The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About jjbehrend
jjbehrend

jjbehrend

Just browsing

Member since Mar 25, 2020

‎03-27-2020

Community Record

3
Posts
0
Kudos
0
Solutions
Latest Contributions by jjbehrend
  • Topics jjbehrend has Participated In
  • Latest Contributions by jjbehrend

AWS VMX100 IP spoofing

by jjbehrend in Security / SD-WAN
‎03-27-2020 09:35 AM
‎03-27-2020 09:35 AM
We need to send traffic over a vpn connection from instances in an aws subnet, but due to an addressing conflict they need to come from a different source IP (we need to either nat or "spoof" an IP address). Since we couldn't find a way to NAT the traffic on the VMX, we tried to set the source IP on the linux box originating the traffic using ip route src. This works between AWS instances, however, for some reason, the VMX doesn't seem to 'see' the traffic (it doesn't even show up on packet capture). Can you help us resolve this?  We need from an instance that we have EC2 in AWS whose IP is 10.111.88.241 it can make IP spoofing and Meraki can receive it. Our Meraki VMX100 is located at IP 10.111.88.43. We unlocked the IP spoofing block parameter for logging only, but still failed to get traffic to be seen in Meraki's Packet Capture. Questions: 1. What is needed to enable traffic to reach Meraki from a spoofed IP, in our case: Original IP: 10.111.88.241 IP spoofing: 172.17.10.153  2. Can we perform NAT changing the origin according to the destination in Meraki? ... View more

Re: Allow SHA256 for Authentication IPSEC Peers Non-Meraki

by jjbehrend in Security / SD-WAN
‎03-25-2020 01:06 PM
‎03-25-2020 01:06 PM
Hi,    I call the TAC and they said to me , that this dont work yet.   Do you have some way to facilities us to allow SHA256 in our tunnel?  Thanks a lot , if we can't do this the Meraki Solution don't work for us. ... View more

Allow SHA256 for Authentication IPSEC Peers Non-Meraki

by jjbehrend in Security / SD-WAN
‎03-25-2020 07:47 AM
‎03-25-2020 07:47 AM
Hi good day? I hope you are doing well, I am writing to you because we need to be able to activate SHA256 for the Authentication phase for our IPSEC VPN tunnels with third parties, this is because we have banking entities that do or do not need this protocol. I understand that they have not yet developed it by the dashboard, but I also understand that below it is a cisco and this is a very standard feature of any appliance or VPN software. From already thank you very much ... View more
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki