Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi.I post this question on reddit.com/r/cisco, but didn't get a response, so hoping for some feedback here instead...I recently rolled out Anyconnect, which is working great for it's intended use - getting users conected when outside the office. Howe...
Hello. I have a site-to-site VPN setup between two MX's very far apart. Only the necessary VLAN's on both sides are configured to be a part of this S2S. I expect very little traffic; some occasional AD replication perhaps, but not much else. Yet my u...
Hello,Yesterday I added a 2nd MX to our network, which until this point was a single MX75. We have a block of 5 usable IP addresses from our ISP.x.x.x.202x.x.x.203x.x.x.204x.x.x.206x.x.x.207Our single MX was set to use .202 as its WAN IP. I setup the...
Hello,I have a single MX75 and looking to add a 2nd for HA. Having read the docs I plan to use Virtual IPs as this offers seamless failover.My WAN1 has 5 usable IPs, so I have the required 3 IPs available to configure one on Primary, one on Spare and...
Hi,Having recently split a flat network into VLANs, I am noticing reduced througput with inter-vlan routing. This is hardly surprising. I'm using an MX84, which has a 'statefull firewall throughput' advertised at 500 Mbps. [MX84 Datasheet]Convenientl...
It is enabled. If I disable this, how could I manage the MX? When clicking the 'what is this' link below, it says the MX will not be able to be managed locally and to configure remote management, then redirects to the firewall rules. Is remote manage...
Thanks for the tip. Unfortunately I don't see the 'Traffic Analytics' menu under my network. Is it a requirement to have Meraki switches for this to show up? If so, this might explain it - we only have the MX's.
Thanks all for the suggestions. They are all useful suggestions. For now, I have setup NetFlow to our PRTG platform and will leave that running overnight to collect more data.
@CMR wrote:Not that it is a solution, but I've always advocated using L2 unmanaged switches for WAN splitting for two reasons:1) what you've seen here where perhaps some tags are clashing2) as the switch is completely unprotected, best to have someth...
So, a packet capture on my switch (mirroring port 1, which is connected to the ISP uplink) showed traffic arriving addressed to IP 205, which confirmed at least the IPS stuff was working as expected. Another packet capture mirroring port 2 (which goe...