The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About AshMead
AshMead

AshMead

Getting noticed

Member since Jan 28, 2019

‎02-18-2022
Kudos from
User Count
NateF
NateF
1
lpopejoy
lpopejoy
1
MeredithW
Community Manager MeredithW
1
BrechtSchamp
BrechtSchamp
1
View All
Kudos given to
User Count
NateF
NateF
1
merakisimon
Meraki Alumni (Retired) merakisimon
1
JosephHays
JosephHays
1
Sneh
Sneh
1
Nene
Nene
1
View All

Community Record

32
Posts
4
Kudos
0
Solutions

Badges

CMNA
First 5 Posts
Lift-Off View All
Latest Contributions by AshMead
  • Topics AshMead has Participated In
  • Latest Contributions by AshMead

Invalid FTE - Fast Transition Element

by AshMead in Wireless LAN
‎02-14-2022 02:22 AM
‎02-14-2022 02:22 AM
  We are getting a lot of Invalid FTE errors when roaming.   802.11 reason Code 51   we have MR56. Clients are using 802.1x authenticating via ISE.   Other clients appear to have no issues.   Has anyone seen this before?     ... View more

Re: Episode 30: Remote working for the long haul

by AshMead in Meraki Unboxed Podcast
‎09-02-2020 03:23 AM
1 Kudo
‎09-02-2020 03:23 AM
1 Kudo
Some great solutions to easily enable secure remote working. Personally I don't believe working from home will become the new normal. Working from home seems a great idea on the surface however the strains of solitary working can take its toll on even the most introverted of us. I believe in many cases this period will allow people to appreciate the many advantages of having a dedicated working environment with face to face contact with our work mates.  ... View more

Re: Teleworker VPN after MX84 move

by AshMead in Security / SD-WAN
‎03-23-2020 05:05 AM
‎03-23-2020 05:05 AM
When re-booting the AP I notice that I get    VPN registry connectivity change vpn_type: teleworker, vap: 5, connectivity: true     but I do not get a VPN tunnel connectivity change Does this mean that the VPN tries to form but the tunnel is not completed?   Also will the APs try to form the tunnel to the Public or local IP address?  ... View more

Re: Teleworker VPN after MX84 move

by AshMead in Security / SD-WAN
‎03-21-2020 10:11 AM
‎03-21-2020 10:11 AM
Wow, thanks. I’ll give this a try on Monday. I’ll update the post with results! ... View more

Re: Teleworker VPN after MX84 move

by AshMead in Security / SD-WAN
‎03-20-2020 06:31 AM
‎03-20-2020 06:31 AM
@PhilipDAth How do I check this please?   ... View more

Re: Teleworker VPN after MX84 move

by AshMead in Security / SD-WAN
‎03-20-2020 05:00 AM
‎03-20-2020 05:00 AM
Hi   Thanks but unfortunately the reboot did not work. The SSID is still not visible. btw it's an MR45 on 25.14.   Any other ideas? I'm thinking I need to call support ... View more

Teleworker VPN after MX84 move

by AshMead in Security / SD-WAN
‎03-20-2020 02:45 AM
‎03-20-2020 02:45 AM
I have an SSID configured as a Teleworker VPN. It connects to an MX84 configured as a one armed VPN concentrator.   I have moved the MX84 into our data centre and onto a new subnet. The SSID is now not advertised.   I suspect that the tunnel needs re-building to the MX84 in it's new network location. How do I make this happen?    Many thanks ... View more

Re: Client Usage Alerts

by AshMead in Dashboard & Administration
‎03-10-2020 04:08 AM
‎03-10-2020 04:08 AM
Thanks, if this does need to be done via API, do you know of a helpful starters guide?     ... View more

Client Usage Alerts

by AshMead in Dashboard & Administration
‎03-10-2020 02:38 AM
1 Kudo
‎03-10-2020 02:38 AM
1 Kudo
Is it possible to create alerts for excessive client usage?   I am thinking it would be better to remove the bandwidth restrictions and just receive alerts for clients who are bandwidth hoggers.   For example if a clients downloads over 1 GB in an hour an alert email is sent. Or if a client uses a certain restricted web resource such as facebook, again an alert is sent   My motivation for this is to simplify/remove the current traffic shaping. Tell users the network usage rules and then monitor those that disobey the rules.     ... View more

Re: Machine based certificate authentication on Apple Mac iOS devices

by AshMead in Security / SD-WAN
‎03-03-2020 03:40 AM
‎03-03-2020 03:40 AM
Hi @PhilipDAth    It looks like I have I have the same issue as discussed in https://community.meraki.com/t5/Wireless-LAN/Windows-Radius-vs-Meraki-Radius-with-Win-7-Win-10-macOS-Machines/m-p/18630#M3127   There you suggest the Sentry Wi-Fi solution, however would this be not encrypted over the air?   Using EAP-TLS I get the same issue where the certificate is not accepted on the MacOS devices and user is prompted for login credentials.   Ideally we would like both MacOS and Windows devices on the same SSID, authentication by machine with no need to enter credentials each time.   Is there an accepted solution? ... View more

Re: Machine based certificate authentication on Apple Mac iOS devices

by AshMead in Security / SD-WAN
‎03-03-2020 02:04 AM
‎03-03-2020 02:04 AM
I am clearly not an apple expert! Sorry I failed to specify this is MacOS devices not iOS devices. I have now updated the post. Thanks for you help though! ... View more

802.1x Machine based certificate authentication on Apple MacOS devices

by AshMead in Security / SD-WAN
‎02-28-2020 08:11 AM
‎02-28-2020 08:11 AM
I cannot get machine based authentication to work on MacOS devices. This is using my RADIUS server. The RADIUS server does not accept the machine certificates.   It is fine on Windows and fine with user authentication.   Just wondering if anyone else has had similar issues?     ... View more

Re: DC-DC fail-over with one arm concentrators and auto VPN

by AshMead in Security / SD-WAN
‎02-28-2020 07:48 AM
‎02-28-2020 07:48 AM
Hi DensyoV   Thanks, that worked perfectly! The only issue I found was that when switching from one concentrator to another (in the SSID), the SSID was not visible to my windows 10 laptop, IOS devices just remembered the details and reconnected.    Is this a know issue?   Thanks again  ... View more

DC-DC fail-over with one arm concentrators and auto VPN

by AshMead in Security / SD-WAN
‎02-25-2020 01:37 AM
‎02-25-2020 01:37 AM
  We currently have a teleworker VPN configured on an SSID to connect MR clients to a datacentre and the Internet, this is controlled with a single MX84   1. Can I add additional VPNs from separate SSIDs to the same MX84?   2. If I have a second MX84 in a second DC, can i achieve failover between the two?   Below is a network diagram. This shows the proposed MX84 in DC2       Many thanks in advance ... View more

Re: Multiple VPN tunnels into a VPN Concentrator

by AshMead in Security / SD-WAN
‎12-04-2019 03:42 AM
‎12-04-2019 03:42 AM
Would the SSIDs need to be on different VLANs to ensure separation when the traffic hits the MX84?   The Existing SSID is using the default VLAN 0.              ... View more

Re: MR45 brackets

by AshMead in Wireless LAN
‎12-04-2019 02:49 AM
2 Kudos
‎12-04-2019 02:49 AM
2 Kudos
Thanks for the swift response, that's the info I was looking for! ... View more

MR45 brackets

by AshMead in Wireless LAN
‎12-04-2019 02:34 AM
‎12-04-2019 02:34 AM
Are the MR45 mounting brackets the same as the MR33?   Are all MR APs supplied with the same type of mounting bracket?        ... View more

Re: Multiple VPN tunnels into a VPN Concentrator

by AshMead in Security / SD-WAN
‎11-29-2019 04:02 AM
‎11-29-2019 04:02 AM
Thanks, can you recommend a webinar or document which provides details on these options?  ... View more

Re: Multiple VPN tunnels into a VPN Concentrator

by AshMead in Security / SD-WAN
‎11-29-2019 02:12 AM
‎11-29-2019 02:12 AM
Thanks cmr.    To clarify we only have a single MX84 in the data centre. The branch sites only have MRs.   Currently we are using a separate MX64 to tunnel the guest traffic.    Can we have both corporate and guest tunnelled to the MX84 but on different VLANs? ... View more

Multiple VPN tunnels into a VPN Concentrator

by AshMead in Security / SD-WAN
‎11-29-2019 01:45 AM
‎11-29-2019 01:45 AM
We have a one armed VPN Concentrator in a data centre. Is it possible to configure multiple VPN tunnels from the branch sites into the VPN Concentrator in the data centre?   Using an MX84.   The goal is to have a separate VPN tunnel for the corporate traffic and one for guest traffic. There is no Internet breakout at the branches so all traffic needs to traverse the MPLS to break out at the data centre.   Thanks in advance  ... View more

Firewall and Traffic Shaping on the MR

by AshMead in Wireless LAN
‎11-07-2019 06:40 AM
‎11-07-2019 06:40 AM
When traffic shaping is applied on the MR, is this applied to the traffic on the wired side or the wireless side (over the air)?   I ask as surely it would be bad practice to rate limit traffic over the air? Every wireless client should transmit and receive data at the highest rate possible to reduce their contention on the air space.   Is it therefore best practice to apply traffic shaping on the MX?   Thanks ... View more

Re: One-Arm VPN Concentrator - Design Best Practice

by AshMead in Security / SD-WAN
‎11-05-2019 08:58 AM
‎11-05-2019 08:58 AM
That make sense!   Thanks very much for your help   ... View more

Re: One-Arm VPN Concentrator - Design Best Practice

by AshMead in Security / SD-WAN
‎11-05-2019 08:17 AM
‎11-05-2019 08:17 AM
The guest traffic is just required to access the Internet (nothing in the DC).   There is currently traffic shaping on the MRs to rate limit certain websites for the guest traffic   There is currently a second MX set up as a VPN concentrator. This is just used for the guest access. I suspect this was implemented to create a DMZ for the guest traffic.      ... View more

Re: One-Arm VPN Concentrator - Design Best Practice

by AshMead in Security / SD-WAN
‎11-05-2019 06:54 AM
‎11-05-2019 06:54 AM
There is only 1 data centre and 11 branch sites. Some site have only 1 or 2 APs.   Would I need an MX at each site as indicated in the design?   One design goal is to isolate the guest traffic. I know this can be done at the AP but what is the best practice?  - An MX at each of the larger sites then combine the smaller sites with a shared MX?   ... View more

Re: One-Arm VPN Concentrator - Design Best Practice

by AshMead in Security / SD-WAN
‎11-05-2019 06:34 AM
‎11-05-2019 06:34 AM
Looks good, Thanks   Can this design be simply scaled up for multiple branches? ... View more
Kudos from
User Count
NateF
NateF
1
lpopejoy
lpopejoy
1
MeredithW
Community Manager MeredithW
1
BrechtSchamp
BrechtSchamp
1
View All
Kudos given to
User Count
NateF
NateF
1
merakisimon
Meraki Alumni (Retired) merakisimon
1
JosephHays
JosephHays
1
Sneh
Sneh
1
Nene
Nene
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: MR45 brackets

Wireless LAN
2 1581

Re: Episode 30: Remote working for the long haul

Meraki Unboxed Podcast
1 2587

Client Usage Alerts

Dashboard & Administration
1 1201
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki