The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About KarstenI
KarstenI

KarstenI

Kind of a big deal

Member since Mar 22, 2019

Online

Karsten Iwen

Germany

https://cyber-fi.net

Freelance Consultant and instructor. Need help with your Meraki project? Now you know who to contact. ;-)

Groups
  • CLUS 2022 Meraki Lounge

    CLUS 2022 Meraki Lounge

    28
  • Meraki Network Lounge

    Meraki Network Lounge

    49
View All
Kudos from
User Count
PhilipDAth
Kind of a big deal PhilipDAth
359
MajorTom
MajorTom
1
Boyan1
Boyan1
1
Jeizzen
Jeizzen
1
CptnCrnch
Kind of a big deal CptnCrnch
245
View All
Kudos given to
User Count
AmyReyes
Community Manager AmyReyes
20
cmr
Kind of a big deal cmr
72
ww
Kind of a big deal ww
31
CptnCrnch
Kind of a big deal CptnCrnch
49
BlakeRichardson
Kind of a big deal BlakeRichardson
27
View All

Community Record

1341
Posts
1803
Kudos
122
Solutions

Badges

CMSS
ECMS1
ECMS2
Meraki FIT Level One
Meraki FIT Level Two
Meraki360 View All
Latest Contributions by KarstenI
  • Topics KarstenI has Participated In
  • Latest Contributions by KarstenI
  • « Previous
    • 1
    • …
    • 50
    • 51
    • 52
  • Next »

Re: Meraki MX84 - NAT Internal IP to another Internal IP

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-22-2020 05:34 AM
‎09-22-2020 05:34 AM
NAT is only done when the communication is done through the WAN-port. The MX does not have this flexibility as ist is available for example on the Cisco ASA/FTD. ... View more

Re: wireless client DNS issue with AP through site-to-site vpn tunnel.

by Kind of a big deal KarstenI in Wireless LAN
‎09-22-2020 05:27 AM
‎09-22-2020 05:27 AM
Did you change your Umbrella-Setup recently? And who sends the DNS-requests to Umbrella? The client, the MX, a VA? I would first look at the Umbrella dashboard and/or the MX-Umbrella-config if your domain names (the domains that should be processed by your DNS) are configured correctly.  ... View more

Re: wireless client DNS issue with AP through site-to-site vpn tunnel.

by Kind of a big deal KarstenI in Wireless LAN
‎09-21-2020 02:11 PM
‎09-21-2020 02:11 PM
- Do the WLAN clients receive the right DNS-server? - Is it only DNS and the rest is working as expected? If nothing works, Did you perhaps forgot to allow the WLAN clients access to local LAN under Wireless -> Firewall? ... View more

Re: Forwarding web traffic to proxy

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-21-2020 02:05 PM
‎09-21-2020 02:05 PM
Yes, sadly there is no WCCP. Is your L3-switch also Meraki? If it's a "traditional" Catalyst, that one could support WCCP. Although not optimal, you could use WPAD-files and provide the location of the files through DNS. ... View more

Re: Default route on mx

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-21-2020 05:17 AM
2 Kudos
‎09-21-2020 05:17 AM
2 Kudos
A default route is always 0.0.0.0/0 and not /24. What is your topology. The other gateway is connected to a LAN-Port and not the WAN port? In general, the Internet should be connected to WAN. ... View more

Re: Cisco Umbrella 🆚 OpenDNS

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-21-2020 03:19 AM
1 Kudo
‎09-21-2020 03:19 AM
1 Kudo
If you are not aware of your license, then it is very likely that you run the stable version. v15 is Beta and typically only used when a specific function is needed. You see the versions on Security-Appliance -> Appliance status.   For the license, there are Enterprise, Advanced Security and SD-WAN. You need at least Advanced Security to integrate Umbrella into MX. You see your license under Organisation -> License Info.   I would go a phased approach: 1) Buy the Umbrella DNS Essentials license for the amount of users in your organisation. 2) Enroll two Umbrella VMs in your main office and configure them in regards to the Umbrella Documentation. When finished, all users in the Headquarter are protected. 3) Do you have Meraki APs? Then the next step is to integrate Umbrella into your SSID. 4) Now some more months are gone and you can decide how to go on for your branches. Either with dedicated Umbrella VMs or you decide that it is safe enough to go to MX15 and activate the native integration.   ... View more

Re: Cisco Umbrella 🆚 OpenDNS

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-21-2020 02:08 AM
1 Kudo
‎09-21-2020 02:08 AM
1 Kudo
OpenDNS does not have any solution for enterprise customers. That is what Umbrella offers and what matches your use case. You can integrate it with the MX when you run MX version 15 and have the security-license (SD-WAN is not needed). Or for all sites with VM-hosts, there are lightweight VMs that control the DNS-handling. ... View more

Re: Cisco Umbrella 🆚 OpenDNS

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-21-2020 01:25 AM
1 Kudo
‎09-21-2020 01:25 AM
1 Kudo
First: OpenDNS are the free and publicly usable DNS servers operated by Cisco. Umbrella is a product that you can subscribe to from Cisco, same as subscriptions like "OpenDNS Prosumer". You are probably asking for the difference of buying Umbrella separately or combined with the Meraki License. It's really easy to operate Umbrella with the Meraki license that includes Umbrella. You only have one Dashboard and the configuration is super easy. The downside is, up to now you only have the possibility to protect wireless users connected to your MRs. With the "regular" Umbrella license you can protect also your wired- or VPN-Users. And you have much more flexibility in your Umbrella configurations. Another drawback with the MR Advanced license (that is the one including Umbrella). You have to use single device licensing which again can be a little more complex for your organisation. ... View more

Re: VPN Subnet Translation-Problem between MX100/ASA5515 and MX64 - AuttVPN

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-21-2020 12:32 AM
‎09-21-2020 12:32 AM
" VPN Subnet Translation " is only needed if you have sites with identical IP networks and you can't renumber any of them. Based on you addressing, I assume that the MX is configured as one-armed concentrator in an ASA-DMZ? You say that data rom remote-to-main flows. Does this mean you have bidirectional communication? Then there is obvious no routing-problem. It still could be an access-control-problem on the ASA and/or MX. Capture the traffic along the way from source to destination. I would start with: 1) ASA outgoing interface 2) main MX VPN Tunnel 3) Branch MX ... View more

Re: Mass enrollment into MDM

by Kind of a big deal KarstenI in Mobile Device Management
‎09-18-2020 10:26 AM
‎09-18-2020 10:26 AM
est way for that is using the Apple Device Enrollment Program (DEP) in case you are talking about iOS devices: https://documentation.meraki.com/SM/Device_Enrollment/Enrolling_and_Supervising_iOS_Devices_using_Apple_Configurator_2.0   For Android, there is a specifi setup routine that the user can use. ... View more

Re: Content Filtering on Z3 with full tunnel

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-18-2020 10:22 AM
‎09-18-2020 10:22 AM
Yes, that was a faulty assumption. Content-filtering is not done when the traffic reaches the MX over the VPN-Tunnel. Best solution (IMO): Deploy Cisco Umbrella to the branches and configure Content-filtering there. ... View more

Re: Threat Protection Whitelisted Rules

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-18-2020 06:40 AM
3 Kudos
‎09-18-2020 06:40 AM
3 Kudos
Whitelisting of rules is a part of a process named "IPS tuning". Typically it is done (not a complete list) when a rule causes a false positive and or processing the rule is a waste of resources because they are not relevant in the environment. All whitelisted rules, the same as with firewall rules, should be evaluated from time to time to see if they are still implemented correctly. At least I have seen lots of whitelisting that was added when troubleshooting problems. Based on "oh, there is an event in the IPS dashboard, let's disable this rule" the rule was disabled, but regardless if this was the problem or not, the whitelisting stayed in the config.   Given that the MX-IPS is meant to be more or less a "black box" without extensive tuning possibilities, I would look up the rules in the Snort documentation and enable them if it is likely that they will not harm you.   Another approach (but with more risk), switch from Prevention to Detection, and delete the whitelist. If no events will show up, you can go back to Prevention. If Events still show up, it will get harder if it is traffic that is needed for operation. But then, there are no easy rules on how to proceed. ... View more

Re: Meraki devices backup eviences

by Kind of a big deal KarstenI in Full-Stack & Network-Wide
‎09-18-2020 05:44 AM
1 Kudo
‎09-18-2020 05:44 AM
1 Kudo
I don't think that you can get a good answer here as there is nothing like a backup in the Dashboard. If you want to achieve something a backup is for, like your mentioned getting back to operation after a disaster, there is only one way: Generate a script that builds all your networks via API and document exactly where manual adjustment is needed if the API can't do it.   ... View more

Re: DHCP/VLAN issue

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-18-2020 05:34 AM
‎09-18-2020 05:34 AM
Can you explain what you mean with " and I need to be on this VLAN also "? If your DHCP-server is in VLAN 1 and the client is in VLAN X, then DHCP-relay is the feature to use. If your client is in the same VLAN as the DHCP-server, no DHCP-functionality is needed on the L3 device (the MX) between them as the DHCP-server can directly give the client its config. ... View more

Re: Assign layer 7 rules to WAN2

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-18-2020 02:48 AM
‎09-18-2020 02:48 AM
@Cain wrote: Indeed this is my current work around.  I have a webhook that fires off a Python script that modifies the layer 7 rules when the WAN link changes. Do you have a blog? Would be worth publishing your solution. ... View more

Re: Assign layer 7 rules to WAN2

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-18-2020 02:24 AM
‎09-18-2020 02:24 AM
I also have no easy solution and having separate rules per WAN-interface would be really great for this use-case. But how are your Python skills? Based on the availability of the primary link, you could change the L7 firewall rules with the Dashboard-API. ... View more

Re: Can the MG21 behave like the Router?

by Kind of a big deal KarstenI in Wireless WAN
‎09-18-2020 02:13 AM
1 Kudo
‎09-18-2020 02:13 AM
1 Kudo
From all possible solutions, that would probably the most expensive one with the least features. As mentioned, a small MX or even a Z3 with an attached LTE-dongle would be probably much better. ... View more

Re: how to blocked porn video sites Meraki

by Kind of a big deal KarstenI in Dashboard & Administration
‎09-17-2020 07:34 AM
2 Kudos
‎09-17-2020 07:34 AM
2 Kudos
If you have some dollars of the budget left, look at Cisco Umbrella. In my experience, the Blocking of inappropriate content is more powerful than the MX-built-in content filter. ... View more

Re: Deploying Meraki Wi-Fi in a Warehouse for scanning guns

by Kind of a big deal KarstenI in Wireless LAN
‎09-16-2020 10:09 AM
‎09-16-2020 10:09 AM
"Expensive and extreme" is relative if there is a business need for wireless on this one gun ... And probably more will be added later, right? I would look for a company specialised in Warehouse Wifi. There is too much that can go wrong there. And don't focus on specific APs to use. With RF-Guns, you will never need one of the High-End APs with many spatial streams, but you will likely need one with external antennas. ... View more

Re: telnet tool needed in MS switches

by Kind of a big deal KarstenI in Switching
‎09-16-2020 10:02 AM
2 Kudos
‎09-16-2020 10:02 AM
2 Kudos
Yes, a "ping tcp" or similar would be great. Did you add a wish for that? I just did. 😉 ... View more

Re: ASA to MX migration, sanity check

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-16-2020 09:59 AM
2 Kudos
‎09-16-2020 09:59 AM
2 Kudos
All in all, that should work. If you have a spare public IP, I would put the MX in parallel to the ASA and migrate the branches. This way you don't have to change the MX when done and you can also directly use the security-features of the MX for your outgoing traffic. ... View more

Re: Does adding devices to the MDM require a licence?

