Jump to content

Recommended Posts

Posted

I'm testing Meraki with a new ipad (ios7) to see how it would work in our school - the potential looks good.

 

I've configured Meraki and done the registration on the ipad (using the network number) and it now appears in my console. I seem to be stuck where everyone else gets stuck i.e "Client synchronization is not yet complete"

 

I've set the ipad to use our wireless and smoothwall proxy, and whitelisted meraki.com. Our smoothwall goes out of the firewall so http/https is allowed straight from there.

 

We don't have an LEA firewall to worry about so this should be simple, but I'm stuck as to what else could be wrong with this?

Posted

Well checked the firewall - nothing blocked , checked smoothwall and access to ?.meraki.com going through fine.

 

I guess its a non starter for meraki on our network, back to the drawing board!

Posted

I'm not actively using it, but I did get it running to test through the LEA here, I seem to remember that I needed to also allow some service addresses not based on "whatever.meraki.com"

 

They used to have a big list of ranges\addresses on their website that needed to be allowed but I cannot find it in the help, looks like it has changed since I was last there - pre Cisco.

 

Looking for my notes on the firewalls settings...

Posted

This is what I have from my notes, hope this helps - but it may be woefully out of date...

[TABLE=width: 568]

[TR]

[TD]Protocol(s)

 

[/TD]

[TD]Port e.g. 80

80

443

993

2195

2196

5223

5228

60000 TO 61000

[/TD]

[TD]Protocol e.g.

TCP

TCP

TCP

TCP

TCP

TCP

TCP

TCP

TCP

 

[/TD]

[/TR]

[TR]

[TD]IP Addresses From

 

[/TD]

[TD=colspan: 2]INTERNAL

 

[/TD]

[/TR]

[TR]

[TD]IP Addresses to

 

[/TD]

[TD=colspan: 2]

64.156.192.82

64.156.192.83

72.249.183.162

72.249.183.163

50.18.152.159

*.amazon.com

 

[/TD]

[/TR]

[/TABLE]

Posted

Cheers for the info -I've set up our firewall to allow what they say for IOS, but it makes no difference. Obviously meraki is no use if you're using a web proxy.

 

Their list is much smaller:

 

Systems Manager

 

Clients using Meraki Systems Manager initiate outbound management connections to the Meraki cloud using the following addresses and ports:

 

Mac/Windows

 

46.165.249.7, 74.50.56.233, *.amazon.com - TCP ports 80, 443, 993, 60000-61000

 

 

iOS

 

46.165.249.7, 74.50.56.233, 50.18.152.159 - TCP port 443

* - TCP ports 2195, 2196, 5223

 

Android

 

46.165.249.7, 74.50.56.233 - TCP port 443

* - TCP port 5228

Posted
yes, this was / is an issue for me. I tried to make bypasses but it wouldn't work. I don't see how it could (as proxy is set by user, and Meraki client needs to work as a service)
Posted

I think the only way to allow it to work is to allow unproxied access to everything, not a very good option for a school.

 

Just frustrating as it had so much potential, I'll have to use the Apple configuration manager instead.

Posted

You also, need to allow through Apple APNS Servers, which do the pushing and syncing:

 

The entire 17.0.0.0/16 range is owned by apple, whitelist that

 

Also whitelist: gateway.push.apple.com and feedback.push.apple.com also ports 2195 and 2196 for Push and Feedback APNS.

Posted

Hmm, I deleted all of rules I initially put into our firewall and then simply allowed Port 5223 outbound - after an initial delay my dashboard now shows the ipad and installed the App I selected!

 

Hurray! And that's literally only allowing Port 5223, with the web proxy set manually on the ipad.

Posted

Actually, scratch that! After the initial connection and subsequent software download it doesn't connect anymore :mad:

 

Given up with this now, apple configurator is the better solution.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...