Hi, i have configured on meraki mx the web access on the firewaal parameter but if i will connect from remote i not receive login page.
I don't find specific document for this problem on meraki sites.
Can you help me?
Hey @Aondio_Carlo, I'm not too sure I understand your problem, however, I assume it's that you're trying to access the local status pages of your Meraki appliances by VPN into your network?
Are you able to ping the management IP of your Meraki devices when connecting from the VPN?
Have a read of this document too which outlines the configuration steps required to enable remote Local status page access and some common troubleshooting steps; https://documentation.meraki.com/zGeneral_Administration/Tools_and_Troubleshooting/Using_the_Cisco_M....
And it works locally? So you've set this:
If so, the only conclusion I can think of is that it have something to do with the settings on the firewall. If you're MX is the external firewall, you just have to put in your WAN IP-address and that should work.
Can you share a screendump what you see in "Network-wide -> General -> Device configuration" ?
And does it work locally? Have you enabled it and tested it?
"Enable or disable access to the local device status pages at my.meraki.com, switch.meraki.com, wired.meraki.com. For MX's, this disables access from the LAN. Configure MX remote access here."
You see a little box when it is enabled, which forwards you to you L3/L7 firewall rules. Have you set any of those?
If I understand your question correctly - this excerpt from the documentation explains what to do -
Controlling Remote Access to the Local Status Page
On MX/Z1 series devices, by default access to the local status page is only available to devices via the LAN IP address(es). However, it is possible to allow access via the WAN/Internet IP as well.
Make sure you note the username/password you have set for accessing device local pages.
Hi, yes i have tested local page from lan and it's ok.
I don't have firewall 7 rules
Because i don't have remote access choise?
In addition to what the others suggested you may also need to set the Security Appliance>Firewall>Web (local status & configuration) with the IP(s) you'll be connecting from.