SmartPort Profiles and Named VLANs

MartinLL
A model citizen

SmartPort Profiles and Named VLANs

Hey gang.

I did some testing with switching, dynamic vlan assignment using ISE and SmartPort Automations.

 

Here is the setup. 

MR44

MS120-24P

MX68CW

 

The MX is the default gateway for vlan 500 as well as the DHCP server.

 

The switch is plain L2. The port uplinking to the AP is configured as a "dummy" access port. The SmartPort Automation assigns the interface as a trunk allowing all VLANs upon seeing an LLDP string. This works (sometimes... rant for another time).

 

The AP has been configured with the 802.1x ssid wifi-test. This ssid is set to vlan override from ISE with a dummy VLAN set to default tag.

 

Here is the strange part. I use VLAN profiles along with the "use vlan names in radius response " radio checked. Upon authentication this works as expected. The correct autz profile is returned, meraki adds the client in the correct VLAN and the client gets an IP address. But when i try to ping the default gateway the packets are lost.

I did a PCAP on the switch port towards the AP and i can see the ARP mesages trying to resolve the gateway IP/MAC. But the MX sees nothing.

 

To verify that i was not going crazy i disabled the Automation and configured the port manualy and it all started working as expected.

 

The vlan profiles are network local. However i use SmartPort profiles and Automation on the organization level.

 

Is there some known issues/limitations with pairing smart port Automation and Profiles along with VLAN profiles and named VLANs?

 

Thanks for reading!

Software level is latest stable release for all network devices.

MLL
2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

SmartPort Automation may sometimes fail to apply the correct configuration, leading to issues like the one you are experiencing.

There may be conflicts or misconfigurations when using named VLANs with dynamic assignment capabilities. Make sure that the VLAN names and IDs are mapped correctly and are consistent across your network.

In your case, I would suggest opening a support case with Meraki. I believe they will be able to assist you further.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
RaphaelL
Kind of a big deal
Kind of a big deal

If only SecurePort was supported on MS120 family , that would solve your issue.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels