The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About GuiCarvalho
GuiCarvalho

GuiCarvalho

Getting noticed

Member since Apr 9, 2018

Monday
Kudos from
User Count
Adam
Adam
1
jdsilva
jdsilva
1
View All
Kudos given to
User Count
PhilipDAth
Kind of a big deal PhilipDAth
2
AlexP
Meraki Employee AlexP
2
BlakeRichardson
Kind of a big deal BlakeRichardson
1
Bruce
Kind of a big deal Bruce
1
ww
Kind of a big deal ww
1
View All

Community Record

24
Posts
2
Kudos
0
Solutions

Badges

CMNA
CMNO
1st Birthday
First 5 Posts
Lift-Off View All
Latest Contributions by GuiCarvalho
  • Topics GuiCarvalho has Participated In
  • Latest Contributions by GuiCarvalho

CMNA Instructor-led vs eCMNA (on Demand)

by GuiCarvalho in Off the Stack
a week ago
a week ago
Hello Team,   Anyone knows if the eCMNA gives the free Gear too? Or it's exclusively for who did the instructor-led training? ... View more

Re: Meraki MS Switches - Dynamic Voice Vlans

by GuiCarvalho in Switching
2 weeks ago
2 weeks ago
Thanks for the help, Philip. ... View more

Meraki MS Switches - Dynamic Voice Vlans

by GuiCarvalho in Switching
2 weeks ago
2 weeks ago
Hello Team, Is that possible to deliver dynamic voice vlans to Meraki from ISE as we can do with the data vlan?   We have an environment with two voice vlans (vlan A and vlan B). Vlan A is static configured in the switch port as voice vlan. When I connect an IP Phone that needs to be in the vlan B, I can see in the event log a radius response sending the vlan B to the switch, but actually the vlan override didn't occurs (the client keep in the vlan A).   In the ISE side, all the process is okay. We have one authz profile for each vlan with the flag (enable voice vlan domain) checked.   The PC connected behind the IP Phone is working okay, with the data vlan changed according to the AD Group.   I have saw some posts in the community indicating that dynamic voice vlan didn't work in Meraki. Did I understand correct? If so, what is the alternative to automatically delivery the differents voice vlans? Because statically assign one of this two vlans in the ports is not a good option, because the users is moving frequently in the environment.   Thanks. ... View more

Re: Access Local Status Page - MX VPN Concentrator

by GuiCarvalho in Security / SD-WAN
‎06-23-2022 07:30 AM
‎06-23-2022 07:30 AM
Aí que está minha dúvida. Como ele é one-armed, só tem um IP configurado na interface Internet, não há vlan configuradas nesse MX. Se eu conectar em uma porta LAN e configurar o meu PC na mesma subnet em que está a porta a Internet, eu consigo o acesso? ... View more

Re: Access Local Status Page - MX VPN Concentrator

by GuiCarvalho in Security / SD-WAN
‎06-23-2022 07:19 AM
‎06-23-2022 07:19 AM
Obrigado Bettencourt. Imaginei que uma vez em modo VPN Concentrator, as portas LAN não funcionariam nem mesmo para acesso a local status page.   No caso de não ter a porta de gerencia e o acesso for pela porta LAN, mesmo em VPN Concentrator, o MX continua a entregar aquele IP Default via DHCP? Ou preciso configurar algo manualmente? ... View more

Access Local Status Page - MX VPN Concentrator

by GuiCarvalho in Security / SD-WAN
‎06-23-2022 06:58 AM
‎06-23-2022 06:58 AM
Hello Team, How can I access the Local Status Page of an MX as One-Armed VPN Concentrator, once the LAN ports is not used?   The MX was unacessible by dashboard and the option to remotely access the local status page is disabled.   I'd like to know if there is a way to access the local status page without resetting the MX to factory defaults.   Thanks.  ... View more

Re: Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-30-2021 07:05 AM
‎07-30-2021 07:05 AM
@PhilipDAth ,   As I just informed to AlexP, the ranges tha I posted in this topic is incorrect.   The correct remote range for the VPN 1 is 10.0.0.0/16 and the new second vpn is 10.10.0.0/24. So, in this way, I think there is not an IP overlaps.   But, we still have the problem for VPN 1 going down when we configure the VPN 2, until we delete the VPN 2 config. ... View more

Re: Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-30-2021 07:02 AM
‎07-30-2021 07:02 AM
@AlexP ,   I think that the problem is other. I have informed a wrong ranges in this topic.   The correct remote range for the VPN 1 is 10.0.0.0/16 and the new second vpn is 10.10.0.0/24. So, in this way, I think there is not an IP overlaps.   So, the sympthon is the same. When we configure VPN 2, the VPN 1 goes down and just become UP when I delete the VPN 2.   Do you all have any clue about what can be the cause to this problem? ... View more

Re: Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-29-2021 04:11 PM
‎07-29-2021 04:11 PM
@PhilipDAth ,   Thank you for your suggestion.   First, I'll ask the customer to NAT their subnets, as I was talking with AlexP. If it's not a option for the customer, I'll ask them to narrow the subnet range. ... View more

Re: Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-29-2021 04:09 PM
‎07-29-2021 04:09 PM
@AlexP , thank you very much.   I'll ask the customer to do a NAT for their subnets and post here the results. ... View more

Re: Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-29-2021 02:21 PM
‎07-29-2021 02:21 PM
@AlexP ,   Thanks for the information.   So, if a NAT is created in the customer side, and I point the NATed address as remote subnet, it will work?   For example, translating (in the customer side) 192.168.0.0/16 to 172.16.0.0/16, and configure the remote subnet for VPN 1 as 172.16.0.0/16. ... View more

Re: Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-29-2021 12:52 PM
‎07-29-2021 12:52 PM
@BlakeRichardson ,   That is correct, I'm talking about a VPN Site-to-Site between Meraki and 3rd Party.   The MX is configured as HUB, but I'll need to create tunnels for some Spokes too. ... View more

Non-Meraki VPN - Subnet Conflict

by GuiCarvalho in Security / SD-WAN
‎07-29-2021 12:36 PM
‎07-29-2021 12:36 PM
Hello Team, . We have a VPN non-meraki with the remote subnet as 192.168.0.0/16. This VPN is working fine.   But now, we need to create another non-meraki vpn with a different customer, but in this case, the remote subnet is 192.168.20.0/24.   So, when I apply the new Tunnel, the old one failed (close the tunnel). I think it occurs because the remote subnet for VPN 2 (New), is included in the remote subnet range for VPN 1 (old).   Is there a way to workaround it? ... View more

Re: Non-Meraki VPN + NAT + AutoVPN

by GuiCarvalho in Security / SD-WAN
‎07-20-2021 07:31 AM
‎07-20-2021 07:31 AM
Thank you everyone for the help. ... View more

Re: Non-Meraki VPN + NAT + AutoVPN

by GuiCarvalho in Security / SD-WAN
‎07-19-2021 11:40 AM
‎07-19-2021 11:40 AM
ww, Thanks for your reply. So, there is no way to spokes (AutoVPN) communicates with a non-Meraki VPN through the Hub? ... View more

Non-Meraki VPN + NAT + AutoVPN

by GuiCarvalho in Security / SD-WAN
‎07-19-2021 07:40 AM
‎07-19-2021 07:40 AM
Hello Team,   I know that Non-Meraki VPN doesn't communicate whit AutoVPN. The most popular solution is add a new MX, in another Organization todo a bridge between Non-Meraki VPN and AutoVPN.   But, I would like to know if there is an alternative where we don't need another MX.   If I create a NAT in the HUB, to translate the remote address and create a route for the NATed IPs in the spokes, with the hub as next hop, it can be work?   Thanks, Guilherme Carvalho ... View more

