Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello. I created an "Internet only" VLAN on an MS switch. I have an ACL in place that prevents this VLAN from accessing all of my other production VLANs. This "Internet only" VLAN will be for some guests that will be wired clients for several week...
Hello.Is there any way to limit a user's access to specific VLANs when they connect using the AnyConnect VPN client?In other words, I'd prefer they only have access to a few specific VLANs.Thanks!
Hello. I will be using VLAN tagging on a couple of SSIDs. I created a VLAN of 511 (Management) on my switch stack as well as the respective static route on the MX. The VLANs for the SSIDs will be 501 and 502. Regarding the port that the MR access...
Let's say a virtual stack is currently setup with L3 routing enabled and several defined VLANs. One of those VLANs is 104.Now, you connect a new flexible stack to the existing virtual stack. You are a glutten for punishment and need to enable L3 ro...
Well, these are guests "squatting" in our office from different trades. Ideally I would prefer that none of their machines can contact each other on the same VLAN. I don't have enough ports to properly patch them into our Meraki switches.
An update regarding this.An ACL blocking the "Internet Only" VLAN from itself worked. Enabling port isolation on each port worked as well.However, none of these settings will work if a switch (obviously non-Meraki) is connected to one of these ports...
This is exactly what I am looking for.If I am understanding this correctly, the Group Policy (the group created) on the Meraki side does not correlate to a group in AD, correct?This just applies to a specific Network Policy on the RADIUS server.I wou...
So, native VLAN of 1 and then set the VLAN on the IP address tab of the AP to the correct management VLAN of 511?VLAN 1 does not really exist, meaning there is no subnet defined, so where would it grab an IP address from?
So, I can tag a switchport with a VLAN number that is not defined as an L3 routing interface?In other words, if I created a VLAN of 3010 on paper only, I can still tag a port on the switch with a VLAN number of 3010 without it actually existing (defi...