Capturing wirelss destination traffic from MX before it leaves (sort of long)

Caleb_Murphy
Comes here often

Capturing wirelss destination traffic from MX before it leaves (sort of long)

Hey everyone sorry for the long question, I will try to be really clear here.

 

In my org we use an MX250 to tunnel guest wireless traffic out to the internet. We have a couple of different SSIDs that use this set up. Once they Leave the MX they traverse our DMZ in our data center and leave a Palo Alto NGFW. On the Palo I can see destination traffic. The issue is all of the source addresses are the outside interface of the MX. So my need that that I need to see client destinations on the inside before it leaves the MX. I am to understand from Meraki support that the MX does not capture this information, and there is no way to do this on the MX. Does anyone know or have experience with capturing this information this way? I realize that in this set up a tunnel is created from the Wireless access point to the MX so that may cause an issue here. Just trying to run down some traffic issues we are seeing with some folks connecting devices to our guest wireless and sending traffic we would like to investigate. We have URL blocks and L7 firewall wall rules on the MX for all the big bads, but I am sure everyone here knows how users are and folks are constantly finding ways around them. As well if we have folks using personal devices that are reaching out to known malware or botnet C2 that the Palo picks up I would like to be able to tie that back to a user to alert them of the issue.

 

thanks in advance

 

Caleb

2 Replies 2
PhilipDAth
Kind of a big deal
Kind of a big deal

I don't know the answer, but this guide talks about the different options and when NAT is used and when the traffic is bridged.

https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/SSID_Tunneling_and_Layer_3_Roamin... 

 

I think the MX250 would need to be in VPN concentrator mode, and the guests would need to be mapped to a VLAN to see their actual traffic.

So we are also using the MX as a VPN concentrator so it is in that mode and they are mapped to a VLAN. So I can easily see what clients are wireless clients and what IPs they are being handed out, I just don't have any way to see any traffic analytics for those clients.

 

thanks for the response!

 

Caleb

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels