I will keep that in mind. Thank you @PhilipDAth I also had same question for site to site tunnel with Fortinet. What should be remote ID for that. We tried public and private IP both but didn't work. Any Idea ?
... View more
@PhilipDAth Thanks for your response. So only 1 tunnel should be working either 1 or 2 ? Also just to be clear remote ID scenario. Should it be like this ?
... View more
We have 6 tunnels to AWS (pair of 2). Each tunnel has it's backup tunnel to AWS. On 14.53 version we have all 6 tunnels up and running with IKEv1 but when we switchover to 15.42 and 15.44 we encountered same issue. Only 1 tunnel is staying up and backup tunnel is not coming up. On 15.42 and 15.44 we were using IKEv1 too. Does anyone using AWS with IKEv2 on 15.xx version ?
... View more
@AlexP @jguidali I am in same boat too. I've also contacted Meraki support but they didn't help at all. Not sure where to get help from!!
... View more
Hello, @BazMonkey Thanks for the info. I am aware of this but the issue I am having is what should we put in the Remote ID value for AWS peer. Also should IKEv1 work or do I have to use IKEv2 ?
... View more
Has anyone experienced site-to-site VPN tunnels not working in 15.44? The remote peer is AWS. I think it looks like an issue with Remote ID. Have anyone successfully configured the site-to-site tunnel with AWS in version 15. xx?
... View more
Hello @MarcP Thanks for your suggestion but this will be an open wi-fi and also for this we will need someone always be there to approve access which can be little pain.
... View more
I am trying to implement a temporary password for guests which is valid for a day or two. Can someone please provide some guidance here? TIA
... View more
Want to order some MR46 but it is back ordered so they suggested MR44. Is there a huge difference? We do have some MR45 in other locations and we are pretty satisfied with that. By going to MR44 we don't want to ruin the quality. Any suggestions ?
... View more
Hello, @Inderdeep Thanks for your suggestion. I agree with you but we have Okta in place already and it would be a waste of money if we go with Jumpcloud. Is there any other way to restrict switch ports other than Radius ?
... View more
We have OKTA Radius agent as our Radius server. I have been trying to use that as switch access policy but can't make it work. I am just tired with trying. Is there any other way to restrict switch port access with easy way ?
... View more
Hello @Inderdeep Thanks for your response. Sorry If I am not explaining clearly. Let me explain it again. As example : I have new fresh firewall. 1) I implemented 5 site-to-site VPN tunnels to AWS/Azure/GC. 2) Added allow TCP any any 80 3) allow TCP any any 443 4) deny any any Now my question is Do I have to add rule to allow individual tunnel's ip address ? like allow any any tunnel1 IP address allow any any tunnel2 IP address
... View more
Thank you Inderdeep. In document it says : As such, the MX cannot block VPN traffic initiated by non-Meraki peers. So as example: If I put deny all rule , will site to site VPN still work or it will hit deny all ?
... View more