MX and the use of Static addresses

ICTNetworks
Just browsing

MX and the use of Static addresses

Does anyone know why a client machine with a static IP Address directly connected to an MX (67,68,105), cannot communicate over the internet if the vlan it is attached to is configured with a 172.x.x.x address range.

 

Swap this Vlan and static address range address range for a 192.168.x.x and all works perfectly.

Netmask is correct as is the configured Gateway.

 

Cannot even ping the Gateway of the same network it is sitting on 172.23.151.0/24 GW:172.23.151.1

 

Firmware 19.1.11

 

 

7 Replies 7
alemabrahao
Kind of a big deal
Kind of a big deal

Do you have an interface on the 17.x.x..x network configured on the MX record?

Do you have any firewall rules restricting any type of communication?

 

There are no limitations regarding the use of a specific address block on the MX.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ICTNetworks
Just browsing

No rules etc stopping communication.

 
Even the MX ping tool does not work to 8.8.8.8 if the source address is a Vlan starting with 172.x.x.x
Works fine with other options
alemabrahao
Kind of a big deal
Kind of a big deal

Can you share your configuration please?

 

Another question: is the device directly connected to the MX recorder or is it connected to a switch?

Is the correct VLAN properly configured on the port to which the client is connected?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ICTNetworks
Just browsing

There is not a lot to share.

 

I have three Vans configured 

Vlan23 172.23.151.0/24 GW 172.23.151.1   1 Port configured as Access in Vlan

Vlan26 172.26.151.0/24 GW 172.26.151.1   Port configured as Access  in Vlan

Vlan10 192.168.1.0/24    GW 192.168.1.1     Port configured as Access  in Vlan

 

If I activate DHCP on any of these Vlans, the operation is fine

Vlan10 192.168.1.0/24 works with or without DHCP

Vlan23 & 26 does not work with Static address on a Windows Client mchine

If I set a DHCP static reservation on Vlan23 & 26 they work fine

 

This is not a config typo as the same issues has been seen across different sites and across different models of the MX by different configuring engineers.

 

There are no FW rules except the default Deny.

The client Machine being tested is plugged directly into an MX port 

 

Personally I think it is a firmware bug and I am liaising with Meraki support but wondered if this  had been seen before.

 

alemabrahao
Kind of a big deal
Kind of a big deal

There really is no limitation on the MX side.
In your case, I would check with support to see if it's actually a bug, which I believe it isn't, but rather that something has been overlooked.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
GIdenJoe
Kind of a big deal
Kind of a big deal

You should check your DHCP page of the MX.  Per VLAN there is a mandatory DHCP setting  that if enabled will block any static IP client.

alemabrahao
Kind of a big deal
Kind of a big deal

Good point.

alemabrahao_0-1764362811283.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.