Need some suggestions for MX traffic collection

SOLVED
kYutobi
Kind of a big deal

Need some suggestions for MX traffic collection

Hello community,

 

I am curious to ask what would be the best way for me to do WAN/Web App monitoring of our internal traffic without having to really have connections dependant on the MX unit. Any ideas are much appreciated. Thank you ahead of time. 

mx exmaple.PNG

Enthusiast
1 ACCEPTED SOLUTION
BrechtSchamp
Kind of a big deal

Insight bases its analysis on DPI like techniques on the real user traffic. So you would have to have it go through the MX. Maybe you could have it go through the MX and fallback to your current routing instead in case of problems.

 

But that seems like a needlessly complex setup and I'm a fan of k.i.s.s.

 

In the future they may add the sensor functionality to the switches and APs...

View solution in original post

4 REPLIES 4
Owen
Getting noticed

Mirror the uplink port on the switch to a computer running software like Security Onion, ntop etc.

kYutobi
Kind of a big deal

What I mean is I want to use the MX for this. I want to use Meraki Insights I just don't know if there's a way to do it without really affecting my LAN by relying on a connection that is through the MX if that makes sense.

Enthusiast
Owen
Getting noticed

Depends on entire topology. A Meraki switch is able to collect some info, access points some other and MX rounds it out for even more information. Of course you are at the mercy of encryption between the endpoints and servers and the lack of visibility this causes.

 

You would need to provide more information on topology if you wanted more complete answers.

BrechtSchamp
Kind of a big deal

Insight bases its analysis on DPI like techniques on the real user traffic. So you would have to have it go through the MX. Maybe you could have it go through the MX and fallback to your current routing instead in case of problems.

 

But that seems like a needlessly complex setup and I'm a fan of k.i.s.s.

 

In the future they may add the sensor functionality to the switches and APs...

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels