Connection Error Meraki Cam (Poor connectivity to the Meraki cloud) / Video Settings not available

Solved
BentoStep
Conversationalist

Connection Error Meraki Cam (Poor connectivity to the Meraki cloud) / Video Settings not available

Hi folks,

 

we're new to Meraki. Last week we've been installing three Meraki Cams (2 x MV73X, 1 x MV63X).

The three cams are connected to our company network, all of them are making similar errors as I'll try to describe:
The status of one cam is usually "Online", the status of the two other cams is usually "Alert". It seems to be kind of random which cam is the "Online" or might depend on which cam was the last that did a power cycle.
It's possible to see the Live View on ALL cams. It's possible in MAXIMUM ONE CAM (usually the "Online"-one) to open Settings -> Video Settings for example. 
The cams that are on Alert-Status show: "Possibly due to an asymmetric firewall or NAT issue. Please ensure your upstream firewall is configured to allow for Meraki cloud connectivity - How to resolve this error".

Together with external IT support we've been checking firewall rules (including "allow any", manufacturer of the firewall is Stormshield), Firewall Logs, VLAN-Settings, logging of the connected access switch, PoE of the connected access switch, other DNS server. Nothing of that was suspicious.

As a test we've been adding our secondary internet line (connected via SOHO-Router) to the VLAN of the meraki cams. In that constellation the cams worked like a charm. So we know that it's nothing related to the cams hardware themselves, access-switches, PoE, cables. Of course we'd like to have the cams running on our primary internet line and behind our firewall...

I've opened a supportcase but didn't receive answer yet. Maybe one of you was facing similar problems? Thank you for your support!!!

1 Accepted Solution
BentoStep
Conversationalist

Here is the final solution to make the cameras work on our Stormshield Firewall.
Please note: I'm not very professional in firewall configs, trying to describe the problem and solution that I got explained from our firewallsupport as best as I can 😉

In the analysis of packets (Cisco Cams to Firewall and backwards) there were shown "Malformed Packets".

The problem has seemed to be that all the cams were coming from same source port in our internal network. That was the reason why the traffic back to the cams was not able to be sent back to the right device. After using the marked function "random translated source port" for the camera-VLAN the problem was gone.

BentoStep_0-1765202611618.png

 








View solution in original post

5 Replies 5
alemabrahao
Kind of a big deal
Kind of a big deal

Do you perform SSL inspection on your firewall? If so, try disabling it for Meraki's domains.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
BentoStep
Conversationalist

No, we don't use SSL inspection

alemabrahao
Kind of a big deal
Kind of a big deal

Well, in addition to analyzing the firewall logs, I would also capture packets from the firewall using the cameras as the source IPs to see if anything might be being dropped.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
BentoStep
Conversationalist

Thanks a lot for everybody who gave a feedback!
Our firewallsupport solved the problem few minutes ago. It was related to a NAT-problem.
I'll get some more information on Monday and update this topic...

BentoStep
Conversationalist

Here is the final solution to make the cameras work on our Stormshield Firewall.
Please note: I'm not very professional in firewall configs, trying to describe the problem and solution that I got explained from our firewallsupport as best as I can 😉

In the analysis of packets (Cisco Cams to Firewall and backwards) there were shown "Malformed Packets".

The problem has seemed to be that all the cams were coming from same source port in our internal network. That was the reason why the traffic back to the cams was not able to be sent back to the right device. After using the marked function "random translated source port" for the camera-VLAN the problem was gone.

BentoStep_0-1765202611618.png

 








Get notified when there are additional replies to this discussion.