Community Record
8
Posts
0
Kudos
0
Solutions
Badges
Jan 29 2024
8:55 AM
Switch 6/48 has the uplink cable from ISP plugged in which I tried assigning both trunk with no native vlan(saw that Palo alto has issues with meraki and trunking with native vlan assignment) as well as access vlan 100(this vlan is just for use of isp uplink). Both of these assignments to 6/48 did not get internet traffic and meraki dashboard could not reach the switch stack.
... View more
Jan 29 2024
7:07 AM
The management vlan is set to a specific vlan of 1900. When I first configured the switches I assigned them a static IP within this vlan before testing in production with our firewall. All it was connected to when I configured IP was another meraki switch just to get it setup.
... View more
Jan 29 2024
7:01 AM
The ms250 is new and replacing the 4510? Yes I preconfigured ports but it is a new switch/stack of 6 switches. The ms250 is going to do layer3 routing? No this will just be doing layer 2 traffic. The firewall handles all layer 3 routing. All ms250 switches have layer2 connectivity to the firewall/isp subnet? I was able to reach the firewall interface from an internal PC that was plugged into the switch stack so yes it was able to reach with layer 2.
... View more
Jan 29 2024
6:59 AM
Next time I test I will try this. Thanks!
... View more
Jan 29 2024
6:20 AM
Yes I looked at the logs and only saw internal traffic going through the firewall which let me to believe that something between the firewall and MS switch was not configured correctly but I could not figure it out.
... View more
Jan 29 2024
5:54 AM
Hi all, I did a switch migration test over the weekend and ran into an issue with our (6) MS250-48P switch stack not being able to reach the Meraki cloud and no internal endpoints reaching outside our network. We are switch from a standard Cisco switch to this new meraki switch. To give a bit of our topology background, Our existing "core" Cisco Catalyst 4510R switch does all of our layer 2 routing for our building but just 1 port has the ISP uplink which connects over to our Palo Also firewall interface to filter traffic. The firewall then routes back to the switch. I know this is a weird setup to have switch first then firewall but this is just how it was setup when I was here. On the MS250, The switch port for the uplink has been set to trunk with no native vlan set as well as an access port with vlan 100 to firewall traffic to our firewall. The firewall interface is assigned as trunk with no tag. For some reason internet was not accessible with this setup but internal traffic was being routed. I talked with the meraki tech and he was puzzled as well. He mentioned it could be related to bridge priority not being set properly but even when we set that up still no internet. I am curious if someone has run into this issue as well or if anyone has an idea to make this work. Thanks! EDIT: Added a topology image for reference to better explain my setup.
... View more
Labels:
- Labels:
-
Interfaces
Nov 9 2023
1:08 PM
That is one thing I was wondering if it would be beneficial to stack instead of daisy chaining. I do not like that if lets say switch 4 goes down then switch 1-3 wont get traffic. Will physical stacking allow for this safeguard?
... View more
Nov 9 2023
11:49 AM
Hi all we we ordered 6 new MS250-48P Meraki switches. We already paid for them and just planning out how best to set them up given our existing firewall setup. To give a bit of background I work for a small non-profit with 1 office who does not have the biggest budget but enough so we can get something like these switches. Our server room consists of 1 rack for networking. We use 2 HA firewalls for our routing of traffic and VLAN creation so the majority of heavy lifting is done by our firewall. We currently have and are replacing a Cisco Catalyst 4500 series which has 6 blades (thus the 6 switches) which was used an as access layer switch besides only 1 port feeding into our firewall for the uplink. We dont plan to have another ISP for redundancy and are a hybrid wfh office so if we did lose internet in the building everyone can go home until we can swap out the switch for another. Given that background I wanted to know what your thoughts are on setup of these new switches. Ideally any potential for redundancy without a significant cost increase would be great. Below is a rough topology of what I was thinking with a daisy chain layout. Not sure if that would be best though given if one switch goes down, the others don't get traffic. This is my first time swapping out networking switches and networking gear of any kind so I want to make sure this is setup properly. If you have any suggestions and something that is totally wrong please let me know. Thanks!
... View more
Labels:
- Labels:
-
Layer 2