The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About KarstenI
KarstenI

KarstenI

Kind of a big deal

Member since Mar 22, 2019

Online

Karsten Iwen

Germany

https://cyber-fi.net

Freelance Consultant and instructor. Need help with your Meraki project? Now you know who to contact. ;-)

Groups
  • CLUS 2022 Meraki Lounge

    CLUS 2022 Meraki Lounge

    28
  • Meraki Network Lounge

    Meraki Network Lounge

    49
View All
Kudos from
User Count
van604
van604
1
MyHomeNWLab
MyHomeNWLab
7
PhilipDAth
Kind of a big deal PhilipDAth
383
CptnCrnch
Kind of a big deal CptnCrnch
255
Brash
Kind of a big deal Brash
76
View All
Kudos given to
User Count
AmyReyes
Community Manager AmyReyes
30
PhilipDAth
Kind of a big deal PhilipDAth
102
cmr
Kind of a big deal cmr
76
Brash
Kind of a big deal Brash
30
redsector
redsector
6
View All

Community Record

1394
Posts
1896
Kudos
126
Solutions

Badges

CMSS
ECMS1
ECMS2
Meraki FIT Level One
Meraki FIT Level Two
Meraki360 View All
Latest Contributions by KarstenI
  • Topics KarstenI has Participated In
  • Latest Contributions by KarstenI
  • « Previous
    • 1
    • 2
    • 3
    • 4
    • 5
    • …
    • 54
  • Next »

Re: Endpoint for Umbrella status on MX

by Kind of a big deal KarstenI in Developers & APIs
‎01-27-2023 08:50 AM
‎01-27-2023 08:50 AM
This is what I want to do. Really no API for this? That would be quite disappointing. ... View more

Endpoint for Umbrella status on MX

by Kind of a big deal KarstenI in Developers & APIs
‎01-27-2023 07:46 AM
‎01-27-2023 07:46 AM
Hi,   I don't find the endpoint to query if Umbrella is enabled on the MX and if yes with which settings. Any hints for me?   Have a great weekend, Karsten ... View more

Re: ACL rules traffic between DMZ to LAN

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-26-2023 12:47 PM
‎01-26-2023 12:47 PM
Allowing only to be initiated from one side is purely done with the ACL. No need for NAT. And if there is IP overlap inside of the network, something is severely wrong.   ... View more

Re: ACL rules traffic between DMZ to LAN

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-26-2023 10:28 AM
‎01-26-2023 10:28 AM
Why do you want to NAT here if it's going from private to private? ... View more

Re: CMSS badges are here!

by Kind of a big deal KarstenI in Community Announcements
‎01-26-2023 07:17 AM
1 Kudo
‎01-26-2023 07:17 AM
1 Kudo
done! 🙂 ... View more

Re: Cisco WLC3502 with Meraki setup

by Kind of a big deal KarstenI in Wireless LAN
‎01-26-2023 06:01 AM
‎01-26-2023 06:01 AM
There is one thing that will not work: If you now have a LAG between the 3504 and the 2960, this must be removed and configured for individual interfaces as the LAG implementation on the WLC and the MS switches is not compatible. ... View more

Re: Wireless AP - How to create a Firewall rule to allow access to OpenVPN.

by Kind of a big deal KarstenI in Wireless LAN
‎01-26-2023 04:19 AM
1 Kudo
‎01-26-2023 04:19 AM
1 Kudo
The default port for OpenVPN is UDP/1194. If that is the port the OpenVPN server is using (it can be changed), you just have to allow this port. ... View more

Re: ACL rules traffic between DMZ to LAN

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-25-2023 01:40 PM
2 Kudos
‎01-25-2023 01:40 PM
2 Kudos
I typically implement this with four blocks of lines in the Firewall rules: Block1: Allow DMZ-system to any needed destination on other VLANs Block2: Deny DMZ-Network to all RFC1918, this is the LAN and all other DMZs Block3: Allow needed traffic to "any" which is the internet in this case Block4: Deny DMZ-network to any   Yes, this is much easier with zones like on firepower. But it works good. And always remember that the Firewall-Rules do not control traffic to VPN-destinations. This is done in the Site-to-Site-VPN section. ... View more

Re: VPN CLIENTS MX WITH ACTIVE DIRECTORY

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-25-2023 08:24 AM
4 Kudos
‎01-25-2023 08:24 AM
4 Kudos
Yes, it is typically a subscription. But not that expensive and with highly reduces support effort it will save money in the end. ... View more

Re: VPN CLIENTS MX WITH ACTIVE DIRECTORY

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-25-2023 08:19 AM
2 Kudos
‎01-25-2023 08:19 AM
2 Kudos
No, this will not be possible with the native client (which uses IPsec btw and not SSL/TLS). And do yourself a favour and go for AnyConnect for a highly reduced amount of grey hair ... ... View more

Re: VPN CLIENTS MX WITH ACTIVE DIRECTORY

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-25-2023 07:30 AM
2 Kudos
‎01-25-2023 07:30 AM
2 Kudos
If you want to assign differentiated permissions to VPN clients, your AnyConnect-users have to be authenticated with RADIUS (which in turn can use AD). The RADIUS server can return the name of a group-policy that restricts the users access. ... View more

Re: Port 21 disabled→designated

by Kind of a big deal KarstenI in Switching
‎01-25-2023 07:06 AM
1 Kudo
‎01-25-2023 07:06 AM
1 Kudo
The NICs don't report anything back and they don't participate in STP. The logs show a completely normal behaviour. When a port comes up it has to transition to designated to make sure the attached device will receive traffic. ... View more

Re: Port 21 disabled→designated

by Kind of a big deal KarstenI in Switching
‎01-25-2023 06:32 AM
‎01-25-2023 06:32 AM
This is typically the device.  ... View more

Re: Port 21 disabled→designated

by Kind of a big deal KarstenI in Switching
‎01-25-2023 06:22 AM
1 Kudo
‎01-25-2023 06:22 AM
1 Kudo
Port 4 got a link, Port 21 lost a link and got the link back. ... View more

Re: Disable Netbios with DHCP Option 43

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-25-2023 01:25 AM
4 Kudos
‎01-25-2023 01:25 AM
4 Kudos
As this is just an option in DHCP, I don't see any reason it shouldn't work. ... View more

Re: MX roadmap for three or more WAN uplinks

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-24-2023 06:52 AM
2 Kudos
‎01-24-2023 06:52 AM
2 Kudos
Sadly, also the new models are restricted to only two active WAN ports. ... View more

Re: MX roadmap for three or more WAN uplinks

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-24-2023 06:51 AM
2 Kudos
‎01-24-2023 06:51 AM
2 Kudos
Meraki really doesn't like to talk about roadmaps. Being able to use more than two WANs is quite often asked here in the community. But probably the core of the MX has to be changed significantly to make it work. Don't wait for it, likely it won't happen soon. But tell Meraki that you want to have this every time possible. ... View more

Re: Revealing Your 2023 Meraki Community All-Stars!

by Kind of a big deal KarstenI in Community Announcements
‎01-24-2023 06:23 AM
3 Kudos
‎01-24-2023 06:23 AM
3 Kudos
Woohoooooooo! Congratulation to the old and also to all the new All-Stars! 🙂 ... View more

Re: New MX 18.105 Stable Release Candidate - fixes for VPNs, smaller applia...

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-24-2023 03:17 AM
2 Kudos
‎01-24-2023 03:17 AM
2 Kudos
This is what I expected when I saw this new firmware. But the documentation is not yet updated. This would be great although IMO this feature is quite useless with only the MS390 supporting it on the switch side.  ... View more

Re: Windows 11 22H2 breaks MSCHAPv2 authentication for WiFi and wired conne...

by Kind of a big deal KarstenI in Full-Stack & Network-Wide
‎01-23-2023 12:03 PM
2 Kudos
‎01-23-2023 12:03 PM
2 Kudos
Thanks for the info. Just not sure why MS does this also when MSCHAPv2 is done through a TLS tunnel ... ... View more

Re: Allow more modern VPN protocols on MX VPN Client configuration

by Kind of a big deal KarstenI in Security / SD-WAN
‎01-23-2023 06:17 AM
2 Kudos
‎01-23-2023 06:17 AM
2 Kudos
Probably because everyone else just uses AnyConnect and is happy about a rock solid and powerful VPN. And no, the PLUS (or Advantage license as it's called nowadays) is not that expensive. ... View more

Re: General Setup

by Kind of a big deal KarstenI in New to Meraki
‎01-21-2023 08:12 AM
4 Kudos
‎01-21-2023 08:12 AM
4 Kudos
There is an extra Community for Meraki Go: https://community.meraki.com/t5/Meraki-Go-Community/ct-p/go This Community is about the Enterprise range of Meraki devices. ... View more

Re: How do i set a night shutoff timer for the public wifi

by Kind of a big deal KarstenI in Wireless LAN
‎01-21-2023 07:59 AM
4 Kudos
‎01-21-2023 07:59 AM
4 Kudos
Under Wireless -> SSID Availability you can set your schedule for your SSID. ... View more

Re: radius.meraki.com certificate renewal

by Kind of a big deal KarstenI in Mobile Device Management
‎01-20-2023 07:46 AM
‎01-20-2023 07:46 AM
@PaulF wrote: It might be any idea to start forcing the check in of devices, both from a client perspective, and also from an MDM perspective I tried that from the dashboard, but it didn't change anything.   How can I force it on a Windows Client? They all have the Agent installed. ... View more

Re: radius.meraki.com certificate renewal

by Kind of a big deal KarstenI in Mobile Device Management
‎01-20-2023 07:43 AM
‎01-20-2023 07:43 AM
Also, thanks for testing the script. I'm glad that it's already highlighted some devices 🙂 I was very pleased that the script also directly took the API-Key from the environment instead from the parameter. Perhaps the CSV would be better with one client per line. It would directly give an info about the amount of affected devices. ... View more
  • « Previous
    • 1
    • 2
    • 3
    • 4
    • 5
    • …
    • 54
  • Next »
Kudos from
User Count
van604
van604
1
MyHomeNWLab
MyHomeNWLab
7
PhilipDAth
Kind of a big deal PhilipDAth
383
CptnCrnch
Kind of a big deal CptnCrnch
255
Brash
Kind of a big deal Brash
76
View All
Kudos given to
User Count
AmyReyes
Community Manager AmyReyes
30
PhilipDAth
Kind of a big deal PhilipDAth
102
cmr
Kind of a big deal cmr
76
Brash
Kind of a big deal Brash
30
redsector
redsector
6
View All
My Accepted Solutions
Subject Views Posted

Re: Access Point Traffic Encryption

Wireless LAN
16 Wednesday

Re: RSTP root on remote Meraki MS series switches

Switching
242 4 weeks ago

Re: Meraki Switch management IP

Switching
259 ‎02-10-2023 04:23 AM

Re: How does speed affect the velocity test?

Wireless LAN
165 ‎02-10-2023 02:08 AM

Re: Meraki VMX Firewall

Security / SD-WAN
382 ‎02-02-2023 01:22 AM

Re: set specific static public IP to specified PC

Wireless LAN
127 ‎01-30-2023 12:13 AM

Re: MX64--- Unable to login using Serial Number for initial configuration

Security / SD-WAN
187 ‎01-16-2023 04:06 AM

Re: Meraki MX multiple /29 Public Blocks

Security / SD-WAN
234 ‎01-09-2023 01:46 PM

Re: iPSK without Radius not compatible with 6ghz?

Wireless LAN
302 ‎01-05-2023 02:40 PM

Re: Meraki MX support CoA with Cisco ISE?

Security / SD-WAN
769 ‎01-02-2023 03:23 AM
View All
My Top Kudoed Posts
Subject Kudos Views

Re: The Annual Community Points Contest is HERE!

Community Announcements
18 9060

Merakifying the Meraki Cloud Lamp

Meraki Projects Gallery
18 2038

Re: 🎁 🍰 🎈 Happy 5th Birthday, Meraki Community! 🎈 🍰 🎁

Community Announcements
11 2199

Re: The Annual Community Points Contest is HERE!

Community Announcements
11 8743

Re: It’s that time of year again 🧹🧼🧽 — share your spring cleaning pictur...

Community Announcements
10 1019
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki