CoA messages from outside (Internet)

Alexs20
Getting noticed

CoA messages from outside (Internet)

Hi, maybe someone know the answer to the following, CoA related, question.

 

I've verified that the AP responds to CoA messages initiated from the local network. However, the actual requirement is to send these messages from the internet, externally. The option of configuring port forwarding for each AP individually is not very feasible due to security concerns and the complexity involved, especially with a potentially large number of APs. As a result, the only viable approach seems to involve routing these messages from a single open port to the respective AP, based on specific criteria such as the 'NAS-IP-Address' value. So, my question is: does Meraki offer any hardware solutions that can facilitate this message forwarding? Alternatively, is there an alternative solution that I might not have considered?

 

Thanks

4 Replies 4
alemabrahao
Kind of a big deal
Kind of a big deal

I don't know if a Radius proxy is a good solution, I see it as another point of failure, not to mention that I've seen some problems when using Radius Proxy, but that's just my opinion.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ww
Kind of a big deal
Kind of a big deal

We dont use it either. Most times radius behind a vpn is possible.

PhilipDAth
Kind of a big deal
Kind of a big deal

It would be best to have a VPN from the AP management VLAN to the RADIUS server.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels