on MS switch via other router connected to backup Wan 2 now. The MS switch is 10.10.80.10 static IP.
Router Management IP: 10.10.80.50
Opened NAT
Routing:
Vlan 80 10.10.80.0/24 10.10.80.1
I set it before. The MS switch got the different 10.10.80.16 via DHCP server and MR are all disconnected. it is using the ISP DNS. outbound the DNS are pingable.
