The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About Nash
Nash

Nash

Kind of a big deal

Member since Jul 5, 2018

‎12-04-2020

Nash King

Groups
  • API Early Access Group

    API Early Access Group

    554
View All
Kudos from
User Count
akfrnd
akfrnd
1
JGill
JGill
1
allenfred
allenfred
1
cmr
Kind of a big deal cmr
8
JakiraBias1
JakiraBias1
1
View All
Kudos given to
User Count
GreenMan
Meraki Employee GreenMan
2
DarrenOC
DarrenOC
2
nikmagashi
nikmagashi
1
PhilipDAth
Kind of a big deal PhilipDAth
175
Melissa
Meraki Alumni (Retired) Melissa
5
View All

Community Record

1029
Posts
1051
Kudos
70
Solutions

Badges

ECMS2
CMNA
Meraki FIT Level Two
Community All-Star 2020
Community All-Star 2019
MOTM - May 2020 View All
Latest Contributions by Nash
  • Topics Nash has Participated In
  • Latest Contributions by Nash
  • « Previous
    • 1
    • …
    • 36
    • 37
    • 38
  • Next »

Re: Slow client VPN speed

by Nash in Security / SD-WAN
‎03-26-2019 07:08 AM
‎03-26-2019 07:08 AM
In addition to the "what does works fine mean" question, how many machines are affected by this issue? Where is your laptop connecting from?    Is your laptop on the same remote network as the device(s) having problems? ... View more

Re: API l7FirewallRules not working

by Nash in Developers & APIs
‎03-22-2019 03:02 PM
‎03-22-2019 03:02 PM
I am officially bummed out. I filed a ticket to see about getting this end point enabled for my orgs, only to be told it's not an endpoint and there's no ETA on it.   It still shows up in the Postman docs. I swear it used to be in the ones on create.meraki.io change log too? I guess it's time to be patient.  ... View more

Re: MX100 VPN access over Active DIrectory

by Nash in Security / SD-WAN
‎03-21-2019 12:27 PM
1 Kudo
‎03-21-2019 12:27 PM
1 Kudo
Are you looking to use AD to authenticate users for the client VPN?   If so, you've got a second way to go, beyond what @jdsilva linked. I usually use Network Policy Server for RADIUS: https://documentation.meraki.com/MX/Client_VPN/Configuring_RADIUS_Authentication_with_Client_VPN   Partly because I'm usually already doing RADIUS thru NPS for other network equipment, so it's easy to add one more task. ... View more

Re: Flash Swag Giveaway!

by Nash in Community Announcements
‎03-21-2019 10:09 AM
2 Kudos
‎03-21-2019 10:09 AM
2 Kudos
XL Black t-shirt please? Thank you! ... View more

Re: Meraki to sonicwall vpn agressive mode equivalent?

by Nash in Security / SD-WAN
‎03-21-2019 09:16 AM
‎03-21-2019 09:16 AM
Our typical practice is to get a static public IP, then have the ISP's equipment configured to pass the static IP through to the MX btw. So I'd get you a static IP, put the modem into bridge mode (or equivalent), and then go from there.   You'll also want to make sure your SonicWall is set to use IKEv1, and that your lifetimes match. I've run into issues before where the remote site SonicWall defaulted to IKEv2, which Meraki does not yet support.  ... View more

Re: AP's not applying RF profile

by Nash in Wireless LAN
‎03-21-2019 06:46 AM
1 Kudo
‎03-21-2019 06:46 AM
1 Kudo
Do you have physical access to the APs right now? Can you try a quick factory reset to ensure they're pulling a completely fresh config? ... View more

Re: Which Appliance to use for VLAN

by Nash in Full-Stack & Network-Wide
‎03-20-2019 06:14 AM
‎03-20-2019 06:14 AM
@PhilipDAth's got the same logic my company uses. If there's not a lot of inter-VLAN talk, MX is fine. If there's a significant amount of traffic, L3 goes into the core switches. ... View more

Re: Vlan of MX65

by Nash in Security / SD-WAN
‎03-20-2019 06:11 AM
1 Kudo
‎03-20-2019 06:11 AM
1 Kudo
I'd plan for an outage.   If you change your subnet mask, you're going to have to update that on all devices with static IP configs.    Force devices on DHCP to refresh their IP address, and they should be updated. If you've got that outage window, you can also reboot your MX in order to clear its DHCP leases, if I recall correctly. I don't believe there's any other way to force an MX to clear its leases. ... View more

Re: DHCP boot file options

by Nash in Switching
‎03-19-2019 09:09 AM
‎03-19-2019 09:09 AM
@Ahmed83    Two options:   Copy the relevant portions of the capture and paste them into a message.   Open the pcap in Wireshark and take a screenshot. ... View more

Re: Need to add an organisation to my list on the dashbaord

by Nash in Dashboard & Administration
‎03-19-2019 09:06 AM
‎03-19-2019 09:06 AM
@SallyG , I was thinking more like 5-10 minutes, honestly. If you've just been added as an administrator to an organization, it seems to take 5ish minutes most days. 10 on a very sloooow one. ... View more

Re: Need to add an organisation to my list on the dashbaord

by Nash in Dashboard & Administration
‎03-19-2019 08:54 AM
‎03-19-2019 08:54 AM
How long did you give it? It takes a bit of time to propagate across all shards. ... View more

Re: Vlan of MX65

by Nash in Security / SD-WAN
‎03-19-2019 06:45 AM
2 Kudos
‎03-19-2019 06:45 AM
2 Kudos
Your primary question is whether or not you can manage your switches. Can you setup VLANs on the switches themselves?   If you can setup VLANs, how much routing are you expecting to do? The MX can do some, but may get bogged down if you have A Lot going on.   In order to use a vlan, you're going to need to draw it from your source of routing through your switches and exit at your endpoints. It looks like your WAP is also a cloud solution, so you're going to have to draw the VLAN to your AP, and ensure that your SSIDs are configured to assign devices to the correct vlan.   Assuming all that - check out this doc for how to setup vlans on the MX itself: https://documentation.meraki.com/MX/Networks_and_Routing/Configuring_VLANs_on_the_MX_Security_Appliance ... View more

Re: Meraki in the wild - time to brush off those detective skills...

by Nash in Off the Stack
‎03-18-2019 01:36 PM
2 Kudos
‎03-18-2019 01:36 PM
2 Kudos
Panera in the US, pretty much all day every day. My partner likes to make fun of me because I'll whip around and try to identify the model of the AP. ... View more

Re: Configure a mobile WAP across networks?

by Nash in Dashboard & Administration
‎03-18-2019 12:08 PM
‎03-18-2019 12:08 PM
Pretty sure that's a non-starter. A device can belong to a single network at a time in the dashboard. ... View more

Re: Block All users from Internal ip device allow some

by Nash in Security / SD-WAN
‎03-18-2019 09:37 AM
‎03-18-2019 09:37 AM
True fact, but I thought one was discouraged from using MX as the router itself.  ... View more

Re: Communication in Wan 2 is failed - SDWAN

by Nash in Security / SD-WAN
‎03-18-2019 09:12 AM
1 Kudo
‎03-18-2019 09:12 AM
1 Kudo
Are you trying to do something like AutoVPN as well as MPLS?   If so, Meraki has a document here on how to configure a failover situation. Please note that it does not discuss load balancing across the two links, as they are not both WAN.   Please also note that it clearly shows the MPLS connected as a LAN connection, as opposed to WAN. You might also find this article useful. ... View more

Re: Block All users from Internal ip device allow some

by Nash in Security / SD-WAN
‎03-18-2019 09:03 AM
‎03-18-2019 09:03 AM
Does all your traffic hit the MX before being able to go to that IP's subnet?   If it is, you probably really need a switch (with L3 if you've got multiple subnets). MXes aren't routers.   If not, then the outbound rules on the firewall won't help you here. If your traffic is on the same subnet, or if routing between subnets is handled by a proper L3 device, then it won't hit your MX's rules.   You'll need to setup an ACL on the appropriate switch(es) in order to a) first allow your wanted traffic then b) issue a blanket deny to that IP. ... View more

Re: Change IP of VPN on Meraki MX84

by Nash in Security / SD-WAN
‎03-15-2019 06:27 AM
1 Kudo
‎03-15-2019 06:27 AM
1 Kudo
Count me as another vote to use the dynamic DNS provided by Meraki when configuring profiles on your end user's computers. It's especially good practice if you have multiple WAN links.   Easiest place to grab it is from the Client VPN page - it's the second line down, starts with Hostname.   If you don't want to be using wharrrrgarrbbll.dynamic-m.com, you can setup a CNAME record for vpn.yourdomain.com or whatever, on your public DNS. ... View more

Re: New SWITCH PORTS View

by Nash in Switching
‎03-12-2019 11:12 AM
‎03-12-2019 11:12 AM
I honestly like it, but I need assistance with keeping my eye on a single line. I'd kill for some light-dark highlighting, really. ... View more

Re: Report for RF spectrum.

by Nash in Dashboard & Administration
‎03-12-2019 06:03 AM
‎03-12-2019 06:03 AM
Haha, yeah, it is. I just have to talk others into using them when "that's not how we've always done it." ... View more

Re: Report for RF spectrum.

by Nash in Dashboard & Administration
‎03-11-2019 09:49 AM
1 Kudo
‎03-11-2019 09:49 AM
1 Kudo
Thank you for the insight, @MerakiDave. My company's default had been to create a single wireless network for organizations with multiple sites, but I'm now thinking that we shouldn't oughta do that. Especially not for sites that have multiple types of Meraki equipment. (Most commonly - MX and APs.)   Our thinking had been that it makes it easier to broadcast the same SSIDs across multiple sites. But how hard is it to setup the same SSID, really? Especially when the clients don't want PSKs changed regularly.   We don't have a lot of large deployments right now, but we will in the near future. I'm going to start a team discussion about creating a new standard to put us in a better position for when that happens. ... View more

Re: Recycling the power cord bags

by Nash in Off the Stack
‎03-08-2019 06:28 AM
‎03-08-2019 06:28 AM
Power cable bags are good for random cables in your go-bag. (Cisco console cable, micro-USB, power cable for my laptop charger.)   Not good for hand-embroidery, as the weave is very very fine and you're going to drive yourself nuts trying to cover any amount of surface. It's also very firm and you will stab yourself due to needing a sharp needle and forgetting your thimble. I did try though. I wanted to label with pretty colors vs. bad sharpie handwriting.   I suspect they'd take ink stamping very well, so long as you put something absorbent in the bag to prevent bleed-through.   Stacking cable bags hold small knitting projects. I've thought about using one to hold my common screwdrivers, with a couple of paperclips slipped through a few warp threads.   Power-injector bags are good for dice bags.   Who's guessed I work for a VAR and have a heap of these things? ... View more

Re: How to test a second new RADIUS server (NPS) for vpn clients

by Nash in Security / SD-WAN
‎03-06-2019 09:38 AM
‎03-06-2019 09:38 AM
This situation is why we need a test setup specifically for the client VPN, if that's even possible.   I don't think using the 802.1x test off your wireless would necessarily be too helpful here, since that'd be testing off your APs instead of the fw. Did you copy your 802.1x config over to the new NPS server, with your APs as valid clients?   If you're using that test button and not getting a valid test when you should, you probably should check to make sure that packets are actually leaving your device and being received by your NPS server. You can do a pcap off your Meraki device, and then check your NPS logs on your server.  ... View more

Re: MR53 is going offline intermittently.

by Nash in Wireless LAN
‎03-06-2019 06:35 AM
1 Kudo
‎03-06-2019 06:35 AM
1 Kudo
Have you tried a factory reset on the device? If you've done that, and it's still exhibiting this behavior, I'm also Team RMA. ... View more

Re: Cisco Meraki Partner Forum?

by Nash in Community Tips & Tricks
‎02-27-2019 11:03 AM
1 Kudo
‎02-27-2019 11:03 AM
1 Kudo
I'd be down, even though I desperately try to stick to being the nerd in the corner and not care about salesing. 🙂 ... View more
  • « Previous
    • 1
    • …
    • 36
    • 37
    • 38
  • Next »
Kudos from
User Count
akfrnd
akfrnd
1
JGill
JGill
1
allenfred
allenfred
1
cmr
Kind of a big deal cmr
8
JakiraBias1
JakiraBias1
1
View All
Kudos given to
User Count
GreenMan
Meraki Employee GreenMan
2
DarrenOC
DarrenOC
2
nikmagashi
nikmagashi
1
PhilipDAth
Kind of a big deal PhilipDAth
175
Melissa
Meraki Alumni (Retired) Melissa
5
View All
My Accepted Solutions
Subject Views Posted

Re: We need a Wi-Fi count per tag/building

Wireless LAN
3050 ‎06-30-2020 09:41 AM

Re: VPN Split tunnel on iPhone IOS

Security / SD-WAN
8774 ‎06-25-2020 06:34 AM

Re: split vpn traffic / dns resolving

Security / SD-WAN
1089 ‎06-08-2020 03:30 PM

Re: Meraki MX 64 & NAT Rules

Security / SD-WAN
2737 ‎06-04-2020 06:56 AM

Re: Would the factory reset of a Z1 device disable 2FA from dashboard

Dashboard & Administration
2336 ‎05-26-2020 08:26 AM

Re: Communication between Client VPN and IPSec peer subnet

Security / SD-WAN
1134 ‎05-18-2020 09:10 AM

Re: RADIUS server for VPN question

Security / SD-WAN
2112 ‎04-03-2020 11:18 AM

Re: Reorganizing our Dashboard

Dashboard & Administration
5568 ‎03-26-2020 02:05 PM

Re: Unable to ping servername, but servername.domain.com works (VPN and DNS...

Security / SD-WAN
2790 ‎03-23-2020 05:59 PM

Re: Windows 10 Split VPN

Security / SD-WAN
7608 ‎03-19-2020 07:27 AM
View All
My Top Kudoed Posts
Subject Kudos Views

Re: Does disabling all SSID's on an AP turn off the WiFi antennas completel...

Wireless LAN
8 2896

Re: Client VPN & tethering to iPhone

Security / SD-WAN
7 4633

Re: ECMS2

Off the Stack
7 12187

Re: Revealing Round 2 of the 2020 Meraki Community All-Stars!

Community Announcements
6 4568

Hangout spot for Cisco Live Virtual

Off the Stack
6 788
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki