The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About CaptainBeRad
CaptainBeRad

CaptainBeRad

Here to help

Member since Jul 12, 2019

‎03-31-2022
Kudos from
User Count
CptnCrnch
Kind of a big deal CptnCrnch
2
Shigella
Shigella
1
View All
Kudos given to
User Count
cwal21
cwal21
1
Brash
Kind of a big deal Brash
1
ww
Kind of a big deal ww
1
View All

Community Record

16
Posts
3
Kudos
0
Solutions

Badges

CMNA
First 5 Posts
Lift-Off View All
Latest Contributions by CaptainBeRad
  • Topics CaptainBeRad has Participated In
  • Latest Contributions by CaptainBeRad

Re: Firewall Rule Override

by CaptainBeRad in Security / SD-WAN
‎03-18-2022 08:49 AM
‎03-18-2022 08:49 AM
I think you need to make a route to the subnet you are trying to make a rule for. If the subnet doesn't exist anywhere in the meraki I don't think they let you make it. ... View more

Re: Finding source of Content filtering hits in a core switch routed envior...

by CaptainBeRad in Security / SD-WAN
‎03-09-2022 08:11 AM
‎03-09-2022 08:11 AM
Also of note here is the IP address option is ghosted out for some reason ... View more

Re: Finding source of Content filtering hits in a core switch routed envior...

by CaptainBeRad in Security / SD-WAN
‎03-09-2022 08:06 AM
‎03-09-2022 08:06 AM
@Ryan_Miles I did change it, we're on the cusp of a code upgrade. I think it's supposed to happen this weekend. The environment is Meraki top to bottom, so it's AP's, switches, and FW's all meraki. I have client tracking set to "Unique Client Identifier" but it has a little "Beta" text next to it. It doesn't seem to work really well so far. I have a lot of client tracking problems where the clients are showing discovered on switch uplink ports instead of their wired port in a stack downstream. I also see the issue in the original post a lot.  ... View more

Re: Best practice to deploy Meraki client VPN to laptops? All methods seem ...

by CaptainBeRad in Security / SD-WAN
‎03-09-2022 07:48 AM
2 Kudos
‎03-09-2022 07:48 AM
2 Kudos
The windows VPN method is plagued with constant problems. Just when you think you have it right, Microsoft changes something or an update resets your settings and breaks it. as @cwal21 mentions Anyconnect is now available for Meraki, switch to that. You have many more options for managing the VPN well, and most people are familiar with anyconnect from a user standpoint. Update the code on your MX's and give it a try, if you don't have a ton of users the anyconnect licensing isn't too bad price wise. ... View more

Re: Can I use Cisco AnyConnect with Meraki Client VPN?

by CaptainBeRad in Security / SD-WAN
‎03-09-2022 07:45 AM
‎03-09-2022 07:45 AM
Well I think you get credit for answering your own question! ... View more

Finding source of Content filtering hits in a core switch routed enviornmen...

by CaptainBeRad in Security / SD-WAN
‎03-09-2022 07:41 AM
‎03-09-2022 07:41 AM
Hello,   I have a setup where the core switches are the default gateways for many of the VLAN's in our environment. Then we have a transit stub network to connect all of those VLANs to the MX firewalls. The problem I see here is when things hit the content filter the source mac/ip is the interface on the transit VLAN. It's tough to find the device where the traffic has originated from. Anyone have any good methods for this?   -Brad  ... View more

Re: Anyconnect VPN Pre-logon message

by CaptainBeRad in Security / SD-WAN
‎10-21-2021 06:23 AM
‎10-21-2021 06:23 AM
I found this too, but I think that this method is only valid on ASA's. There doesn't appear to be a way in Meraki to edit these message ID's or the catalog on the Meraki MX platform. ... View more

Re: Windows 10 VPN issues for some users after Windows Update

by CaptainBeRad in Security / SD-WAN
‎10-20-2021 01:04 PM
1 Kudo
‎10-20-2021 01:04 PM
1 Kudo
I've had this problem with a bunch of customers. When Microsoft updates the built in windows VPN components it resets some parameters and breaks the VPN. Start looking at switching to AnyConnect instead, works much better. The licensing is not huge money either. ... View more

Anyconnect VPN Pre-logon message

by CaptainBeRad in Security / SD-WAN
‎10-20-2021 01:01 PM
‎10-20-2021 01:01 PM
Hi Everyone, hoping somebody has had experience with this. I am working on a VPN deployment with MX250 and Anyconnect. Everything is working great, I even got MFA to work with AzureAD via NPS. The problem I have is that users are not realizing they are supposed to look at their phone for the Microsoft Authenticator push. Meraki with Anyconnect doesn't support an interactive prompt for 2FA, but I can do a push via MFA extension on the RADIUS server. The push works and everything works when I test it but I want to pop a message for the user at some point during the process.    I explored a prompt for MFA but it isn't supported, so I am researching the "showprelogon message" attribute of the anyconnect profile. I'm having trouble finding useful documentation. In the anyconnect XML you can see this section   <AnyConnectProfile xmlns="http://schemas.xmlsoap.org/encoding/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://schemas.xmlsoap.org/encoding/ AnyConnectProfile.xsd"> <ClientInitialization> <UseStartBeforeLogon UserControllable="true">false</UseStartBeforeLogon> <AutomaticCertSelection UserControllable="true">true</AutomaticCertSelection> <ShowPreConnectMessage>true</ShowPreConnectMessage> <CertificateStore>All</CertificateStore> <CertificateStoreMac>All</CertificateStoreMac> <CertificateStoreLinux>All</CertificateStoreLinux> <CertificateStoreOverride>false</CertificateStoreOverride> <ProxySettings>Native</ProxySettings>     I want to make that part "True" and populate a message (basically telling the user to enter creds then expect a microsoft authenticator push), but I'm not sure where to put the message or the XML syntax required to define the message string. Anyone have any examples, or am I barking up the wrong tree here? I was thinking maybe this might be an ASA only thing where the message is defined on an ASA group policy but I'm not sure.   -Brad ... View more
Labels:
  • Labels:
  • Client VPN

Re: API PUT blockedUrlCategories won't update. Comes back with not valid

by CaptainBeRad in Developers & APIs
‎04-30-2020 01:40 PM
‎04-30-2020 01:40 PM
Hi Guys,   I think I'm running into this too. Big disclaimer here, I'm no expert on programming, so excuse the crudeness if I'm doing something wrong here. I am working on a script that will allow me to specify a site to clone the content filtering rules. I just made the same script for the L7 rules and it worked perfectly. This one is not working so well. Below is the script I'm using right now. I'm just trying to collect the content filtering rules, which comes in as a hashtable of hashtables I believe. I am then converting it to a JSON, which I thought turned it into a string.   When I try to run the single Invoke-RestMethod, at the bottom, to put the JSON rules at another site I get an Error (400) Bad Request. I used the Streamer method to try to troubleshoot. That tells me the following    {Each element in 'blockedUrlCategories' must be a string}   I can't understand why that would be the case. If I do a GetType() on my $json it shows that name is string but the basetype is system.object. I'm not sure what I'm missing here. Do I have to do something to the JSON data to change it to a string?   IsPublic      IsSerial         Name         BaseType --------           --------          ----                 -------- True           True              String         System.Object       #create header with API key Write-host "Creating API Key Header" $header_org = @{ "X-Cisco-Meraki-API-Key" = $api_key "Content-Type" = 'application/json' } ####################################################### # Get list of all the network ID's in the org ################################################## #create meraki uri to list the networks in the org $MerakiUri = $baseuri + "/organizations/$org_id/networks" #execute rest call Write-host "Collecting all network ID's in the organization" $networklist = Invoke-RestMethod -Method Get -Uri $MerakiUri -Headers $header_org #create empty array to store network ID's for each site $networkArray = $null $networkArray = @() #put networks into an array using the list we got from the REST API call foreach($network in $networklist){ $networkArray = [array]($networkArray + $network.id | where-object{$_ -notlike "$network_id"}) } ############################################################### # Get the L7 geoblocking countries out of site we are cloning # ############################################################### #create merakiuri to list the L7 rules in the network $MerakiUri = $baseuri + "/networks/$network_id/contentFiltering" #execute rest call to get the config for the site to clone write-host "Collecting Content Filtering FW rules from $network_id" $tempcontentrules = Invoke-RestMethod -Method Get -Uri $MerakiUri -Headers $header_org #drop the name property from the blockedurlcategories. Found this in the forums to resolve error wtih API put $tempcontentrules.blockedUrlCategories = $tempcontentrules.blockedUrlCategories | Select-Object -Property * -ExcludeProperty 'name' #convert rules to json format Write-host "converting rules into JSON format" $contentrules_json = ConvertTo-Json -Depth 100 -InputObject $tempcontentrules ############################################################### # Put the content filters onto the rest of the sites # ############################################################### foreach ($each_network_id in $networkArray){ #create URI for contentfiltering rule put $content_uri = $baseuri + "/networks/$each_network_id/contentFiltering" #add rule write-host "Creating content rules for network $each_network_id" Invoke-RestMethod -Method Put -Uri $content_uri -MaximumRedirection 0 -Headers $header_org -Body $contentrules_json }   ... View more
Kudos from
User Count
CptnCrnch
Kind of a big deal CptnCrnch
2
Shigella
Shigella
1
View All
Kudos given to
User Count
cwal21
cwal21
1
Brash
Kind of a big deal Brash
1
ww
Kind of a big deal ww
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: Best practice to deploy Meraki client VPN to laptops? All methods seem ...

Security / SD-WAN
2 4387

Re: Windows 10 VPN issues for some users after Windows Update

Security / SD-WAN
1 1884
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki