MX68CW - wanting to turn 3 ports into a dumbswitch

JethroCrates
Here to help

MX68CW - wanting to turn 3 ports into a dumbswitch

Title pretty much describes what I'm trying to do.  Basically we have Starlink, and our reseller wants to plug a management device directly into the Starlink Box.  

 

They want us to use Starlink -> dumbswitch -> their management device, and our Meraki gear into that dumbswitch.

 

I prefer not to do that because:

a: point of failure

b: what's stopping random user from plugging in a dlink in our dumbswitch and bypassing our meraki gear.

c: I'm also being told that we don't want any third party gear plugged in behind our appliance.  I know....

 

I'm just doing proof of concept at home. so basically I have this "working" on a MX68CW. I have a vlan setup that doesn't broadcast DHCP, and it's active on 3 ports. The modem plugs into port 3 on the LAN.  Port 4 goes back into the internet port 1 on the meraki, and port 5 is just active.  (I don't have the management box ATM).  I have packet loss over my DMZ, but I think my DMZ just sucks.  However, if you can let me know why I might have packet loss with this setup please tell me.

 

Am I going to get a better result if I attempt to do this on a MS250?

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

I don't think it will make much of a difference, but it's a try.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
GIdenJoe
Kind of a big deal
Kind of a big deal

Well an MS250 is instantly a big cost unless that MS250 is already part of the network where that MX68CW is at.
What you are trying to do sound like a bit of a hack.  Because to make this work you would have to have some random VLAN that does not have the same range as what is behind the Starlink router and you would better not use any if your internal LAN's too because you could have internet martian stuff going on.  So it's a big if for that deployment.

 

If possible just use your internal MS250 with an "external' vlan.  You'll at least see when someone unplugs it and you won't have to hack stuff to make it work.

JethroCrates
Here to help

There is a MS250 in play here, and a spare MX68CW, so after looking around I found this: https://community.meraki.com/t5/Security-SD-WAN/How-to-turn-MS120-into-WAN-breakout-for-2-ISPs-and-2...

Looks like I'll just do this.

Thanks for the help.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels