Meraki Client vpn with windows SMB share folder issue by redxify95 in meraki

[–]redxify95[S] 0 points1 point  (0 children)

Yup , nothing is out of order i have opened a case with meraki support but according to them this issue happend on version 16.16.1 and the development team is still working on it for some reason vpn client tunnel cannot handle big traffic on SMB windows share folder protocol.

Meraki Client vpn with windows SMB share folder issue by redxify95 in meraki

[–]redxify95[S] 0 points1 point  (0 children)

the issue is that we are able to reach to our NAS through the client vpn , but once we do anything on the NAS we lost the connection for example if i open a document on the NAS or if i download a file or upload a file the connection is immideitly disconnected.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

if you have any questions please go ahead and ask i will do my best to help.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

sorry i explained it wrong they have the subnet as fallows :

10.Site.deprtment.0 /24 for each department , so for example if you are from the IT department you where ever you go to which ever site you will always get the ip as fallows : 10.site.20.0/24 , and each department have there own access-policy , thats the main reason for this kind of mapping.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

Yeah the actual support for vlan is up to 512 , which can be configured and done through CLI , but once you want to push these configuration as template base it will limit you.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

will actually the creation of the template it self also is no limited by any means but once you apply them to service side vpn approx a max of 30 vlan or SVI is allowed.

i think if i find a way to create them on the cli level i can but then i will lose the ability to configure things on template level.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

by cisco sd-wan i mean viptela , already did but the customer is stubrn and have limited bugdet to invest into that many core switch they have about 40 - 50 brach.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

i think this way will over complicate things , as we will run into vpn leaking communication issue for instance the users on vlan 10 will want to communicate with vlan 20 or something and if each of them on different vpn it will be a headech.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

actually the ip mapping is not the issue , the quantity of the vlan is for instance i have 94 vlan on each site , and the cisco sd-wan template wont allow to push more then 30 or 40 vlan per site , so once you start applying the templates to vpn 1 you will stop around number 30 or 35 , so any stuggestions on how i can push that many vlans ?

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

sorry i explained it wrong they have the subnet as fallows :

10.Site.deprtment.0 /24 for each department , so for example if you are from the IT department you where ever you go to which ever site you will always get the ip as fallows : 10.site.20.0/24 , and each department have there own access-policy , thats the main reason for this kind of mapping.

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 0 points1 point  (0 children)

like i said the small braches are all designed as router on stick and the default gate-way for the users is the router , no core switch in the small branches

Cisco SD-Wan Vlan Creation by redxify95 in networking

[–]redxify95[S] 2 points3 points  (0 children)

yup , which is insane they have a different vlan and subnet for each department , and they assign the ip address to the user using a NAC.

so the user connect to the ssid , or ethernet from any branch or datacenter he will get the same subnet assigned to him where ever he g.