The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About RomanMD
RomanMD

RomanMD

Building a reputation

Member since Apr 14, 2020

3 weeks ago
Groups
  • API Early Access Group

    API Early Access Group

    554
  • Cloud Monitoring for Catalyst - Early Availability Group

    Cloud Monitoring for Catalyst - Early Availability Group

    50
  • Meraki Network Lounge

    Meraki Network Lounge

    49
View All
Kudos from
User Count
EJN
EJN
2
Chris_Skees
Meraki Employee Chris_Skees
1
AmyReyes
Community Manager AmyReyes
2
alemabrahao
Kind of a big deal alemabrahao
1
MeredithW
Community Manager MeredithW
2
View All
Kudos given to
User Count
cmr
Kind of a big deal cmr
1
CptnCrnch
Kind of a big deal CptnCrnch
1
Brash
Kind of a big deal Brash
1
ww
Kind of a big deal ww
3
DarrenOC
DarrenOC
4
View All

Community Record

129
Posts
116
Kudos
15
Solutions

Badges

ECMS1
ECMS2
Everybody Wins
Year 5 - Solver Award
5th Birthday
100 Posts View All
Latest Contributions by RomanMD
  • Topics RomanMD has Participated In
  • Latest Contributions by RomanMD
  • « Previous
    • 1
    • 2
    • 3
    • 4
  • Next »

Re: Meraki MFA with MSP

by RomanMD in Dashboard & Administration
‎07-03-2021 03:18 AM
‎07-03-2021 03:18 AM
The other option would be, to have Local Dashboard accounts.. isn't it? I think local Dashboard accounts are allowed regardless other authentication options are enabled for the organization.  ... View more

Re: MR52 wireless instability with Win10 PCs

by RomanMD in Wireless LAN
‎07-03-2021 12:05 AM
4 Kudos
‎07-03-2021 12:05 AM
4 Kudos
You know what, a setting that's often ignored: Go in the Radio profiles and disable Client Balancing which is enabled by default.  I have experienced a lot of problems because of Client Balancing, and that should not be enabled if one wants to have a stable environment. ... View more

Re: DHCP option for TFTP server

by RomanMD in Wireless LAN
‎07-01-2021 08:04 AM
‎07-01-2021 08:04 AM
According to your initial request I think further clarifications are needed.  What devices do you manage? Access points only? Or do you have also Meraki MX and switches?   I am asking, because you say " but I need a DHCP option 150 to be configured on the Meraki wireless".   The DHCP options are set on the DHCP server. So if you have a Meraki MX or L3 switch which acts as DHCP for the Voice vlan - then you can set the option in the Meraki. Otherwise, if the DHCP is still a 3rd party machine (Windows, Linux, Infoblox, etc.) then you have nothing to configure in Meraki. ... View more

Re: DHCP option for TFTP server

by RomanMD in Wireless LAN
‎07-01-2021 07:41 AM
2 Kudos
‎07-01-2021 07:41 AM
2 Kudos
Option 150 is not predefined DHCP option, but you always can configure any custom options with values type String, HEX or IP.   So, the answer is - yes, you can configure option 150, either on L3 switch or on MX appliance.     ... View more

Re: MX68CW amber light

by RomanMD in Security / SD-WAN
‎06-23-2021 11:11 AM
1 Kudo
‎06-23-2021 11:11 AM
1 Kudo
I would connect the Internet Port of the MX to the router via a L2 switch. I would connect with a PC to the same VLAN and start the Wireshark to see the DORA process.  Also, make sure that the configuration in Internet Port 1 for VLAN Tagging says "Don't use vlan tagging". ... View more

Re: Witch transceiver to choose ?

by RomanMD in Switching
‎06-23-2021 10:58 AM
1 Kudo
‎06-23-2021 10:58 AM
1 Kudo
Hi,   1. you need to know if this is Single Mode or Multi mode fiber. Since you say this is OM4, then it must be Multimode.  For multimode:  MA-SFP-10GB-SR MS420 does not support 40Gb QSFP modules.   2. same as in the first point. ... View more

Re: Switch Naming Convention

by RomanMD in Switching
‎06-18-2021 03:02 AM
‎06-18-2021 03:02 AM
@rhbirkelund it only works like this if you have you housekeeping in Excel  😂 ... View more

Re: Remove Device from Network and Enable Warmspare in an Action Batch

by RomanMD in Developers & APIs
‎06-18-2021 02:53 AM
‎06-18-2021 02:53 AM
Never used the action batches at all, but I believe that for removing the device the action is "remove" not "delete". Not sure about the Warm Spare config. ... View more

