Community Record
28
Posts
1
Kudos
0
Solutions
Badges
Oct 17 2024
9:04 AM
I have questions for our new Meraki proposed setup with Enterprise License, and I would want to know your experience with those regarding below questions 1. Can we connect internet and MPLS lines on a single or dual MX? 2. If we have two internet lines, can we use FQDN based traffic steering to route certain traffic via the primary link and other traffic via the secondary? 3. If we use ZScaler as our SSE, can we specify whether Zscaler traffic should flow over the primary or secondary internet line only? 4. Does routed mode on Meraki imply that it is internet facing, or can it be behind a firewall or router and still be in routed mode?
... View more
May 20 2024
1:27 AM
But given IPv4 default route is always checked, even if I do not declare that VLAN on VPN, still it will flow via DC, right ?
... View more
May 20 2024
12:32 AM
Hi All, Client ask is to add a new VLAN which should have direct internet breakout with no access to DC services. Currently site has default routes coming from DC hence all internet + VPN traffic goes to DC from site. Restriction to DC services can be set up using group policies but how to allow local breakout for particular VLAN? In order to manage the request, I need to 1. Remove IPv4 Default Route checkbox from Hubs under Site-to-Site VPN 2. select VLANS that I want to follow DC path and select appropriate DC as next hop for them. Doing this, not selected VLANS in step 2 will automatically have local breakout as bi-product of first 2 steps. However, I only see one DC as a next hop can be selected. what if primary DC fails, will that route automatically sends the traffic to next available DC Hop without explicitly configuring that or not ? What happens when next hop fails? Also, is there any other workaround available?
... View more
May 5 2024
10:45 PM
How can one improve the user experience when you have an MX appliance on-site with load balancing enabled across two internet lines? I have a site with 50 users and two 100Mbps lines. So far, that site has been operating on an active-standby configuration, but the client just requested that I change the configuration to active + active in order to boost throughput and make better use of the standby line. Now, there was recently some difficulty with the secondary line, which was experiencing packet loss or low latency but never went down, thus Meraki continued to consider it an active line and kept sending traffic on it, and it resulted into site users to have a bad experience due to the degraded connection. Now, how can I get Meraki to move traffic to a better WAN connection if it detects a performance issue with one of the lines? Can I use a customized performance class? Can it simply used for Auto VPN traffic, or can it also be used for Internet traffic? And do I have the option of selecting that custom policy for one of two WAN connections, or does it apply to both automatically?
... View more
May 5 2024
10:15 PM
After replacing HP Core switch, issue got resolved. Thanks for all the suggestions and you were right.
... View more
Apr 3 2024
8:02 AM
Is your DHCP server online, operational, and configured correctly with an active DHCP scope? Yes, correctly configured. Have you exhausted all of your available IP addresses in your DHCP address pool? Do you need to increase the size of your DHCP address pool? Has 0 utilization. If the DHCP scope for your local LAN is configured on a DHCP server located in a different broadcast domain, do you have IP helper or a DHCP relay agent configured on the local LAN to intercept DHCP discovery broadcasts and forward them to the appropriate DHCP server? Switch VLAN is having IP Helper address pointing to Meraki IP. If you are using a DHCP reservation, is the IP address assigned to your potential clients MAC address part of your DHCP address pool and not excluded? No DHCP reservations are done. Are DHCP discovers reaching your DHCP server successfully? MX receives DISCOVERY Packet and seems Source is VLAN IP (20.20.20.1) from Switch and Destination IP reaching to MX IP of ICN VLAN.
... View more
Apr 3 2024
7:54 AM
My bad if I am not being clear there. There are only 2 machines in that Subnet so pool is completely free.
... View more
Apr 3 2024
7:46 AM
IP Helper Address is configured pointing to Meraki IP of Interconnect VLAN 10.10.10.1 but still no luck.
... View more
Apr 3 2024
7:27 AM
I have a created static route for subnet 20.20.20.0/26 and pointed it to next hop 10.10.10.2 (IP on HP core switch). That IP belongs to Interconnect VLAN 10.10.10.0/29 (VLAN 11) between Meraki MX67 (10.10.10.1) and Core switch (10.10.10.2). Meraki is acting as DHCP Server for 20.20.20.0/26 subnet, settings are as follows : Client addressing : Run a DHCP server Gateway IP : 20.20.20.1 (IP On HP Core Switch) - I can reach this IP Lease time : 1 day DNS nameservers : Specify nameservers... Custom nameservers 1.1.1.1 2.2.2.2 Boot options disabled No DHCP Option No Reserved Range No Fixed IP assignment Configured Switchport as Trunk and configured ICN VLAN 11 as Native Now there are two machines in Subnet 20.20.20.0/26 which are not able to receive IP from Meraki. In the event log, I see below error. DHCP DHCP problem extra: no_offers_received, vap: 0, vlan: 11 Above error only appears for first machine... Whereas for second machine, it requests IP from whole different range and can be seen under DHCP Option 50 in packet capture. (Will run this with client first thing tomorrow) For first machine, it does not list any DHCP option 50 So far whenever I run packet capture, I Only see DHCP Discovery packets but nothing for DHCP OFFERS and all. I have similar setup at other sites where it is working flawlessly but not here. Firmware (18.107.2) is also up to date, same firmware is also present on working sites. Client says switch has same config as other sites, so far CISCO TAC not able to conclude.. Any help ?
... View more
Labels:
- Labels:
-
Other
Mar 19 2024
8:47 AM
yes, I am still pointing to same DNS Server as before.
... View more
Mar 18 2024
8:47 AM
1 Kudo
We have central Windows server at DC for DNS/DHCP Services. I have moved DHCP role to Meraki MX at site and DC Windows Server is still working as DNS server. So far end users at site receives IP properly, able to resolve and reach websites and all. Whenever end users gives printing order, it goes to print server in azure and then it returns to site and reaches to local printers, that's the flow. This works fine when MX does not run as DHCP server but the moment I switch it to Meraki DHCP, all print jobs from local user gets stuck at azure print server and does not reach to local printer further. That local printer is reachable from Azure Print Server and vice versa. Tried to run packet capture however does not saw anything weird. Has anyone faced similar issues? Any idea what might be the case here?
... View more
Labels:
- Labels:
-
Azure
Mar 18 2024
7:28 AM
Hi Raphael, Thanks for the suggestion, it helps. Apparently Meraki Insight costs a bomb hence unfortunately not able to explore that. Only thing is even if it shows inter-vlan usages clubbed, still uplink traffic per second utilization seems ridiculously low. Lets see...
... View more
Mar 6 2024
5:39 AM
Suppose at one site client has 300 MB FTTH Line and client needs to know how much of that line BW is actually getting utilized so they can decide whether to downgrade or upgrade BW? Now when I see the utilization numbers in Meraki Appliance - I see something like 400 kbps per second or 1.2 mbps per second. Available vs Utilization Gap is way too drastic but not sure how much this sounds realistic? I mean I understand that circuit won't remain heavily utilized per second basis but it becomes bit difficult to address it to business about this thing. What's your take on this ? Does Meraki uses some different logic to calculate BW utilization, do they average it by some means or it straightforward as below and it is actual real use?
... View more
Labels:
- Labels:
-
Other
Mar 4 2024
12:08 AM
Hi, I have a Meraki setup where I have 2 hubs.. two Meraki in Physical DC (Hub 1 & 2) and other two in Azure (Hub3 & 4). Now both hub pairs are connected to spokes as Hub1-2 serves DC LAN subnets whereas Hub3-4 serves Azure Route. This organization has "Hub to Hub communication is disabled" from the start because the client had an issue with an earlier organization setup (different org than this), so he made it mandatory for all future organizations to have hub to hub disabled. Given that the Hub1-2 cannot receive the Azure route advertised by the Hub3-4 in order to access Azure resources, a direct S2S VPN tunnel is formed between Azure GW and the DC FW. Recently there been some severe disconnections between Physical DC FW and Azure, with no resolution on the horizon but the impact occurring on a daily basis. Now, I believe If I was to enable Hub to Hub communication and disable tunnel from Physical DC to Azure; then, that Hub1-2 should begin receiving routes from Hub3-4 and the problem will be resolved. What is your take on this?
... View more
Labels:
- Labels:
-
Auto VPN
Feb 16 2024
5:00 AM
I am relatively new to network automation. I understand a little bit about programming. The manager assigned me the task of automating some operations for the Meraki dashboard. For example, make bulk changes to multiple networks within an organization such as VLAN creation, IP whitelisting, VPN exclusion rules, and so on. Those changes wont be limited for multiple networks but sometimes for multiple organizations as well. I've been assigned one Linux VM, and it appears that I'll need to use it as a launch pad for API jobs. I've tried browsing the API documentation and even running a couple of GET queries and was successful, but I don't have a thorough understanding of it, so I'm hesitant. Where do I begin to learn this? On a high level, I'm thinking about using HTML as a frontend. Fields will appear based on the task selected from the dropdown; the user should enter a value in them and click the enter button, and the API should shoot. Is this too complicated and requires rocket science? Also, is there a way to change the way the result output is displayed? It currently appears in syntax format, but can I convert it to a tabular format with only specific information to be displayed ? For example If I run getOrganizationAdmins, I receive information like ID, name, e-mail, authenticationMethod, orgAccess,AccountStatus,twoFactor, lastactive, tags etc.. If I just want to receive limited info like ID, name, e-mail, OrgAccess then how it can be achieved? I believe that as I learn more, may be I will gain a better understanding of what works and what does not. But, if anyone has been through this and come out on top, do you have any advice for me? I'd request you to advise me on how to get started, what I should read, and any website/youtube video urls - any assistance in this regard would be greatly appreciated.
... View more
Jan 18 2024
11:33 AM
I have done that but still cannot receive the route from vWAN for Azure Spokes
... View more
Jan 18 2024
9:42 AM
Hello, Is it possible to do BGP peering with Azure vMX and vWAN Hub without VNET peering? I am told VNET peering between SDWAN VNET and vWAN VNET is absolutely necessary before even beginning with BGP configuration. I thought VNET peering is alternative to BGP routing for communication between vMX and vWAN. Currently my routing is acting strange because of this I believe as I am able to ping IP for which I don't see any routes in vMX route table. Any light on this?
... View more
Labels:
- Labels:
-
Azure
Jan 12 2024
8:48 AM
If Hub to Hub communication is disabled then how specific routes advertised by new Hubs will be learned by existing hubs?
... View more
Labels:
- Labels:
-
Auto VPN
Jan 10 2024
5:39 AM
I am trying to apply QoS policies on Meraki MX to see if it improves anything about Client WebEx call quality Connectivity is like : User Machine (Soft Phone) > Aruba Switch > Meraki MX > Internet Bandwidth is really sufficient Neither Default Traffic shaping rule is helping nor selecting application category is helping hence trying to apply customized rules based on destination WebEx server IP which are in internet. Now webEx traffic or any voice traffic for that matter usually has Call Control, Signaling and Media traffic. I have used CS3 for Call Control and EF for Signaling and Media. However provider suggests to use EF for Media and CS3 for Signaling but I have one destination IP for Media and signaling so not sure how can I apply two different TAGS for single host IP. For example - Can I apply EF for 1.1.1.1:TCP and CS3 for 1.1.1.1:UDP? Also not sure how much of this TAG is going to help once packet leaves MX and rushes to internet. Also I see many RST triggered by local user IP for Call Control within a minute. What could that suggest? Any help would be really appreciated.
... View more
Labels:
- Labels:
-
Other
Jan 8 2024
6:57 AM
Hi All, I have migration coming in where I would need to introduce 2 Meraki devices as Hubs in existing organization for 50 sites. Which means all 50 sites have existing 1st and 2nd Hub and I will be adding 3rd and 4th Hub. I would really like to perform that change in one go, is it possible at all to do it quickly using template ( using template will bring any new problems?) or can CISCO TAC do it ? I have no API experience so not comfortable with it.
... View more
Labels:
- Labels:
-
Other
Dec 9 2023
3:29 AM
Hello, Did you make it work ? If yes, would you be able to share some pointers? Currently I am stuck in same situation.
... View more
Dec 4 2023
3:34 AM
Now I see all routes in green on remote end which are advertised on local network of vMX however i am not able to ping those from remote sites. I tried to ping SDWAN VNET GW IP and I receive no response found error which means return traffic to be configured from Azure side ? Azure route table should be useful here correct?
... View more
Dec 4 2023
3:12 AM
Client is refusing to let me select AZ as NONE. As per him, not selecting AZ for both instances would put them in any single AZ and if that AZ fails - both instance will lost the connectivity. Do you have any CISCO documentation confirming this about selecting NONE AZ or this is your experience based on practical scenarios which is not yet documented in Meraki guide. I have enabled manual NAT traversal, thanks for that but not sure how remote sites will be able to form Auto VPN tunnel with two vMX who are having same masked IP from Azure FW. I have used different UDP port for each vMX but will it work properly do you think?
... View more
Dec 2 2023
7:02 AM
Hi Philip thanks for this insight.. helps a lot . So latest development. We dropped the plan of s2s peering because of need to setup tunnel from every network to azure peer and not just from hub vMX. Now I have two org to connect with azure so for first org i enabled vnet peering between vmx vnet and vwan hub... then I added azure routes under local network. but when I added vMx in hub preference for remote site.. couple routes were shown red and couple were green on remote site. I was able to ping those routes from vMX but not from remote site.. i think I need to convert vMX into routed mode then also add static routes for local networks and then it should work, what do you think?? For second org, I enabled bgp peering between vMX and vWAN and received all routes and also got propogated to remote site but there was no filteration from azure vwan so received every route. Azure is going to release route map in production soon, hope we receive it on time. One thing though.. given azure FW is coming in between vWAN hub and vMX.. its public IP is being masked to both instances of vMX under every organization. Is this right, will it affect later?
... View more
Nov 28 2023
6:03 PM
Hi Philip, Thanks. vMX is in passthrough mode. Since I had two vMX for each org, I was told to deploy first in AZ1 and second in AZ2 for high availability. if I select NONE, wouldn't it compromise the HA? Or given additional vMX it should be OK? BTW both are going to be active active. Also is there any documentation link you could refer to which mentions AZ challenge as you suggest? Static route configured where? Which instance it should be configured on ? Are you referring to UDR or route table? and I can configure supernet covering all physical branches network or subnet per site under local subnet in vMX to advertise towards Azure side and that will anyways reach to vNET gateway and driven further correct? Because given in passthrough mode, I dont think I can configure any static route on vMX anymore.
... View more
My Top Kudoed Posts
Subject | Kudos | Views |
---|---|---|
1 | 970 |