External Website(s) Blocked - How?

jpjeffery
Getting noticed

External Website(s) Blocked - How?

Hello

 

I'm deploying MR36 units in our office.

 

We have a Ruckus-based WiFi in production. Traffic over our guest WiFi is allowed (via our Firewall).

 

I've added a guest WiFi with our Meraki units (which again has to route out via our Firewall) but I'm finding some traffic is blocked (traffic that is allowed via the Ruckus).

 

Where do I need to look to work out why this is happening? Presumably the traffic is being passed out so is there a Meraki Firewall service doing the blocking?

5 Replies 5
Brash
Kind of a big deal
Kind of a big deal

Meraki AP's can implement firewall rules on SSID's.

Look under wireless -> firewall and traffic shaping in the dashboard 

Thanks, yes, I've seen that but I don't recall changing the Firewall settings from the defaults.

 

To double-check I created a new temp SSID and compared. The only thing that's different in the first SSID is that Local LAN is set to Deny (which is what we want)

alemabrahao
Kind of a big deal
Kind of a big deal

if it's allowed on the ssid, this is probably not a Meraki issue. Is the Client IP assignment set to Bridged or NAT?

If you are using NAT, the IP of the AP is used to make the accesses, so it may be that you have some blockage in the APs network.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

In order to segregate guest devices from our office network I set it to "Meraki AP assigned (NAT mode)".

So, try to find some log on your firewall coming from the AP IP.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels