Lately we have had some weird occurrences with access to some websites, in this instance Github.com. I've taken some captures and I see a ton of SYN Resets. I have a case open with the Meraki team, but just wanted to bounce it off the team on here, since we have no idea what could be causing it. We have outbound http and https allowed, so its not an access issue. Plus, I'm not blocking it with any content filtering. If anyone wants a crack at it, I'm all for it! Thanks!
I have no access lists in place currently. Also, I'm just running the MX with IDS/IPS on Prevention and Balanced. When I check the flow logs (sent to a syslog server), I see the traffic is allowed out, and it keeps repeating itself on different ports. For example, if I go to a page using destination port 443, it will allow it, but the source port keeps changing every millisecond.
I'm running 14.39 on the MX and was told to try the beta, but being in production and getting an outage window is difficult sometimes, since it has to reboot after the upgrade.