Community Record
203
Posts
106
Kudos
5
Solutions
Badges
Dec 9 2022
2:02 AM
3 Kudos
I'm calling MTU on this problem too. I had a similar issue where a couple of our WAN sites would not receive the accept response, and would appear as a Radius timeout error in the dashboard logs, but the request was being received by the radius server. We use SDWan where the WAN traffic is encrypted, add this to using EAP/TLS client certificate authentication, and the packets were too big for the MTU packet size at these sites, hence were being fragmented. You can try pinging the sites (using the -f and -l and mtu size (1180 in this example) switches e.g ping 10.8.6.1 -f -l 1180 and check if the packet size needs to be lower at your affected sites before fragmentation (change the value (1180) up and down until you get a reply that is not fragmented), compared to your working sites You made be able to change the MTU on your routers/switches etc at the remote site, or change the MTU size in the ISE radius config for these sites (radius connection/auth policies) You could also try sending the requests via the Meraki cloud radius and then into your on-prem radius (put the affected AP's into a different network and change the radius destination to the Meraki cloud radius), these requests will then go out/back in unencrypted (lower packet size), which may prove if it is MTU related or not. You can also try setting up a different authentication method, say MSCHAP, and try authenticating with client username/password only (no EAP/TLS certs), if this works then it's also most likely MTU/defragmentation good luck
... View more
Nov 16 2022
5:39 AM
General question about the UNII-3 channels...If everything is working fine, and I'm using 20MHz channels, will enabling UNII-3 channels cause issues in that are all clients able to use these higher channels? If not I could creating dead spots for some clients in the building where AP's switch to these higher channels. I appreciate that these channels have a lower maximum power transmit rating (23dBm) Thanks
... View more
Jul 19 2022
6:57 AM
I had a site with 8 x MR44 that had lost it's internet connection for 3 days, once the internet was restored, the AP's would not come online in the dashboard but I could ping them OK- I had to cycle the POE ports on the switch (reboot the AP's) to get them to come online. V28.6.1 firmware. Clients were unable to connect while they were showing as offline
... View more
Feb 10 2020
9:22 AM
@yepper Hi, what model AP's are you running that these cams are connected to ? Thanks
... View more
Feb 4 2020
9:57 AM
@randhall That's worrying. I was all set to upgrade our estate this coming week, starting with a small group of AP's, but will hold off until I hear the outcome of your problem. I'll do some testing in our lab setup on a MR32 here to see if I can replicate the issue. Please keep us updated Thanks
... View more
Jan 6 2020
9:12 AM
3 Kudos
@CodeMercenary So under the MR dashboard under clients, you can see in the dashboard that they have previously connected (last 30 days) and/or are currently connected. Now that you have them listed in dashboard (under OS they are indentified as Windows 7 - you can search for just windows 7 etc), if you select each one and then apply to a policy you have created that either limits what they can access or block them entirely using the default 'block' action
... View more
@NolanHerring It's in the doc Phil linked further up under number of devices per network Number of Devices per Network The number of Meraki devices (MX, MS, MR, MV, etc., not user devices) per network is a much more variable number that does not have a general recommendation. It will vary from case to case. Note that there is a limit of 1000 devices per network. Networks exceeding this number should be split. However, it is generally uncommon for networks to approach this number unless they have a very large number of cameras or wireless access points. If this is the case, it is recommended to split the networks based on physical areas or use cases.
... View more
Dec 5 2019
3:06 AM
Perhaps they are referring to the 1000 access point limit per network (as opposed to the 25k limit per organisation). Although best practice for autoRF would be not to have that kind of number in a single network (unless of course that was one (BIG) single geographic location)
... View more
Dec 4 2019
6:47 AM
If you are uncomfortable running beta or 'stable release candidate' firmware (i.e. 26.6) and are having this issue, just log a support call so they can apply the option on your dashboard for your network(s) for you to schedule a roll back to 25.13 (or whatever version works for you)
... View more
Nov 27 2019
7:07 AM
1 Kudo
Was considering moving from 25.13 to the latest 'stable' 25.14 version... Random disappering SSiD's ? Think I'll pass.
... View more
Nov 26 2019
6:05 AM
MR18 is not an old model, end of sale was only 2017. It's bugs like these (if it is as a result of a bug introduced in new firmware) that worry me, and with end of support at 2024 for this model we shouldn't have to bin these older models or have them firmware locked. I still have a few MR16's, again firmware locked because of a bug introduce in 25.x I hopeful that the firmware release quality control improves significantly in the future
... View more
Nov 4 2019
3:10 AM
2 Kudos
They might of meant AutoRF, if so, https://documentation.meraki.com/MR/Monitoring_and_Reporting/Location_Analytics/Meraki_Auto_RF%3A__Wi-Fi_Channel_and_Power_Management
... View more
Oct 28 2019
2:08 AM
1 Kudo
Goodbye and good luck Caroline !, and thanks for building the community from scratch. Welcome back anytime you need a rest from the new day job ! Paul
... View more
Oct 25 2019
6:04 AM
1 Kudo
I find the local status page (my.meraki.com) a handy tool for clients to check what connected AP, signal strength and throughput ('run speed test') if experiencing any issues. If you, like me, find it handy, just make the local admin password something impossibly long and complex, you do this in one place, in the dashboard, Network-Wide>General
... View more
" and we can't downgrade to an older more reliable firmware because it's not allowed " Have you checked with support ? I remember a couple of years ago they gave us the ability to roll back to a much earlier version long after that option had dissapered in the dashboard
... View more
Aug 21 2019
5:08 AM
7 Kudos
Happy Birthday all ! Thanks for all of the tips and advice, a great community Special thanks to @MeredithW and @CarolineS for keeping it buzzing !
... View more
Jul 5 2019
3:38 AM
3 Kudos
Check the cabling, patch port, switch port to the affected AP. Have seen it where the AP is powered up and in Mesh mode but not able to operate as a gateway, turned out to be cabling that had degraded. Try rebooting the ap before you do that
... View more
In your PEAP authentication settings for your Machine Network Policy, in NPS (under constaints tab), have you got Eap types 'smart Card or other certificate' in there ?
... View more
Apr 4 2019
8:10 AM
@BrandonSwrote: Is the problem that they can't establish VPN connection or they connect and then can't access resources? I have had the latter problem with Meraki NAT/DHCP mode due to 10.0.0.0/8 conflicting. Maybe you also have some subnet overlap between your guest network and the remote side? My money's on Brandon's theory, we have run into this exact problem a few times. Ended up having create a new SSID which was bridged using a different client subnet
... View more
Feb 15 2018
8:29 AM
Yes, you can. Firewall rules are setup in the same way per SSiD. Just make sure that at the bottom of your layer 3 rules, you deny Local Lan access (if that's the intention)
... View more
Dec 14 2017
7:26 AM
1 Kudo
You can ask support to enable a switch in the dashboard for your network to turn off meshing. I recently asked for this, as I was seeing a WEP encrypted hidden SSiD from every Meraki AP being broadcast on both 2.4ghz and 5ghz (these are used for the meshing functionality), and wanted to cut down on unnecessary radio/SSi'd on our network (as we do not or have plans to use meshing) Unfortunately, even after turning off the meshing option in dashboard, you will still see these hidden ssid's broadcasting on your network. Meraki tell me that they cannot turn these networks off, they are permanently on by design !!
... View more
Oct 18 2017
7:05 AM
After upgrading to MR 24.11 2 days ago, I noticed there's a new version...This officially lists the KRACK vulnerabilities, does it add anything to MR 24.11 ? EDIT: I've just noticed these are new vulnerabilities, not KRACK related
... View more
Oct 16 2017
5:48 AM
1 Kudo
Comments from other community memebers that version 24.11 does include a fix. Can Meraki provide official statement here to confirm that fix is included in 24.11 ??
... View more
- « Previous
- Next »
My Accepted Solutions
Subject | Views | Posted |
---|---|---|
13219 | Jan 6 2020 9:12 AM | |
1759 | Nov 4 2019 3:10 AM | |
12480 | Jun 26 2019 2:14 AM | |
4815 | Feb 15 2018 8:29 AM | |
4974 | Dec 14 2017 7:26 AM |
My Top Kudoed Posts
Subject | Kudos | Views |
---|---|---|
7 | 39059 | |
3 | 1387 | |
3 | 23537 | |
3 | 2566 | |
3 | 13856 |