Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello there,has anyone ever managed to set up a VPN with tunnel interfaces using a MX?We have a few customers that use the MX for SD-WAN to connect to their sites. They also need VPN tunnels to non Meraki peers which is no problem with policy-based v...
Hello there,we have a root CA imported to our Access Manager.There we can set the identity part to either: Common Name or RFC822(mail):If we want to authenticate with device certificates we need the Common Name as identity.Obviously our non domain de...
Hello there,
we have a two-node deployment with our PAN on a SNS3615.
Since the last upgrade to 3.4 P2 the licensing page shows this screen:
As far is i'm informed. Version 3.4 P2 should be supported on the SNS3615 platform.
I already renewed the re...
Hello there,
I just updated a ISE from 2.7 to 3.4P1. We use an api user to check the backup status of the nodes. After the update we only get 404. SNMP checks with the same user work fine. The buttons to toggle Open API are missing since the upgrade....
Hello there,yesterday we created about 80 new FW rules after migrating all services to our MX-Cluster.Today I want to see if everything is working and if traffic is getting allowed by the correct rules.In the firewall log I can see almost every entry...
We don't try any random recovery commands because the switch is inaccessible now. After cloud conversion the cli is read only and the specific switches dont have a local status page.We also have these lines in the startup cli output. This is 100% the...
We have C9200CX-12P-2X2G and in the boot log via cli they show very old versions 17.5.xx.We upgraded all to 17.18.3 before cloud conversion tho. I have not checked the version of other switches, if they all show an older release or not. We have a TAC...
Hi Aimad,we have the same issue with a few switches after cloud conversion.How did you fix it? Is RMA the only way?I tried everything to get them online. Did many packet captures and can confirm that the switches IP layer is dead. Best regards
Hi Aelxapie,i tested your solution and it works just fine. On the other side i have a firewall(sophos and sonicwall) using xfrm tunnels and on the meraki side it looks just like you suggested. Now we can make IKEv2 work with multiple subnets on the ...
Hi,we considered using BGP but this is not the right solution for our customers and we can't force this configuration on third-party service providers. We just want to use a normal solution like we do with our other firewall vendors.Best regardsPhili...