The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About Nash
Nash

Nash

Kind of a big deal

Member since Jul 5, 2018

‎12-04-2020

Nash King

Groups
  • API Early Access Group

    API Early Access Group

    554
View All
Kudos from
User Count
akfrnd
akfrnd
1
JGill
JGill
1
allenfred
allenfred
1
cmr
Kind of a big deal cmr
8
JakiraBias1
JakiraBias1
1
View All
Kudos given to
User Count
GreenMan
Meraki Employee GreenMan
2
DarrenOC
DarrenOC
2
nikmagashi
nikmagashi
1
PhilipDAth
Kind of a big deal PhilipDAth
175
Melissa
Meraki Alumni (Retired) Melissa
5
View All

Community Record

1029
Posts
1051
Kudos
70
Solutions

Badges

ECMS2
CMNA
Meraki FIT Level Two
Community All-Star 2020
Community All-Star 2019
MOTM - May 2020 View All
Latest Contributions by Nash
  • Topics Nash has Participated In
  • Latest Contributions by Nash
  • « Previous
    • 1
    • …
    • 35
    • 36
    • 37
    • 38
  • Next »

Re: Client VPN and registering to DNS

by Nash in Security / SD-WAN
‎06-05-2019 02:46 PM
‎06-05-2019 02:46 PM
What happens if you do not specify DNSSuffix? I've never had to do that for my clients, assuming I had DNS configured correctly on the MX Client VPN page. In full disclosure, my clients only ever have one local domain in their AD setup. ... View more

Re: Client VPN and registering to DNS

by Nash in Security / SD-WAN
‎06-05-2019 09:51 AM
2 Kudos
‎06-05-2019 09:51 AM
2 Kudos
Could you share a sanitized version of your add-vpnconnection? What DNS settings do you have under Client VPN on your MX?   We set the internal DNS under the Client VPN screen in the MX, seen here with decorative black boxes and rando client VPN subnet:     Then I configure the VPN on the end user's device using a script that contains the following:   Add-VpnConnection - Name $ConnectionName - ServerAddress $ServerAddress - AllUserConnection - TunnelType L2tp - L2tpPsk $PresharedKey - AuthenticationMethod Pap - EncryptionLevel Optional - Force - WA SilentlyContinue   (Full scripts in GitHub.) ... View more

Re: Weird DNS issues on some of the switch

by Nash in Switching
‎05-28-2019 08:03 AM
‎05-28-2019 08:03 AM
If you can resolve names correctly from the device and the error lingers for an hour or so, I wouldn't worry too much. I've had it take 90 minutes before. Same with bad gateway.   Like, device passed traffic fine! I could talk to it on the dashboard. It was cool. The error just didn't wanna clear. ... View more

Re: Dashboard API Script Reports

by Nash in Developers & APIs
‎05-28-2019 06:26 AM
2 Kudos
‎05-28-2019 06:26 AM
2 Kudos
That sounds like your request isn't correct. You could have the URI wrong, or be missing a portion of the header.   Here's a demonstration using the Postman environment from https://postman.meraki.com   When I call GET  {{baseUrl}} /organizations but don't include the key:value pair of "X-Cisco-Meraki-API-Key":{{X-Cisco-Meraki-API-Key}}, I'll get 404.    But if I ensure that my header includes that key:value pair (my API key), then I get a list of orgs that my API key works on. ... View more

Re: Apple TV's causing a Conflict IP with other machines

by Nash in Dashboard & Administration
‎05-22-2019 02:58 PM
1 Kudo
‎05-22-2019 02:58 PM
1 Kudo
Have you considered putting a DHCP reservation on the AppleTV? Or have you tried that already? ... View more

Re: Meraki Client VPN Issue

by Nash in Switching
‎05-22-2019 11:02 AM
‎05-22-2019 11:02 AM
For Windows 7, yes.   For Windows 10, the Network Reset function will also reinstall your network drivers, above and beyond resetting tcp/ip and winsock.  ... View more

Re: Meraki Client VPN Issue

by Nash in Switching
‎05-22-2019 09:00 AM
‎05-22-2019 09:00 AM
If you're using Windows 10, there's also a "Network Reset" function that condenses a number of NIC, TCP/IP and Winsock functions into a single utility. It will reset your NIC(s) to DHCP, so do be warned if you're using a static for some reason. ... View more

Re: Meraki VPN Client

by Nash in Security / SD-WAN
‎05-21-2019 04:29 PM
1 Kudo
‎05-21-2019 04:29 PM
1 Kudo
Two last things, @cwal21.    Have you run the Network Reset utility in Win10? If you have and it's still broken...   Have you uninstalled and reinstalled the WAN miniadapters? Usually, it's sufficient to only do the L2TP one.   Here's the instructions I gave my help desk:       1. As administrator, open Device Manager.       2. Under View, select Show Hidden Devices:       3. Under Network Adapters, find WAN Miniport (L2TP)       4. Right click and select Uninstall Device. If it asks to uninstall the DRIVERS, click no.         5. Reboot the computer. Windows should automatically reinstall the device.       6. Test the VPN again. ... View more

Re: Meraki VPN Client

by Nash in Security / SD-WAN
‎05-21-2019 09:33 AM
1 Kudo
‎05-21-2019 09:33 AM
1 Kudo
So you don't find any error codes in Event Viewer. It just dies off?   The "overlay" between the standard Windows 10 method (click on network connector by clock, click VPN, login) is pretty wonky and will not always pass correctly to rasphone. Rasphone's what's doing the dialing at the end of the day.   Suggestions:   Windows-R, run rasphone.exe. Find your saved VPN there. Try to connect with rasphone and see if it goes through.   If it does, you can make a rasphone.exe shortcut. Create a shortcut on your desktop, and set the target to: C:\WINDOWS\system32\rasphone.exe -d "VPN NAME"   If it doesn't connect, delete and re-create the VPN connection. I like the scripts I put above, especially if you want a split tunnel connection. Read the script comments before you run - it does more than create a saved VPN connection. By default, it'll make a rasphone shortcut on the desktop. ... View more

Re: Can't ping a subnet from VPN

by Nash in Security / SD-WAN
‎05-17-2019 12:21 PM
1 Kudo
‎05-17-2019 12:21 PM
1 Kudo
How did you deny internet access to vlan 3? Is it a set of permit statements for the associated subnet followed by a blanket deny for said subnet?    If so, then you'll need to add permit statements between the subnet for vlan 3 and your client VPN subnet. ... View more

Re: Client VPN and Azure AD

by Nash in Security / SD-WAN
‎05-17-2019 06:35 AM
‎05-17-2019 06:35 AM
So to confirm, your only source of AD is Azure AD? You do not have an on-premises AD that syncs to Azure? ... View more

Re: Azure VPN (IKEv2) intermittent

by Nash in Security / SD-WAN
‎05-17-2019 06:11 AM
‎05-17-2019 06:11 AM
What version of firmware are you running on the MX? There's a thread from earlier this year that discusses a way to work with support to get 15.x to support IKEv2. Most of the changes to it, it looks like you're going to have to work with Support. ... View more

Re: Meraki VPN Client

by Nash in Security / SD-WAN
‎05-16-2019 11:13 AM
1 Kudo
‎05-16-2019 11:13 AM
1 Kudo
Windows 10 is a problem that can be dealt with. I've got some PowerShell scripts that create a split tunnel by default, so long as you feed them the appropriate subnets. ... View more

Re: success story with meraki

by Nash in Off the Stack
‎05-16-2019 08:12 AM
1 Kudo
‎05-16-2019 08:12 AM
1 Kudo
I work at a VAR/MSP combo. We have dozens of clients with Meraki equipment.   Do you know how much time it saves us to not have to manually update software...? I'm getting ready to do Cisco equipment at a client, and it's taken me a couple hours just to verify existing firmware, get the new recommended firmware, transfer it to the client's network, and book an outage.   Meanwhile, updating all the MX to 14.x was about an hour of checking firmware and scheduling updates for 3am. ... View more

Re: API Call reboot MX

by Nash in Security / SD-WAN
‎05-16-2019 07:26 AM
4 Kudos
‎05-16-2019 07:26 AM
4 Kudos
Sure can: https://dashboard.meraki.com/api_docs#reboot-a-device   I'd probably:   IF you have multiple orgs, pull a list of orgs Pull a list of networks for your org Pull a list of devices Check if a device is an MX If MX, add serial to list For device in list, send reboot command. 🙂   I've got some Python code snippets I can throw into a github if you're not sure how to execute this.   Edit: Or @BrechtSchamp can beat me to the punch after help desk interrupts me! ... View more

Re: Site-to-Site VPN from MX64 to Non-Meraki (SonicWALL TZ) stops passing t...

by Nash in Security / SD-WAN
‎05-15-2019 06:26 AM
1 Kudo
‎05-15-2019 06:26 AM
1 Kudo
I've had success in the past with having support disable nat-t. It was between an ASA and an MX65, but I had a tunnel that just kept... dropping. Up and happy for a while, then boom splat unhappy remote site with no DNS.   After support disabled NAT-T, it has stayed up successfully for almost two months. I hope you get the same result! ... View more

Re: VLAN!

by Nash in Wireless LAN
‎05-14-2019 07:19 AM
3 Kudos
‎05-14-2019 07:19 AM
3 Kudos
I've set up similar for a client. In their case, they have wired clients hanging off an L3 switch as well as an AP.     Here, vlan1 gets cut off as soon as it hits the L3 switch on the far side. Far side uses vlan 15. There's one SSID shared between the two buildings, and I've got it set to L3 Roaming right now. It could be bridged but this client had reasons.   I need an L3 switch or a router on a stick so that I can a) remote manage my switch, and b) have both APs and wired clients on the far side.   Everything on the far side is on vlan15, with a dhcp helper setup to point DORA to her own pool on my AD DHCP server.  ... View more

Re: Building segregated VLAN for Guest wifi

by Nash in Wireless LAN
‎05-13-2019 08:17 AM
‎05-13-2019 08:17 AM
Make sure you set the SSID firewall so that the guest wifi doesn't have access to your normal network. It can be easy to miss, even if you're following that doc. ... View more

Re: Learn more about your community peers in our Member Spotlight!

by Nash in Community Announcements
‎05-09-2019 12:27 PM
4 Kudos
‎05-09-2019 12:27 PM
4 Kudos
@Cmiller No, I thought I'd just mention the scripts exist and not share...   I threw them up in a github repo: https://github.com/gammacapricorni/happy-meraki-client-vpn   They're mostly based on snippets I've found on the forums here, all mushed together to pro-actively avoid common problems that my help desk has run into. I taught myself PowerShell for these so... they may not be super well written, but they mostly work.   AddMerakiVPN.ps1 is designed for you to pre-populate it with VPN name, address, PSK, and any routes for a split tunnel. I believe it should be possible to apply via GPO, but I haven't been able to try that. The server folks are not as interested in VPNs as I am.   AddMerakiVPN_Prompts.ps1 is designed for my help desk to use when someone from any client calls in. They pull the VPN details from our documentation, answer the prompts, then delete the script when they're done. Allows us to update the info in one place, rather than maintaining scripts for dozens of clients. ... View more

Re: Network Policy Server VPN authentication weird ip address

by Nash in Security / SD-WAN
‎05-09-2019 10:51 AM
1 Kudo
‎05-09-2019 10:51 AM
1 Kudo
I took a quick look at the NPS logs for a client of mine. Their requests also originate from a 6.0.0.0/8 IP address. I'd be willing to bet that this is due to communication with the Meraki cloud but I have no proof. ... View more

Re: PCI Compliane and Client VPN

by Nash in Security / SD-WAN
‎05-08-2019 02:37 PM
2 Kudos
‎05-08-2019 02:37 PM
2 Kudos
There's a doc for that!  https://documentation.meraki.com/MX/Client_VPN/MX_Security_Audit_Failed_-_Recommended_Steps   and more generally on PCI compliance:   https://documentation.meraki.com/MR/Other_Topics/PCI_Compliance_with_Meraki     ... View more

Re: How to divide a growing network in two networks without loosing switch ...

by Nash in Switching
‎05-07-2019 11:34 AM
‎05-07-2019 11:34 AM
If I understand the documentation correctly, you won't be able to move a switch without losing the config:   https://documentation.meraki.com/zGeneral_Administration/Inventory_and_Devices/Moving_Devices_Between_Networks   However, here's what you can do. Plan for an outage:   Use Postman to pull down as many settings as possible. Pay special attention to your switchports.   Save the resulting JSON in a folder.   Move the switch.   Upload those settings to your switch.   You could also get clever and write a script to pull your settings, move the switch, then update the moved switch with the settings. ... View more

Re: Thanks for the sweet SWAG

by Nash in Off the Stack
‎05-06-2019 01:42 PM
3 Kudos
‎05-06-2019 01:42 PM
3 Kudos
My partner told me my water bottle got here today. I am not going to lie: I look very much forward to swanning around the office with it and making a specific coworker jealous.   Also, I really needed a new water bottle but kept dragging my feet on buying one. ... View more

Re: MS250 NTP config

by Nash in Switching
‎05-06-2019 07:12 AM
4 Kudos
‎05-06-2019 07:12 AM
4 Kudos
NTP is handled by the Meraki Cloud. You cannot manually configure NTP on Meraki devices nor use them as time servers for other devices on your network. ... View more

Re: Dashboard API Breaking Change

by Nash in Developers & APIs
‎04-25-2019 07:56 AM
‎04-25-2019 07:56 AM
I can confirm as well. I'm getting:   Lat lng address serial mac lanIP tags name model No network ID.   Perhaps @DexterLaBora can shed some light on this? ... View more
  • « Previous
    • 1
    • …
    • 35
    • 36
    • 37
    • 38
  • Next »
Kudos from
User Count
akfrnd
akfrnd
1
JGill
JGill
1
allenfred
allenfred
1
cmr
Kind of a big deal cmr
8
JakiraBias1
JakiraBias1
1
View All
Kudos given to
User Count
GreenMan
Meraki Employee GreenMan
2
DarrenOC
DarrenOC
2
nikmagashi
nikmagashi
1
PhilipDAth
Kind of a big deal PhilipDAth
175
Melissa
Meraki Alumni (Retired) Melissa
5
View All
My Accepted Solutions
Subject Views Posted

Re: We need a Wi-Fi count per tag/building

Wireless LAN
3035 ‎06-30-2020 09:41 AM

Re: VPN Split tunnel on iPhone IOS

Security / SD-WAN
8754 ‎06-25-2020 06:34 AM

Re: split vpn traffic / dns resolving

Security / SD-WAN
1088 ‎06-08-2020 03:30 PM

Re: Meraki MX 64 & NAT Rules

Security / SD-WAN
2737 ‎06-04-2020 06:56 AM

Re: Would the factory reset of a Z1 device disable 2FA from dashboard

Dashboard & Administration
2331 ‎05-26-2020 08:26 AM

Re: Communication between Client VPN and IPSec peer subnet

Security / SD-WAN
1134 ‎05-18-2020 09:10 AM

Re: RADIUS server for VPN question

Security / SD-WAN
2107 ‎04-03-2020 11:18 AM

Re: Reorganizing our Dashboard

Dashboard & Administration
5565 ‎03-26-2020 02:05 PM

Re: Unable to ping servername, but servername.domain.com works (VPN and DNS...

Security / SD-WAN
2789 ‎03-23-2020 05:59 PM

Re: Windows 10 Split VPN

Security / SD-WAN
7596 ‎03-19-2020 07:27 AM
View All
My Top Kudoed Posts
Subject Kudos Views

Re: Does disabling all SSID's on an AP turn off the WiFi antennas completel...

Wireless LAN
8 2890

Re: Client VPN & tethering to iPhone

Security / SD-WAN
7 4607

Re: ECMS2

Off the Stack
7 12181

Re: Revealing Round 2 of the 2020 Meraki Community All-Stars!

Community Announcements
6 4566

Hangout spot for Cisco Live Virtual

Off the Stack
6 788
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki