- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
UDP7351 giving way too many problem.
Im using a private circuit and i have allowed 7351 UDP for MX84/100 but they seem to be failing to communicate.
I see the traffic going out once every hour ~ but nothing... the devices show unreachable and from time to time they would show reachable.
There are no apparent drops at all for UDP 7351. Is there any way to change this to only https like MX67 for example?
Have a case open already but was wondering what the community can add to this.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You allowed any traffic from the wan IP to internet, or at least all traffic mentioned at help>firewall info
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Go to the top right-hand corner and then down to "Firewall info" to get the complete list of firewall rules. You need far more than just udp/7351.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yup. All this was already done. The unit was working and it stopped reporting. Additionally we have incoming traffic from meraki replying the upd 7351 which is confusing.
We have other appliances including mx67 that works without issues.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pretty sure that MX84 and MX100 do support NextTunnel :
- While Meraki appliances have traditionally relied on UDP port 7351 for cloud communication and TCP ports 80 and 443 for backup communications, with MX 16 we are beginning a transition to using TCP port 443 as the primary means for cloud connectivity. In order to ensure proper connectivity to the Meraki cloud after this upgrade, please ensure that traffic using TCP port 443 between 209.206.48.0/20 is allowed through any firewalls that may be deployed upstream of your Meraki appliances.
You should probably open a case to investigate that
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correct. We have allowed all that traffic. We can see the matches on our firewall hitting the public ip going out with 7351. Its a bit odd. Plus like i stated to another reply earlier, for some reason meraki is replying in udp that 7351. I wonder if that is clogging in some way the service.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is not true unfortunately - MX64s, 65s, 84s, 100s, 400s and 600s do not support the use of TLS for management traffic, and there's no way for support to override this (due to reasons I'm not at liberty to disclose)