Re: API - VPN Full-Tunnel Exclusion

by RomanMD in Developers & APIs
‎06-18-2021 02:37 AM
1 Kudo
‎06-18-2021 02:37 AM
1 Kudo
Maybe I've not understood you correctly, but for site-2-site vpn you can either have a default route checked if your MX is in Spoke mode or Exit Hub if it is in Hub mode.    If that is what you are trying to accomplish then the /networks/{networkId}/appliance/vpn/siteToSiteVpn should help you do the changes. ... View more

Re: /v1/organizations/{organization-id}/appliance/uplink/statuses

by RomanMD in Developers & APIs
‎06-17-2021 12:49 AM
‎06-17-2021 12:49 AM
Description:List the uplink status of every Meraki MX, MG and Z series devices in the organization   If you don't have any of those devices in the organization, then you will have an empty array, but that's nothing you can't handle. Just check the length of the response array, if it is 0 -> skip and go further or whatever logic you need. ... View more

Re: VPN, subnet, and shared folder

by RomanMD in Security / SD-WAN
‎06-16-2021 06:38 AM
‎06-16-2021 06:38 AM
There is no trick for this.  Most probably you are trying to access the shared folders via name which cannot be resolved.  You can try to access them via IP address, or make sure you access them via FQDN which can be resolved. Also, worth looking if there are any group policies/firewall rules which will block port 445.     ... View more

Re: co-term licensing type installed

by RomanMD in Developers & APIs
‎05-19-2021 02:34 PM
1 Kudo
‎05-19-2021 02:34 PM
1 Kudo
Unfortunately, you don't seem to be able to do much when the org is in Co-Term. I also found it frustrating but all the Endpoints are mostly for the PDL model. ... View more

Re: Python getting UserID of Guest User with merakiAuthUsers query mail add...

by RomanMD in Developers & APIs
‎05-18-2021 10:56 AM
1 Kudo
‎05-18-2021 10:56 AM
1 Kudo
The most obvious way is to loop thru the user list:     import meraki API_KEY = 'xxxxxxxxxxxxxx' dashboard = meraki.DashboardAPI(API_KEY) network_id = 'xxxxxxxxxxxxxxx' required_username = 'myuser@name.com' users = dashboard.networks.getNetworkMerakiAuthUsers( network_id ) for user in users: if user["email"] == required_username: pprint(user)     Pythonic way would be to substitute the for loop with list comprehension :   myuser = [user for user in users if user["email"]==required_username] pprint(myuser)     ... View more

Re: Layer 3 Switching and the Client VPN

by RomanMD in Security / SD-WAN
‎05-18-2021 10:25 AM
‎05-18-2021 10:25 AM
The Meraki world is not different than normal Cisco world. Having that vlan100 on both MX and core switch and acting as management vlan for switches doesn't sound good for me. That's the only thing that I want to point.   We have similar setup in our location.  I have the management vlan on MX which is a native vlan on the MX port and acting as management for switches, then another vlan on the switch core for management of the access points. I need another vlan just because S2S VPN, but in your case another vlan for AP's is not needed.   ... View more

Re: Layer 3 Switching and the Client VPN

by RomanMD in Security / SD-WAN
‎05-18-2021 09:36 AM
1 Kudo
‎05-18-2021 09:36 AM
1 Kudo
I don't have the full picture of your network but assuming you only have Mx, switch and Client VPN, and everything is behind the switches then: what is the Management VLAN all about? Is it the management for the switches only? Then it does not make any sense to have the vlan100 interface on the stack. It is better just to have that as native vlan on the MX port.  If it is for some other purposes, then again... what's the purpose? ... View more

Re: Layer 3 Switching and the Client VPN

by RomanMD in Security / SD-WAN
‎05-16-2021 12:51 PM
2 Kudos
‎05-16-2021 12:51 PM
2 Kudos
Have you checked the RADIUS logs from which IP the requests are coming from?  If my memory serves me well, when I was testing the Client-VPN the request to Radius were coming with the source IP of the highest vlan id.  Now, that you moved the VLANs to the switch, the IP from which the requests are going out to RADIUS have also, probably, changed.  Can you verify that? ... View more

Re: Running scheduled scripts with API keys

by RomanMD in Developers & APIs
‎05-03-2021 10:36 AM
1 Kudo
‎05-03-2021 10:36 AM
1 Kudo
I do two three different things: 1. either store in the environment variable  2. either store in the database in the setting table (usually using this when the scripts run on Django) 3. either way - I have an encryption/decryption algorithm, so the key is not stored in plain text. It does not mean that the key is fully safe, as long as one will have access to the algorithms, but at least having the encrypted API key does not make much sense for some .... ... View more

Re: SCRIPT CREATION

by RomanMD in Wireless LAN
‎05-03-2021 10:27 AM
‎05-03-2021 10:27 AM
Hello,   it is possible, of course. It is possible to create/update almost any settings from from dashboard, but this requires you to be familiar with some programming/scripting language.   Assuming that by "blocking IP" you mean that you want a L3 firewall rule or an inbound firewall rule, here are the Endpoint descriptions. https://developer.cisco.com/meraki/api-v1/#!update-network-appliance-firewall-l-3-firewall-rules https://developer.cisco.com/meraki/api-v1/#!update-network-appliance-firewall-inbound-firewall-rules     ... View more

Re: software-defined radio for Dual 5ghz on WIFI 6 AP ?

by RomanMD in Wireless LAN
‎04-22-2021 09:49 AM
1 Kudo
‎04-22-2021 09:49 AM
1 Kudo
NBAR2 will not disturb the clients at all, but NBAR2 will not be available in a mixed environment. I have just discovered this hard way few days ago when my script had trouble adding one AP to a network.   You want to read "Disabling NBAR" paragraph. https://documentation.meraki.com/MR/Firewall_and_Traffic_Shaping/Network-Based_Application_Recognition_(NBAR)_integration_with_MR_access_points ... View more

Re: software-defined radio for Dual 5ghz on WIFI 6 AP ?

by RomanMD in Wireless LAN
‎04-20-2021 11:11 PM
1 Kudo
‎04-20-2021 11:11 PM
1 Kudo
I am totally with Philip. Don't mix. Either build the environment with MR46 (preferred), either only Wifi5. You will start running into different issues and unavailability of certain features like NBAR2.   When you'll have the env ready and working and later on you will want to add another wifi5 AP, you will have to disable traffic analysis, add new ap, enable traffic analysis. This one problem, and I am not sure which other may appear... ... View more

Re: SSID Tunneling on MX, different VLANS

by RomanMD in Security / SD-WAN
‎04-20-2021 01:20 AM
3 Kudos
‎04-20-2021 01:20 AM
3 Kudos
I have a replication of Cisco WLC controllers infra in few locations and it is exactly like you said. Except, I am doing exactly like WW suggested - on the switch I have a trunk port with native vlan for management, and other vlans to tunnel different type of clients, including Guests. ... View more

Re: Suggestion: Make it harder to change MX operation mode from Routed to P...

by RomanMD in Security / SD-WAN
‎04-17-2021 08:51 AM
1 Kudo
‎04-17-2021 08:51 AM
1 Kudo
I'll agree with the OP. Changing a mode of a device is something important. And since they can offer a double confirmation for s2s route overlap, they can offer also a double confirmation for changing the mode.   I'll disagree with UCert regarding the rights, especially with the lack of access rights granularity (full or readonly only) Meraki offers. ... View more

Re: SSID Get Radius host IP or URL

by RomanMD in Developers & APIs
‎04-13-2021 06:06 AM
‎04-13-2021 06:06 AM
in Python:  when Radius is enabled on SSID the result dict will have a key "radiusServers" which will contain a list of dicts, for every radius server, however, if the SSID does not have Radius active then the key will not exist and you can't address it via [""]. Use dict get() method to check if the key exists.   {'authMode': '8021x-radius', 'availabilityTags': [], 'availableOnAllAps': True, 'bandSelection': 'Dual band operation with Band Steering', 'concentratorNetworkId': 'N_111111111111111111', 'dot11r': {'adaptive': False, 'enabled': False}, 'dot11w': {'enabled': True, 'required': False}, 'enabled': True, 'encryptionMode': 'wpa-eap', 'ipAssignmentMode': 'VPN', 'mandatoryDhcpEnabled': True, 'minBitrate': 12, 'name': 'thisismyssidname', 'number': 2, 'perClientBandwidthLimitDown': 0, 'perClientBandwidthLimitUp': 0, 'perSsidBandwidthLimitDown': 0, 'perSsidBandwidthLimitUp': 0, 'radiusAccountingEnabled': False, 'radiusAttributeForGroupPolicies': 'Filter-Id', 'radiusAuthenticationNasId': '$NODE_MAC$:$VAP_NUM$', #this seems to be future settings in MR28 'radiusCalledStationId': '$NODE_MAC$:$VAP_NAME$', #this seems to be future settings in MR28 'radiusCoaEnabled': True, 'radiusFailoverPolicy': None, 'radiusLoadBalancingPolicy': None, 'radiusOverride': False, 'radiusProxyEnabled': False, 'radiusServers': [{'host': '10.10.10.10', 'id': 111111111111111111, 'port': 1812}, {'host': '11.11.11.11', 'id': 222222222222222222, 'port': 1812}], 'radiusTestingEnabled': False, 'splashPage': 'None', 'ssidAdminAccessible': False, 'visible': True, 'vlanId': 888, 'wpaEncryptionMode': 'WPA1 and WPA2'}         ssids = dashboard.wireless.getNetworkWirelessSsids(networkId) for ssid in ssids: radius_server_list = [] if ssid.get("radiusServers"): #Only execute if radiusServers key exists for server in ssid.get("radiusServers"): radius_server_list.append(server["host"]) print(radius_server_list)     ... View more

Re: get-organization-licenses  state field value description

by RomanMD in Developers & APIs
‎03-30-2021 12:26 AM
‎03-30-2021 12:26 AM
This is my guess, because I don't use PDL licensing: "claimDate" : "2019-08-29T12:40:10Z" , "activationDate" : "2019-09-01T15:01:46Z" , "expirationDate" : "2020-10-30T15:01:46Z"   state : 'active',   --- description ??? -> the license is assigned to a device. This is expected state of the license in the org. 'expired',--- description ??? -> the license is expired. expirationDate is in the past. 'expiring',--- description ??? -> the license expirationDate is less than 30 days from now. 'unused',--- description ??? -> License was claimed in the Organization but was not assigned to any device. 90 days have not passed yet, so activationDate has not yet started. 'unusedActive'--- description ??? -> License is not assigned to any device but activationDate is in the past. or 'recentlyQueued'--- description ??? -> can't imagine what this could be. ... View more

Re: What's the first thing you think about when you think about your networ...

by RomanMD in Dashboard & Administration
‎03-27-2021 11:10 AM
3 Kudos
‎03-27-2021 11:10 AM
3 Kudos
As an admin of more than 10 Meraki Organizations, I've created a scrip using the all-mighty API's, to send me each  morning the Change log for yesterday, so that I can see what my peers or junior admins have changed in the Organizations and to act accordingly. So I start my day by scrolling thru the change log. ... View more
  • « Previous
    • 1
    • 2
    • 3
    • 4
  • Next »
Kudos from
User Count
EJN
EJN
2
Chris_Skees
Meraki Employee Chris_Skees
1
AmyReyes
Community Manager AmyReyes
2
alemabrahao
Kind of a big deal alemabrahao
1
MeredithW
Community Manager MeredithW
2
View All
Kudos given to
User Count
cmr
Kind of a big deal cmr
1
CptnCrnch
Kind of a big deal CptnCrnch
1
Brash
Kind of a big deal Brash
1
ww
Kind of a big deal ww
3
DarrenOC
DarrenOC
4
View All
My Accepted Solutions
Subject Views Posted

Re: Cloud Monitoring for Catalyst dashboard join troubleshooting

Cloud Monitoring for Catalyst Discussions
2503 ‎06-24-2022 05:57 AM

Re: SNMP Issue

Dashboard & Administration
684 ‎06-22-2022 12:21 AM

Re: What if a device with a Per-Deveice License is broken?

New to Meraki
325 ‎06-22-2022 12:02 AM

Re: AnyConnect SAML w/Azure AD Enterprise application question

Security / SD-WAN
380 ‎06-15-2022 07:31 AM

Re: Authorization for "Administered Orgs deep link"

Developers & APIs
2427 ‎08-24-2021 03:32 AM

Re: Advanced License

Dashboard & Administration
1399 ‎07-30-2021 01:24 PM

Re: Local Status Page Password

Security / SD-WAN
1253 ‎07-15-2021 12:44 PM

Re: SAML SSO - user/email address removal

Dashboard & Administration
2070 ‎07-13-2021 10:30 AM

Re: DHCP option for TFTP server

Wireless LAN
2712 ‎07-01-2021 08:04 AM

Re: Remove Device from Network and Enable Warmspare in an Action Batch

Developers & APIs
612 ‎06-18-2021 02:53 AM
View All
My Top Kudoed Posts
Subject Kudos Views

Meraki AnyConnect + ADFS OnPrem SAML authentication guide

Security / SD-WAN
8 457

Re: Load balancing question

Security / SD-WAN
6 1123

Re: What if a device with a Per-Deveice License is broken?

New to Meraki
5 325

Re: Recognizing September's Members of the Month

Community Announcements
4 403

Re: Local Status Page Password

Security / SD-WAN
4 1253
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki