is it possible meraki access point suspect as a virus?

Solved
Agus
Getting noticed

is it possible meraki access point suspect as a virus?

Hi,

 

I have a strange log from my gateway (using other brand) that saying on the log like this

 

Agus_1-1649414973270.png

Agus_2-1649415056561.png

 

 

from srcip (192.168.10.6) that source from my MR52. my question is it possible virus came from merak access point? IP addess that we configure on access point is dhcp and already reserve for this access point.

anyone have experience like this?

Appreciate.

 

Thanks

1 Accepted Solution
MarcP
Kind of a big deal

Wild guess...
Thinking of 802.1x where you need to configure the AP IP on the radius, maybe your firewall just sees the MR IP instead of the clients IP?

View solution in original post

4 Replies 4
KarstenI
Kind of a big deal
Kind of a big deal

Just a guess: You have an SSID that is configured for "Meraki DHCP" and the traffic belongs to one of these WLAN users.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Agus
Getting noticed

Hi,

 

Thank for your reply, we have 3 vlan 1 vlan for manage device include this meraki access point (192.168.10.6) and other vlan as internal network and also 1 network using meraki nat. as you said yes...1 network for guest using meraki nat dhcp. i tought like that too may be user on meraki nat dhcp cause this, i mean our gateway listen to meraki dhcp not user ip (meraki dhcp)

Thanks

MarcP
Kind of a big deal

Wild guess...
Thinking of 802.1x where you need to configure the AP IP on the radius, maybe your firewall just sees the MR IP instead of the clients IP?

Agus
Getting noticed

Hi,

 

I same like your tought, our gateway only listen to meraki IP instead client ip address, this first time i receive log like this, ussually other log that i was receive it came from client ip address/ our own vlan that create for internal ( not meraki  dhcp).

 

Thank you 

Get notified when there are additional replies to this discussion.