The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About Sarv
Sarv

Sarv

Here to help

Member since Jun 14, 2021

a month ago
Kudos from
User Count
Red-Five
Red-Five
1
Inderdeep
Kind of a big deal Inderdeep
1
View All
Kudos given to
User Count
Bruce
Bruce
1
View All

Community Record

21
Posts
2
Kudos
0
Solutions

Badges

First 5 Posts
Lift-Off View All
Latest Contributions by Sarv
  • Topics Sarv has Participated In
  • Latest Contributions by Sarv

Re: WAN Ports - non-public IP Addresses?

by Sarv in Security / SD-WAN
‎02-11-2023 09:02 AM
‎02-11-2023 09:02 AM
Typically the Public IP is assigned to the 5G device and those devices typically have 1, 2 or more "LAN" ports. Those 5G device LAN ports would be plugged directly into your Meraki MX or via L2 switch (5G Lan Port connect to Switch port, MX WAN Ports connected to the switch) with all of those switch ports being in the same VLAN and having private IP's in the same address space/vlan.  Your MX WAN configuration should have the Private IP of the 5G device as their Gateway.     So assuming your 5G device configuration as above, should be fine.  ... View more

Re: InterVlan Routing not working

by Sarv in Security / SD-WAN
‎02-11-2023 08:37 AM
‎02-11-2023 08:37 AM
Not sure about the VMware on Windows (Im assuming you are using VMWare workstation?). Did you try changing the MX Port settings for the port connected to this VM? Change it from Trunk port to Access Port (VLAN 30).  Im assuming you are changing the virtual machine (the same one) from VLAN 1 to VLAN 30. If that is not the case and you have a switch port uplinked to the Meraki make sure you have presented VLAN 30 over that. ... View more

Re: Talos 'threat' content category

by Sarv in Security / SD-WAN
‎01-16-2023 07:00 AM
1 Kudo
‎01-16-2023 07:00 AM
1 Kudo
We block the full threat categories list for multiple customers. Have been doing it for a few weeks with no issues....So far...   Sarv ... View more

Re: Meraki MX multiple /29 Public Blocks

by Sarv in Security / SD-WAN
‎01-16-2023 06:41 AM
‎01-16-2023 06:41 AM
Thanks Bruce ... View more

Re: Meraki MX multiple /29 Public Blocks

by Sarv in Security / SD-WAN
‎01-16-2023 06:40 AM
‎01-16-2023 06:40 AM
Thank you.  ... View more

Meraki MX multiple /29 Public Blocks

by Sarv in Security / SD-WAN
‎01-09-2023 06:29 AM
‎01-09-2023 06:29 AM
  I just want to validate this configuration will work on the MX (latest firmware).   We have a need to get a second /29 public ip block from the same (Primary) ISP.  The MX will have a public IP on its WAN interface from the first /29 block. The 2nd /29 block from the same ISP will be used for NAT forwarding. Is this a valid configuration that will work with the MX (I know it works with other FW's), this second /29 will be not be contiguous with the first /29 block.   I believe this configuration will work but wanted to ask the community if there are any gotcha's.   Thanks Sarvjit ... View more
Labels:
  • Labels:
  • Firewall

Re: Default Route MX

by Sarv in Security / SD-WAN
‎11-19-2022 03:37 PM
‎11-19-2022 03:37 PM
Makes sense. Thanks ... View more

Default Route MX

by Sarv in Security / SD-WAN
‎11-19-2022 01:44 PM
‎11-19-2022 01:44 PM
Here is the scenario:   Site1 has Internet access Site2 has no Internet access (only cellular available) Site1 and Site2 connected via Private Metro-E circuit   We want all Traffic from site2 to site1 (including internet traffic) over the Metro-E (which will be connected to LAN port of MX68CW at Site2), if Metro-E at Site2 goes down we want to have VPN (auto-vpn) failover over cellular.    This would mean default route 0.0.0.0/0 will need to go over the LAN port (Metro-E circuit) and then failover to cellular (which should have auto-vpn setup from site2-to-site1 for failover).   Is this possible? Site1 will have an MX85.   Thanks Sarvjit       ... View more

Re: Failover E-LAN to Auto-VPN

by Sarv in Security / SD-WAN
‎11-18-2022 06:17 AM
‎11-18-2022 06:17 AM
Thanks. I was hoping to avoid purchasing additional HW (Firewall) as each site would also need a FW. I knew about the single-arm VPN concentrator mode as this was the only solution available from Meraki prior to the ability of using static routes and active while next hop responds to pings. The client wont spring for additional HW. ... View more

Re: Failover E-LAN to Auto-VPN

by Sarv in Security / SD-WAN
‎11-18-2022 06:13 AM
‎11-18-2022 06:13 AM
Thanks. I will give the 2nd part of your solution a try. They will not have an internet breakout so both circuits connected to WAN ports will not be an option. Thanks again. ... View more

Failover E-LAN to Auto-VPN

by Sarv in Security / SD-WAN
‎11-17-2022 12:12 PM
‎11-17-2022 12:12 PM
We have a requirement to failover from E-lan service to Meraki auto-vpn in case E-lan connectivity is lost. The following is the scenario:   3 sites using a e-lan through a provider (using layer3 over E-lan). Each site will also have internet egress, all sites will have Meraki MX (different MX models based on size/bw/etc) and would like to use site-to-site VPN (auto-vpn) between the 3 sites in case e-lan connectivity is lost at any given site (or all sites). The requirement would also be that the failover is automatic. T   I read the following deployment guide:  https://documentation.meraki.com/MX/Deployment_Guides/MPLS_Failover_to_Meraki_Auto_VPN   Would this work for our requirement as well? I do not see any real difference besides the service (MPLS) being used in the deployment guide example.    Thanks Sarvjit   ... View more

Re: Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 05:27 PM
‎06-29-2021 05:27 PM
Wow Bruce you nailed everything without knowing our infrastructure, color me impressed. So my plan was exactly what you detailed out.   All Devices ===> MX LAN Interface (VLAN 100), the appliance would also have one of its interfaces on that same VLAN connected to the MX.   Branch Appliance over the internet ipsec tunnel to appliance at HQ ===> out to internet or internal VLAN's whichever the case may be. This ensures all traffic to/from that branch site is optimized.   Potentially I could connect a 2nd interface from appliance and run it back through the MX on another VLAN, lets say VLAN 200, the appliance would NAT the traffic using it VLAN 200 interface back through the MX but that seems counter intuitive to me.   P.S only a single VLAN currently at the branch location so its not too complicated and AutoVPN will be turned off for the site since all traffic will be routed through this appliance.   Thanks Sarvjit           ... View more

Re: Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 03:23 PM
‎06-29-2021 03:23 PM
Perfect. I will give it a try. Thanks ... View more

Re: Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 02:44 PM
‎06-29-2021 02:44 PM
I will give it a shot. Thanks Bruce. ... View more

Re: Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 02:39 PM
‎06-29-2021 02:39 PM
Remote site has no broadband access available. Using LTE 4G for primary. ... View more

Re: Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 02:38 PM
‎06-29-2021 02:38 PM
But I suppose its not going to let me create a static route for 0.0.0.0/0. So will have to add each IP accessed by the users individually? That wouldnt be possible, of course. ... View more

Re: Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 02:27 PM
‎06-29-2021 02:27 PM
We are using the MX for FW, Content Filtering, Threat protection, etc. The third party appliance is for compression and TCP optimization. I suppose I can make the 3rd party appliance the default route for the branch site devices, or possibly use it as inline bridge mode so that all outbound traffic has to pass through the device before hitting the MX, and then the reverse inbound.   I wish Meraki would just bring back the compression/optimization features then no need for additional devices.   Thanks   Sarvjit ... View more

Re: Client VPN Issue

by Sarv in Security / SD-WAN
‎06-29-2021 12:24 PM
‎06-29-2021 12:24 PM
Not sure if this helps, we had similar issues on Windows 10 Native VPN client. The option I believe we had to set was to make sure all traffic was routed through the VPN (i.e no split tunneling).   Thanks Sarvjit ... View more

Meraki MX Default Route

by Sarv in Security / SD-WAN
‎06-29-2021 12:22 PM
‎06-29-2021 12:22 PM
Is it possible to change the default route on MX to another LAN port (instead of WAN ports, for all Internet Traffic). We have a 3rd party appliance that we need to route all of the internet traffic through.   If its not possible my other idea was to use on of the free WAN ports on the MX and connect that up to our 3rd party appliance but that seems a little kludgy to me but if that's the only option maybe I will give that a shot.   Thanks Sarvjit ... View more

Re: MS 355 Port Mirroring

by Sarv in Switching
‎06-14-2021 07:02 AM
‎06-14-2021 07:02 AM
Thank you.  ... View more

MS 355 Port Mirroring

by Sarv in Switching
‎06-14-2021 05:46 AM
1 Kudo
‎06-14-2021 05:46 AM
1 Kudo
I want to Mirror ports (one-to-one), Mirror trunk port 49 to port 30, then mirror Trunk port 50 to Port 31 on the same switch, it seems that I can not do that? Is this not possible? Each time I try to mirror it forces me to use the same destination port from the previous Mirror I have setup.    Thanks Sarv ... View more
Kudos from
User Count
Red-Five
Red-Five
1
Inderdeep
Kind of a big deal Inderdeep
1
View All
Kudos given to
User Count
Bruce
Bruce
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: Talos 'threat' content category

Security / SD-WAN
1 206

MS 355 Port Mirroring

Switching
1 720
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki