cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

MX68 and 802.1x

Getting noticed

MX68 and 802.1x

Hello everyone

We had a case of deploying very small branches and we opt for using the Meraki MX68 as a solution, with many sites without MS switches.
During our study we looked at the MX65, however we knew that this will be EoS, and the replacement would be the MX68, we bought MX68 for all these branches.
The issue is that we require the 802.1x Wired LAN authentication option on the MX68, which seems to be dropped by Meraki, the MX65/MX64 fully supports the 802.1x.

I raised a ticket and could not have even a little support from the Meraki team, tomorrow I will be calling them and giving them some shouts.

Has anyone required the 802.1x on the MX68? did Meraki enable this for you?

25 REPLIES 25
Head in the Cloud

Re: MX68 and 802.1x

https://meraki.cisco.com/lib/pdf/meraki_datasheet_mx.pdf

 

Per this doc the MX65 does not support 802.1x. You need the wireless model of 65 or 68 (MX65W, MX68W, or MX68CW)

Getting noticed

Re: MX68 and 802.1x

I mean it sucks and maybe you can call your rep and see if you can get them swapped out or something to save some face with your company. But man I got to call you out for being that guy who is in a industry where we are always getting blamed for everything and people screaming at us because its broken and you have the nerve to do that to another IT professional. Man you know full well who ever you are going to call and "Give some shouts" to had nothing to do with the design change, the possibility of you swapping it out for the hardware you need, any policy that will prohibit that from happening, how long it took you to realize it wont work, and your blind ignorance and laziness of not checking the documentation before making an order. Seriously man not cool.
Kind of a big deal

Re: MX68 and 802.1x

The 802.1x support has only ever been for wireless connections.  Never for wired connections.

Kind of a big deal ww
Kind of a big deal

Re: MX68 and 802.1x

@PhilipDAth   you can enable it on the interface of the mx 64 and 65 if you set it to access mode. for the 67 and 68 this function should work in the near future (with beta firmware)

Kind of a big deal

Re: MX68 and 802.1x

I stand corrected.  I just tried it and you can enable 802.1x on an MX65 wired port.

Getting noticed

Re: MX68 and 802.1x

When I raise a ticket to a support desk, I expect a reasonable answer, not just saying MX68 does not support 802.1x. If Meraki would say MX68 is a replacement for MX65, then you should expect that all the features to be available, if not this should be mentioned somewhere, I did read all the documentation for MX65 and I know what I am taking about. Such comment from you does not help in any way.
Getting noticed

Re: MX68 and 802.1x

Thanks @ww for your answer, do you have any reference stating that this will be available in a beta firmware? I can wait for it, or even test it in production.
Head in the Cloud

Re: MX68 and 802.1x

If I'm reading this correctly then it should already be available.

 

https://documentation.meraki.com/MX/Access_Control_and_Splash_Page/MX_Access_Policies_(802.1X).

 

 

Getting noticed

Re: MX68 and 802.1x

@SoCalRacer , yes it is available for MX64/65 and not for MX67/68:
"MX64(W) and MX65(W) Security Appliances as well as Z3(C) Teleworker Gateways support port-based access policies using 802.1X. This feature can be leveraged for deployments where extra authentication is desired for devices that are connecting to the MX."
Getting noticed

Re: MX68 and 802.1x

Well , 

 

We have over 300 MX68 with 802.1X enabled and over 1200 MX65.  We are running the 14.39 firmware.

Head in the Cloud

Re: MX68 and 802.1x

I have MX67s on 14.39 and this change is not available. I also looked through the firmware release notes and I didn't see one that indicated it was turned on. Also alot of the release notes seems to show they are having issues with this on the 64/65 so I wonder if they is delaying roll out.

Getting noticed

Re: MX68 and 802.1x

Here is a screenshot. This is a template for our MX65-68. Access policy is hybrid ( MAB and 802.1x ) and it is working like a charm 

 

8021x.png

Head in the Cloud

Re: MX68 and 802.1x

Confirmed with support 802.1x wired is not available on MX67/MX67W/MX67C/MX68/MX68W/MX68CW up to firmware 15.13 , which is the highest beta firmware currently. It is is set to be implemented, but you will have to wait to watch release notes on the new beta firmware.

Getting noticed

Re: MX68 and 802.1x

Ah ! I think we had our Meraki Rep to enable this feature for us.

 

It is the only explanation that I can give for the moment.

 

 

 

EDIT : Tested and ... not working with 14.39 firmware and MX67/MX68 series. Seems like you are right about it. I will test the latest version and report the results

Highlighted
Getting noticed

Re: MX68 and 802.1x

Even with the latest firmware it is not available  : 

 

 

Support : 

Wired 802.1x is planned for the MX67/68 platform, however, it is unfortunately, not available at this time. Support does not have an ETA of when this will be available and what firmware build will include this feature. Let us know if you have any further questions.

Building a reputation

Re: MX68 and 802.1x

I asked about this when I first got the MX67/68 last year. It's one of the huge oversights in my opinion. I can't believe they did not have port security in a brand new device superseding an older model which did have the feature.

This really needs to be enabled.
Getting noticed

Re: MX68 and 802.1x

@Aaron_Wilson, this is exactly what I am referring to, the MX is a security device after all, they cannot drop a feature which would secure LAN ports, when I contacted support they never provided a solid answer, they just said this feature is not available.
I am with you this should really be enabled.
Getting noticed

Re: MX68 and 802.1x

@RaphaelL , I tested the latest beta firmware before posting here, it is not there, but if you had a feedback from support this is planned for the MX67/68 then, what we can only do is wait. I believe this is an important feature which should be kept.
Building a reputation

Re: MX68 and 802.1x

Oh, here is the reply I received back in Nov 2018, similar to others:

"Thank you for contacting Cisco Meraki Technical Support!

Aaron, the MX67/68 series currently doesn't support port-based access policies using 802.1x. The feature set will be addressed in a future firmware upgrade when tested and released by our Development team. Let me know if you have any questions.
Thanks!"
Getting noticed

Re: MX68 and 802.1x

Below is what I received, and it does not give any hint that this would be enabled in the future, but again, which future are we talking about, if you raised this 6 month back and till no there is no plan for it.

"The 802.1X feature is MX model specific and it is not possible to enable it on MX68 and MX84.
Unfortunately there is no way to enable it."
Building a reputation

Re: MX68 and 802.1x

Just a heads up. I tested port security on my MX68W and it was horrible. Countless errors in the dashboard and the MX rebooted every couple hours. Had to roll back to 14.x to make it "normal" again.
Getting noticed

Re: MX68 and 802.1x

An update on this post.
I contacted a Meraki Architect and he enabled the 802.1x for our dashboard on the MX68 devices, however he mentioned that I need to have the latest beta version and this is only for Lab testing.

We tested this in our lab and it seems to be working, I will not be deploying this to our production environment until this is official announced in the next 3 month (as per the Meraki Architect).

 

Building a reputation

Re: MX68 and 802.1x

Was that a MX68 or 68W?
Getting noticed

Re: MX68 and 802.1x

It is an MX68, the subject is about wired port security.

Building a reputation

Re: MX68 and 802.1x

MX68W has wired ports too 😉
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.