10-25-2021 10:33 PM
Hi all,
I've recently started receiving alerts of IP sharing after a power outage. It goes on to say "NAT has been detected on 1 client in the...," etc. I'm not sure what it means exactly. Prior to the abrupt power outage, I've never received these alerts before. Can someone educate me, please?
Thanks in advance.
Solved! Go to Solution.
10-26-2021 07:20 AM
Check your DHCP server. It means more than one client/device is using the same IP address. Go to Clients view and sort by IP address (depending on how many clients you have).
Cycle the port or client and that should fix for now. If it happens again or frequently, then more troubleshooting is needed.
10-26-2021 07:20 AM
Check your DHCP server. It means more than one client/device is using the same IP address. Go to Clients view and sort by IP address (depending on how many clients you have).
Cycle the port or client and that should fix for now. If it happens again or frequently, then more troubleshooting is needed.
10-26-2021 07:18 PM
Thank you! I will try that.
11-11-2021 12:21 PM
There has got to be another cause to be generating literally hundreds of alerts across all sites. Any ideas anyone?
11-11-2021 12:30 PM
What hardware are you guys on? We're using MS250-24Ps and the firmware version is MS 14.32
11-11-2021 01:16 PM
11-14-2021 11:00 AM
Same latest FW versions for our network Meraki switches. We are set to auto update switch FW.
11-14-2021 09:36 AM
We are seeing this on two network subnets, started all of the sudden this week. I checked the two dhcp servers on each site’s subnet AD controllers. I don’t think I have multi site DHCP issues, I think its the Meraki’s latest switch FW update… we had to turn off this alert. Waiting on Meraki to acknowledge the firmware update bug
11-14-2021 10:54 AM
I have had alerts now from a subnet that has all static IPs on it so its deffo not related to duplicate addresses issued by DHCP
11-14-2021 10:57 AM
@markrichard have you opened a case with Meraki?
Would be good to get some confirmation of a firmware related issue as the number of alerts is just crazy.
10-29-2021 06:51 AM
I noticed a new alarm type in Network-wide>Alerts that appears to relate to this:
Its appeared on my MX85 running 16.8.
If enabled, options are ASAP, daily or weekly.
Or you could disable - I cannot recall whether or not it was enable by default.
10-29-2021 07:58 AM
This is a function that was added to MS14 on a few specific switches. It watches traffic for anomalous behavior that would indicate a device is NATing clients. The intention was to try and help people identify rogue access points that are NATing and catching clients that are using VMs that may be performing NAT to the host address. We are working on producing documentation but as of today, I would recommend daily alerts, as if you have misbehaving or oddly behaving clients, it can produce false positives due to the nature of fingerprinting.
10-29-2021 08:05 AM
Ahh yes, its in the switch section of the alerts, I had forgotten that this particular network was running later switch firmware to my others.
10-29-2021 08:35 AM
easy to do, the ui could use a little modernizing!
10-29-2021 03:42 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide