cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

MX68 and 802.1x

Highlighted
Getting noticed

MX68 and 802.1x

Hello everyone

We had a case of deploying very small branches and we opt for using the Meraki MX68 as a solution, with many sites without MS switches.
During our study we looked at the MX65, however we knew that this will be EoS, and the replacement would be the MX68, we bought MX68 for all these branches.
The issue is that we require the 802.1x Wired LAN authentication option on the MX68, which seems to be dropped by Meraki, the MX65/MX64 fully supports the 802.1x.

I raised a ticket and could not have even a little support from the Meraki team, tomorrow I will be calling them and giving them some shouts.

Has anyone required the 802.1x on the MX68? did Meraki enable this for you?

31 REPLIES 31
Highlighted
Kind of a big deal

Re: MX68 and 802.1x

https://meraki.cisco.com/lib/pdf/meraki_datasheet_mx.pdf

 

Per this doc the MX65 does not support 802.1x. You need the wireless model of 65 or 68 (MX65W, MX68W, or MX68CW)

Highlighted
Getting noticed

Re: MX68 and 802.1x

I mean it sucks and maybe you can call your rep and see if you can get them swapped out or something to save some face with your company. But man I got to call you out for being that guy who is in a industry where we are always getting blamed for everything and people screaming at us because its broken and you have the nerve to do that to another IT professional. Man you know full well who ever you are going to call and "Give some shouts" to had nothing to do with the design change, the possibility of you swapping it out for the hardware you need, any policy that will prohibit that from happening, how long it took you to realize it wont work, and your blind ignorance and laziness of not checking the documentation before making an order. Seriously man not cool.
Highlighted
Kind of a big deal

Re: MX68 and 802.1x

The 802.1x support has only ever been for wireless connections.  Never for wired connections.

Highlighted
Kind of a big deal
Kind of a big deal

Re: MX68 and 802.1x

@PhilipDAth   you can enable it on the interface of the mx 64 and 65 if you set it to access mode. for the 67 and 68 this function should work in the near future (with beta firmware)

Highlighted
Kind of a big deal

Re: MX68 and 802.1x

I stand corrected.  I just tried it and you can enable 802.1x on an MX65 wired port.

Highlighted
Getting noticed

Re: MX68 and 802.1x

When I raise a ticket to a support desk, I expect a reasonable answer, not just saying MX68 does not support 802.1x. If Meraki would say MX68 is a replacement for MX65, then you should expect that all the features to be available, if not this should be mentioned somewhere, I did read all the documentation for MX65 and I know what I am taking about. Such comment from you does not help in any way.
Highlighted
Getting noticed

Re: MX68 and 802.1x

Thanks @ww for your answer, do you have any reference stating that this will be available in a beta firmware? I can wait for it, or even test it in production.
Highlighted
Kind of a big deal

Re: MX68 and 802.1x

If I'm reading this correctly then it should already be available.

 

https://documentation.meraki.com/MX/Access_Control_and_Splash_Page/MX_Access_Policies_(802.1X).

 

 

Highlighted
Getting noticed

Re: MX68 and 802.1x

@SoCalRacer , yes it is available for MX64/65 and not for MX67/68:
"MX64(W) and MX65(W) Security Appliances as well as Z3(C) Teleworker Gateways support port-based access policies using 802.1X. This feature can be leveraged for deployments where extra authentication is desired for devices that are connecting to the MX."
Highlighted
Building a reputation

Re: MX68 and 802.1x

Well , 

 

We have over 300 MX68 with 802.1X enabled and over 1200 MX65.  We are running the 14.39 firmware.

Highlighted
Kind of a big deal

Re: MX68 and 802.1x

I have MX67s on 14.39 and this change is not available. I also looked through the firmware release notes and I didn't see one that indicated it was turned on. Also alot of the release notes seems to show they are having issues with this on the 64/65 so I wonder if they is delaying roll out.

Highlighted
Building a reputation

Re: MX68 and 802.1x

Here is a screenshot. This is a template for our MX65-68. Access policy is hybrid ( MAB and 802.1x ) and it is working like a charm 

 

8021x.png

Highlighted
Kind of a big deal

Re: MX68 and 802.1x

Confirmed with support 802.1x wired is not available on MX67/MX67W/MX67C/MX68/MX68W/MX68CW up to firmware 15.13 , which is the highest beta firmware currently. It is is set to be implemented, but you will have to wait to watch release notes on the new beta firmware.

Highlighted
Building a reputation

Re: MX68 and 802.1x

Ah ! I think we had our Meraki Rep to enable this feature for us.

 

It is the only explanation that I can give for the moment.

 

 

 

EDIT : Tested and ... not working with 14.39 firmware and MX67/MX68 series. Seems like you are right about it. I will test the latest version and report the results

Highlighted
Building a reputation

Re: MX68 and 802.1x

Even with the latest firmware it is not available  : 

 

 

Support : 

Wired 802.1x is planned for the MX67/68 platform, however, it is unfortunately, not available at this time. Support does not have an ETA of when this will be available and what firmware build will include this feature. Let us know if you have any further questions.

Highlighted
Building a reputation

Re: MX68 and 802.1x

I asked about this when I first got the MX67/68 last year. It's one of the huge oversights in my opinion. I can't believe they did not have port security in a brand new device superseding an older model which did have the feature.

This really needs to be enabled.
Highlighted
Getting noticed

Re: MX68 and 802.1x

@Aaron_Wilson, this is exactly what I am referring to, the MX is a security device after all, they cannot drop a feature which would secure LAN ports, when I contacted support they never provided a solid answer, they just said this feature is not available.
I am with you this should really be enabled.
Highlighted
Getting noticed

Re: MX68 and 802.1x

@RaphaelL , I tested the latest beta firmware before posting here, it is not there, but if you had a feedback from support this is planned for the MX67/68 then, what we can only do is wait. I believe this is an important feature which should be kept.
Highlighted
Building a reputation

Re: MX68 and 802.1x

Oh, here is the reply I received back in Nov 2018, similar to others:

"Thank you for contacting Cisco Meraki Technical Support!

Aaron, the MX67/68 series currently doesn't support port-based access policies using 802.1x. The feature set will be addressed in a future firmware upgrade when tested and released by our Development team. Let me know if you have any questions.
Thanks!"
Highlighted
Getting noticed

Re: MX68 and 802.1x

Below is what I received, and it does not give any hint that this would be enabled in the future, but again, which future are we talking about, if you raised this 6 month back and till no there is no plan for it.

"The 802.1X feature is MX model specific and it is not possible to enable it on MX68 and MX84.
Unfortunately there is no way to enable it."
Highlighted
Building a reputation

Re: MX68 and 802.1x

Just a heads up. I tested port security on my MX68W and it was horrible. Countless errors in the dashboard and the MX rebooted every couple hours. Had to roll back to 14.x to make it "normal" again.
Highlighted
Getting noticed

Re: MX68 and 802.1x

An update on this post.
I contacted a Meraki Architect and he enabled the 802.1x for our dashboard on the MX68 devices, however he mentioned that I need to have the latest beta version and this is only for Lab testing.

We tested this in our lab and it seems to be working, I will not be deploying this to our production environment until this is official announced in the next 3 month (as per the Meraki Architect).

 

Highlighted
Building a reputation

Re: MX68 and 802.1x

Was that a MX68 or 68W?
Highlighted
Getting noticed

Re: MX68 and 802.1x

It is an MX68, the subject is about wired port security.

Highlighted
Building a reputation

Re: MX68 and 802.1x

MX68W has wired ports too 😉
Highlighted
Conversationalist

Re: MX68 and 802.1x

I spoke with Meraki support this week about this feature missing on the MX68CW.  They indicated that the feature was pulled due to a bug that would send the MX into a reboot loop.  After some back and forth with support they indicated that the patch was actually available in the latest published beta firmware (15.23 - Released 1/6/2020).  I had to update to the indicated beta firmware and recontact support so they could turn a backend knob to re-enable the feature.  Fortunately this did restore the functionally and I was able to successfully test/validate dot1x on this platform.

Highlighted
New here

Re: MX68 and 802.1x

Hey just wanted to follow up on this thread. I am currently running 14.40 across the board. My Z3s have been doing 802.1x quite well for at least a few months now. I just got some mx68s and it appears like they are NOT doing 802.1x. Has there been an official firmware release that supports 802.1x for the mx68s? 

Highlighted
Building a reputation

Re: MX68 and 802.1x

@Khue- you will need to go to the 15.x train. It became stable for me after some more recent code versions, I'm on 15.27 right now.

Highlighted
Building a reputation

Re: MX68 and 802.1x

You have tried this with cisco ISE yet ?

Highlighted
Building a reputation

Re: MX68 and 802.1x

Yup. Running hybrid auth on the Meraki port and pointing to ISE for radius auth.
Highlighted
Here to help

Re: MX68 and 802.1x

We had issues on the 15.x train. We had to roll back to 14.4.

Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.