by Kind of a big deal KarstenI in Mobile Device Management
‎09-16-2020 04:53 AM
2 Kudos
‎09-16-2020 04:53 AM
2 Kudos
It's under Organization -> License Info. Could look similar to this:     ... View more

Re: Does adding devices to the MDM require a licence?

by Kind of a big deal KarstenI in Mobile Device Management
‎09-16-2020 04:46 AM
1 Kudo
‎09-16-2020 04:46 AM
1 Kudo
Each device will consume one license: https://documentation.meraki.com/zGeneral_Administration/Licensing/Systems_Manager_Licensing ... View more

Re: Meraki Templates

by Kind of a big deal KarstenI in Security / SD-WAN
‎09-16-2020 02:39 AM
1 Kudo
‎09-16-2020 02:39 AM
1 Kudo
Before planning for templates, make sure that you understand what they are and how they work. Especially, look at the way IP addressing is done. If you come from a traditional setup with summarized networks for your branches, you will be a little bit "shocked" how addressing is done here. And you should be aware that every change of the addressing in the template will renumber the addressing in the networks.  At least for me, these are too many drawbacks and I only use individual networks. For automation, the Meraki API will help you to keep your networks consistent.   https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Best_Practice_Design_-_MX_Security_and_SD-WAN/MX_Templates_Best_Practices   ... View more

Re: Aesthetically pleasing access points

by Kind of a big deal KarstenI in Wireless LAN
‎09-15-2020 01:06 PM
1 Kudo
‎09-15-2020 01:06 PM
1 Kudo
Never used them myself, but have heard good things about http://www.acceltex.com/skins/ ... View more
  • « Previous
    • 1
    • …
    • 50
    • 51
    • 52
  • Next »
Kudos from
User Count
PhilipDAth
Kind of a big deal PhilipDAth
359
MajorTom
MajorTom
1
Boyan1
Boyan1
1
Jeizzen
Jeizzen
1
CptnCrnch
Kind of a big deal CptnCrnch
245
View All
Kudos given to
User Count
AmyReyes
Community Manager AmyReyes
20
cmr
Kind of a big deal cmr
72
ww
Kind of a big deal ww
31
CptnCrnch
Kind of a big deal CptnCrnch
49
BlakeRichardson
Kind of a big deal BlakeRichardson
27
View All
My Accepted Solutions
Subject Views Posted

Re: Meraki VMX Firewall

Security / SD-WAN
114 Thursday

Re: set specific static public IP to specified PC

Wireless LAN
80 a week ago

Re: MX64--- Unable to login using Serial Number for initial configuration

Security / SD-WAN
159 3 weeks ago

Re: Meraki MX multiple /29 Public Blocks

Security / SD-WAN
170 a month ago

Re: iPSK without Radius not compatible with 6ghz?

Wireless LAN
253 ‎01-05-2023 02:40 PM

Re: Meraki MX support CoA with Cisco ISE?

Security / SD-WAN
651 ‎01-02-2023 03:23 AM

Re: vAnalytics?

Meraki Insight
354 ‎12-09-2022 06:29 AM

Re: MX Firmware 16.x and 17.x compatibility between different MX devices

Security / SD-WAN
386 ‎12-02-2022 04:14 AM

Re: What is this "Enforce" in v17 L3 inbound rules

Security / SD-WAN
263 ‎11-30-2022 07:47 AM

Re: Limiting Internal traffic between two subnets

New to Meraki
217 ‎11-17-2022 07:19 AM
View All
My Top Kudoed Posts
Subject Kudos Views

Re: The Annual Community Points Contest is HERE!

Community Announcements
18 8556

Merakifying the Meraki Cloud Lamp

Meraki Projects Gallery
18 1809

Re: 🎁 🍰 🎈 Happy 5th Birthday, Meraki Community! 🎈 🍰 🎁

Community Announcements
11 2076

Re: The Annual Community Points Contest is HERE!

Community Announcements
11 8239

Re: Sign the Community’s birthday card!

Community Announcements
10 2034
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki