The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About PhilipDAth
PhilipDAth

PhilipDAth

Kind of a big deal

Member since Aug 26, 2017

yesterday

Philip D'Ath

Auckland, New Zealand

http://www.ifm.net.nz/

Groups
  • API Early Access Group

    API Early Access Group

    545
View All
Kudos from
User Count
Chris_Skees
Meraki Employee Chris_Skees
4
cmr
Kind of a big deal cmr
386
KarstenI
Kind of a big deal KarstenI
92
joaro
joaro
1
AdBurl
AdBurl
3
View All
Kudos given to
User Count
ww
Kind of a big deal ww
769
alemabrahao
Kind of a big deal alemabrahao
274
KarstenI
Kind of a big deal KarstenI
357
Ryan_Miles
Meraki Employee Ryan_Miles
341
JacekJ
JacekJ
4
View All

Community Record

12173
Posts
8627
Kudos
945
Solutions

Badges

CMNA
Meraki Master
Community All-Star 2023
Community All-Star 2022
Community All-Star 2021
Community All-Star 2020 View All
Latest Contributions by PhilipDAth
  • Topics PhilipDAth has Participated In
  • Latest Contributions by PhilipDAth
  • « Previous
    • 1
    • 2
    • 3
    • …
    • 470
  • Next »

Re: User unable to connect to a specific wireless MR33

by Kind of a big deal PhilipDAth in Wireless LAN
a week ago
a week ago
Are you using WPA2-Enterprise mode?  Can the AP talk to your RADIUS server?  Is the AP authorised in the RADIUS server? ... View more

Re: Company Owned Android Devices

by Kind of a big deal PhilipDAth in Mobile Device Management
a week ago
a week ago
Why would "Google" for users to install Systems Manager onto their personal devices?  What configuration or policy have you go forcing it? ... View more

Re: How to prioritize traffic for Cloud Hosted Server

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
4 Kudos
a week ago
4 Kudos
If you have users "inside/outside" with performance issues - then it is probably the cloud service itself is having the issue.  If this is the case, then nothing you do on the client side will solve the performance issue.   If it is a web app, you could use Meraki Insight to monitor it - but that is all you can do. https://meraki.cisco.com/products/meraki-insight/  ... View more

Re: Multiple IP Address assigning to single website

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
a week ago
I think you are asking if it is possible to create a static route where the next hop is a DNS name, rather than an IP address.   If this is the case, then the answer is no. ... View more

Re: Trouble Linking to Active Directory

by Kind of a big deal PhilipDAth in Mobile Device Management
a week ago
a week ago
This document lists the requirements for the certificate: https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Configuring_Active_Directory_with_MX_Security_Appliances#Install_a_Digital_Certificate_on_Each_Domain_Controller  ... View more

Re: Cisco AnyConnect+custom certifictae

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
a week ago
You could create a startup task that deletes the global_preferences.xml file to stop the caching. ... View more

Re: Cisco AnyConnect+custom certifictae

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
1 Kudo
a week ago
1 Kudo
Each MX will need its own certificate - each with exactly the same DNS name - vpn.company.com.   Azure Traffic Manager is just returning the IP address of the MX to connect to, using the vpn.company.com DNS name. ... View more

Re: Meraki Dashboard to Azure AD not connecting

by Kind of a big deal PhilipDAth in Dashboard & Administration
a week ago
a week ago
Double-check for the role in the Meraki Dashboard.  Check for a spelling mistake. ... View more

Re: Clients showing uplink instead of switch port.

by Kind of a big deal PhilipDAth in Switching
a week ago
a week ago
Do all of the switches plug into one of those switches (making it a core switch)? ... View more

Re: Ping Google(8.8.8.8) from MX source VLAN 10 from Tools

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
a week ago
Is the colour of grass a bug or a feature?  Neither.  It's just the way it is. ... View more

Re: Trouble Linking to Active Directory

by Kind of a big deal PhilipDAth in Mobile Device Management
a week ago
a week ago
Does the AD controller have a certificate installed on it? ... View more

Re: Trying to replace vlan 1 with different vlan without changing the subne...

by Kind of a big deal PhilipDAth in Switching
a week ago
a week ago
Are the switches operating as layer 2 switches only, or are they operating in layer 3 mode (and also doing routing)?   More specifically, what does the routing for the current VLAN1? ... View more

Re: MX105 locked up after scheduled update to 17.10.2 completed

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
1 Kudo
a week ago
1 Kudo
I haven't seen any issues with upgrades to 17.10.x that require an MX to be power cycled to come back online. ... View more

Re: Cisco AnyConnect+custom certifictae

by Kind of a big deal PhilipDAth in Security / SD-WAN
a week ago
1 Kudo
a week ago
1 Kudo
A little bit outside of my area; but I believe Azure Traffic Manager is just a DNS load balancing service, returning the nearest IP address of the service to the user.   So if you connect to vpn.company.com, it will return the IP address of the nearest MX.  If the MX is configured to use its dynamic DNS name and certificate, it expects a connection to xxx.dynamic-m.com. However, AnyConnect thinks it is connecting to vpn.company.com, so a certificate issue is created.   If you want to use Azure Traffic Manager then you will need to load a custom certificate onto each MX that matches the original DNS name that AnyConnect is told to connect to.  You will also have to manage the process of rolling these certificates each time they get close to expiry.  A process prone to failure because humans don't tend to be good at managing this process. That is why the easier option is to use the AnyConnect Optimal Gateway Selection feature, and have it do everything automatically.  You don't have to touch any certificates, nothing.  It will keep working year after year without you having to do anything.     ... View more

Re: Revealing Your 2023 Meraki Community All-Stars!

by Kind of a big deal PhilipDAth in Community Announcements
a week ago
2 Kudos
a week ago
2 Kudos
Welcome to the matrix, the new matrix. ... View more

Re: Info: Syslog to Webhook Tranceiver

by Kind of a big deal PhilipDAth in Developers & APIs
a week ago
a week ago
Great work Thomas. ... View more

Re: SHOULD I USE MY OWN EMAIL TO CREATE A DASHBOARD ACCOUNT OR CAN I USE A ...

by Kind of a big deal PhilipDAth in Dashboard & Administration
a week ago
2 Kudos
a week ago
2 Kudos
From a security perspective, it is best if everyone has their own account. ... View more

Re: Ugly Patch Panel Cables

by Kind of a big deal PhilipDAth in Switching
a week ago
a week ago
You might be able to get some inspiration with this "before and after" thread. https://community.meraki.com/t5/Off-the-Stack/Before-and-After-Pictures/m-p/4650  ... View more

Re: Ugly Patch Panel Cables

by Kind of a big deal PhilipDAth in Switching
a week ago
a week ago
First tip - use slim-line patch leads for patch panels like this: https://cdlnz.com/PLSY-C6-025    If you have to run the cables "aerially" like that, velcro tie them into bundles of 6 or 8.   When you have a lot of cables, cable management bars really help.  I quite like the "fingered" variety, like: https://cdlnz.com/PP-CMC01 You take the lid off, run the cables, and then put the lid back on to make it tidy.  This is an example using both horitzontal and vertical fingers (the vertical fingers don't have their lid on here).   ... View more

Windows 11 22H2 breaks MSCHAPv2 authentication for WiFi and wired connectio...

by Kind of a big deal PhilipDAth in Full-Stack & Network-Wide
a week ago
8 Kudos
a week ago
8 Kudos
This is a heads up - a big problem that is going to affect a huge number of WiFi networks.   Windows 11 22H2 enables credential guard by default - which disables MSCHAPv2 by default for single sign-on.  Many companies use MSCHAPv2 for authenticating to WiFi and wired connections (because it was the default setting in Windows 10 and 11 till now).   If you use this configuration, as users upgrade to Windows 11 22H2 they will no longer be able to authenticate to the network "at login" (as in automatically - single sign-on).  If enabled, users will still have the ability to click on the connection concerned and manually re-authenticate - but this breaks the whole user experience of seamless connectivity.   Microsoft recommends migrating to certificate-based authentication.   https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations      This is going to be a lot of work ... ... View more

Re: Port forward to remote host via AutoVPN

by Kind of a big deal PhilipDAth in Security / SD-WAN
2 weeks ago
2 weeks ago
Ok - that must be an extra check they have added.  I have done something similar to this, but a LONG time ago.  I assume you have AutoVPN configured already, so the remote subnet is in the local routing change.   You could try opening a case with support, and seeing if this is a check they can disable for you (stop NAT checking to see if the destination is a local host). ... View more

Re: Traffic shaping

by Kind of a big deal PhilipDAth in New to Meraki
2 weeks ago
4 Kudos
2 weeks ago
4 Kudos
Hi @KathleenJ .  What @eLvs is meaning - even if you have a client directly connected to an MX, and you make a layer 7 firewall change - that change may not take effect for 10 minutes or so.  The MX has a flow cache, and you need the existing entry in the flow cache in the MX to expire before the new rule takes effect. Sometimes if you don't want to wait, you might reboot the MX to expedite this process.   @eLvs - I'm not sure about the answer (about using a group policy with a bandwdith limit applied to a client).  I think the bandwidth takes effect pretty quickly.  Like maybe 30s.   ... View more

Re: Meraki Organization Notes/Tags

by Kind of a big deal PhilipDAth in Security / SD-WAN
2 weeks ago
2 weeks ago
Not a 100% solution, but if you wanted to add a note you could try using the "MSP" field under organization/settings.     I believe this is the "details" field under "management". https://developer.cisco.com/meraki/api-v1/#!get-organization  ... View more

Re: Azure SSO Issues Sign in Redirect Just says TRUE

by Kind of a big deal PhilipDAth in Dashboard & Administration
2 weeks ago
2 weeks ago
Building on @MyHomeNWLab's answer, for this reason I always get the SAML Idp to present something like sAMAccountName instead of the email address as the username. ... View more

Re: Authentication failed because the remote party has closed the transport...

by Kind of a big deal PhilipDAth in Developers & APIs
2 weeks ago
2 weeks ago
Can you try running it from a different public IP address as a test?  Perhaps you are exceeding the rate limit with other scripts, or maybe your IP address has been black listed or something.   Did any Windows Updates install themselves during the timeframe? ... View more
  • « Previous
    • 1
    • 2
    • 3
    • …
    • 470
  • Next »
Kudos from
User Count
Chris_Skees
Meraki Employee Chris_Skees
4
cmr
Kind of a big deal cmr
386
KarstenI
Kind of a big deal KarstenI
92
joaro
joaro
1
AdBurl
AdBurl
3
View All
Kudos given to
User Count
ww
Kind of a big deal ww
769
alemabrahao
Kind of a big deal alemabrahao
274
KarstenI
Kind of a big deal KarstenI
357
Ryan_Miles
Meraki Employee Ryan_Miles
341
JacekJ
JacekJ
4
View All
My Accepted Solutions
Subject Views Posted

Re: Azure vMX's getting Errors with Meraki's new IP block

Security / SD-WAN
194 Thursday

Re: VLAN capabilities per MX

Security / SD-WAN
251 2 weeks ago

Re: Event Log - Content Filtering - Wired Clients

Security / SD-WAN
129 2 weeks ago

Re: client VPN on 4G backup line

Security / SD-WAN
110 2 weeks ago

Re: Traffic Shaping categories

Security / SD-WAN
173 3 weeks ago

Re: can't sign into meraki go portal

Dashboard & Administration
266 a month ago

Re: FQDN Policy object does not seem to be working

Security / SD-WAN
481 a month ago

Re: Is AutoVPN PCI Compliant?

Security / SD-WAN
137 a month ago

Re: MV Sense custom CV models

Smart Cameras
436 ‎12-23-2022 04:29 PM

Re: anti-DDOS & MX

Security / SD-WAN
343 ‎12-19-2022 11:11 AM
View All
My Top Kudoed Posts
Subject Kudos Views

Re: Welcome! Please introduce yourself.

Community Tips & Tricks
53 103335

Re: Community Challenge: Show off your WiFi chops for a chance to win!

Community Announcements
23 12884

Before and After Pictures

Off the Stack
22 42536

Re: Happy New Year! What are your Networking Resolutions?

Community Announcements
19 44247

An open letter to all Meraki product managers

Off the Stack
17 4677
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki