Community Record
48
Posts
21
Kudos
4
Solutions
Badges
Jul 16 2019
10:41 PM
@Max70 agreed it should be like this but i’m using pac also. and the route preference for the meraki is Directly Connected Client VPN Static Routes AutoVPN Routes Non-Meraki VPN Peers NAT* Since non meraki vpn peers are on number 5 then and then NAT come . It should choose non meraki vpn path and hence traffic flow through zscaler tunnel directly not through nating.
... View more
Jul 16 2019
4:27 AM
Are you using it now or earlier you have tried with MX name?
... View more
Jul 16 2019
4:10 AM
you can't do it on MX now since there is another upstream device who is performing Nating. can you ask your ISP to do the Nating for you. or there is another way i believe you can establish client vpn via MX name not with ip. it should work.
... View more
Jul 16 2019
3:07 AM
1 Kudo
You are using private ip's it can't be possible without 1:1 nating .
... View more
Jul 16 2019
2:03 AM
Are we sure that we have public ip configured on the MX? if yes try with server name this time not with the IP.
... View more
Jul 16 2019
1:45 AM
Are you using a public ip on MX interface? if yes, i don't think there will be any challenge. just follow below URL. client vpn will establish through MX public ip go to Security & SDWAN>Uplink to check the ip https://documentation.meraki.com/MX/Client_VPN/Client_VPN_OS_Configuration
... View more
Jul 16 2019
1:35 AM
Absolutely right @RichardChen1 . I believe as of now you can't configure the policy for Non Meraki VPN peer.
... View more
Jul 15 2019
2:25 AM
1 Kudo
if you are running MS120 then your MX would be probably working as L3 Gateway. Check on your MX ARP table. This feature is unsupported by MS120
... View more
Jul 15 2019
1:40 AM
@RichardChen1 you need to put your zscaler node ip under proxy setting to ensure your http and https traffic travels through zscaler. or you can download the pac file for that.
... View more
Jul 14 2019
11:36 AM
definitely you will be. where are these gateways configured on MX65 ? if not then you need to put the static route in your mx pointing towards other device in the same subnet that tells you the path to reach to other network.
... View more
Jul 14 2019
12:09 AM
4 Kudos
Yes, this is my MX configuration for zscaler tunnel with meraki. under non Meraki section enter the name for your zscaler node and the public ip of your zscaler node. now the ipsec custom policies i have configured like below. Now you have to whitelist your MX wan ip with zscaler by raising a ticket with them. and then you need to configure the VPN credentials at Zscaler for your MX WAN ip. Make sure it matches with meraki also. Now add location at zscaler and call your vpn credentials and add your private ip's range as sub location.
... View more
Jul 13 2019
11:59 PM
1 Kudo
MS120 port should be in access when it is going to computer. MS120 is L2 switch so you have to define the VLAN in MX65 by going into Step 1: Security & SDWAN>Address & VLAN> Add VLAN Step 2: Now go to Security & SDWAN->Address & VLAN-> Per port VLAN setting and it should be trunk depend upon Native vlan you have configured like 1 or any Step 3: Now configure the DHCP scope by Security & SDWAN>DHCP and run a DHCP server for selected vlan. Now the MS120 part Uplink to MX 65 will be trunk. go to Switch> DHCP servers & ARP and enter the MX65 mac address in Allowed DHCP servers box.
... View more
Jul 12 2019
10:16 AM
1 Kudo
that depends if you want the MR to be in the same subnet as the MS. Secondly if you want to configure the multiple subnet then you need to configure MS port as trunk or if you want to advertise only single subnet then it would be access port.
... View more
Jul 12 2019
9:45 AM
1 Kudo
Your modem is acting as a WAN for your MX and its ip would be different and you cant give the same subnet ip to MS too. LAN and WAN ip subnet can't be same, right. Go to Security & SDWAN > Addressing and VLAN > configure one subnet for your MS. Now Go to Security & SDWAN > DHCP and run the dhcp server. That's all.
... View more
Jul 12 2019
1:33 AM
2 Kudos
@SCC below are the feature wise comparison between both the licenses.
... View more
Jul 5 2019
4:02 AM
1 Kudo
@Lucifer AP comes in repeater mode when it doesn't have the direction connection to the internet. Repeater mode AP could be a issue of bad cable, or bad power supply. Sometimes rebooting the AP can fix the issue.
... View more
Jul 4 2019
7:42 AM
1 Kudo
Another one. Yippie
... View more
Jul 4 2019
7:11 AM
2 Kudos
Since you are already working on cisco traditional network. Meraki is cisco cloud based solution. you can change/monitor your network from anywhere. Trust me you will love the technology. Go for it. But to keep one thing in mind which can panic you at the time of running your legacy + Meraki Network simultaneously. Don't choose Native vlan other than vlan 1 between your Legacy uplink device to Meraki. Between Meraki you can choose native vlan anyone but between your legacy and Meraki it will cause an issue.
... View more
Jun 26 2019
9:00 PM
Hi, I believe the server gateway is misconfigured. though you are on the same subnet thus it doesn't required any gateway to communicate within the same VLAN and on the other network it required a gateway which tells it the path to reach on other network. Try to check your server gateway either the gateway is not there or it is misconfigured. check your desktop gateway and configure the same on server end it should work. if you have firewall disabled at server end
... View more
Jun 24 2019
8:15 PM
1 Kudo
For SDWAN VPN traffic the preferred link can be configured under the policy and also the backup path can be defined thats totally depend on you how you want to perform sdwan.
... View more
My Accepted Solutions
Subject | Views | Posted |
---|---|---|
20355 | Jul 14 2019 12:09 AM | |
4645 | Jul 12 2019 9:45 AM | |
4777 | Jun 26 2019 9:00 PM | |
4209 | Jun 24 2019 8:15 PM |
My Top Kudoed Posts
Subject | Kudos | Views |
---|---|---|
4 | 20355 | |
2 | 10855 | |
2 | 7738 | |
1 | 13375 | |
1 | 3749 |