Re: Using the trap send from the Dashboard

by GuiCarvalho in Dashboard & Administration
‎07-10-2018 08:38 AM
‎07-10-2018 08:38 AM
Hello, DonL.   How is configured the Client Tracking in the Addresssing & VLAN menu? Try to set this option to "Track clients by IP address" (if it doesn't already) and verify if the information of the IP Address is sent in the trap.   Regards, Guilherme Carvalho ... View more

Re: About URL Filtering

by GuiCarvalho in Security / SD-WAN
‎06-04-2018 11:53 AM
‎06-04-2018 11:53 AM
@WilliamQin, Please, try to include the URL without the "www" (just baidu.com). You also could try to include a wildcard character in the end of the URL (baidu.com* or only baidu.*)   PS.: As the other colleague said above, you need to wait about 10 minutes to the change take effect. Or, if you are in a lab environment, you can restart the appliance.   ... View more

Re: MX Firewall

by GuiCarvalho in Security / SD-WAN
‎06-04-2018 11:04 AM
‎06-04-2018 11:04 AM
Alexander, Take a look at this post. I think that will problably help you: https://community.meraki.com/t5/Security-SD-WAN/Prevent-inter-VLAN-routing-on-MX/td-p/1437 ... View more

Re: MX Firewall

by GuiCarvalho in Security / SD-WAN
‎06-04-2018 10:18 AM
‎06-04-2018 10:18 AM
AlexanderDrago, Please disconsider my last phrase. The "Security appliance services" is about services that you can enable or disable to the traffic sourced in the outside interface. ... View more

Re: MX Firewall

by GuiCarvalho in Security / SD-WAN
‎06-04-2018 10:13 AM
‎06-04-2018 10:13 AM
Hello AlexanderDrago, If I understood correctly, you are allowed to ping the GWs of another VLANs, but you can ping another devices of these others vlans? Besides the ping, you can access devices of others VLANs? If the "problem" is only that you are able to ping the GWs, did you tried to block it in the Security Appliance -> Firewall -> Security appliance services, putting "None" in the "Allowed remote IPs" box? ... View more

Re: Include an exception in a Syslog Server

by GuiCarvalho in Security / SD-WAN
‎06-04-2018 09:31 AM
1 Kudo
‎06-04-2018 09:31 AM
1 Kudo
Adam, Thanks for your help. ... View more

Re: Include an exception in a Syslog Server

by GuiCarvalho in Security / SD-WAN
‎06-04-2018 09:30 AM
1 Kudo
‎06-04-2018 09:30 AM
1 Kudo
Jdsilva, thanks for your reply. I'll just filter this in the server side. ... View more

Include an exception in a Syslog Server

by GuiCarvalho in Security / SD-WAN
‎05-30-2018 09:08 AM
‎05-30-2018 09:08 AM
Hello All, I'm configuring a Syslog Server in a MX64 to log URLs accessed by the clients, but I need to exclude one specific host from this. Is it possible?   Ex.: I want to log all URLs accessed by my LAN (10.0.0.0/24, for instance), except the host that have the IP 10.0.0.10.   I have enabled the Syslog Server in Network-Wide -> General - Logging, putting the IP of my Syslog Server and choosing the Role "URL". But, I coudn't find any way to prevent a client to have its URLs access logged.   Thanks in advanced!   Regards, Guilherme Carvalho ... View more
Kudos from
User Count
Adam
Adam
1
jdsilva
jdsilva
1
View All
Kudos given to
User Count
PhilipDAth
Kind of a big deal PhilipDAth
2
AlexP
Meraki Employee AlexP
2
BlakeRichardson
Kind of a big deal BlakeRichardson
1
Bruce
Kind of a big deal Bruce
1
ww
Kind of a big deal ww
1
View All
My Top Kudoed Posts
Subject Kudos Views

Re: Include an exception in a Syslog Server

Security / SD-WAN
1 2180

Re: Include an exception in a Syslog Server

Security / SD-WAN
1 2180
View All
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2022 Meraki