Skip to main content

 

Cisco Meraki Documentation

Troubleshooting Meraki Cloud Connectivity After IP Range Changes

Clike 日本語 for Japanese

Overview 

The Cisco Meraki engineering team is changing the IP addresses that devices use to contact the cloud. These changes are part of ongoing efforts to improve performance and resiliency. 

For customers with restrictive firewalls that block access to new IP addresses, firewall changes may be necessary to ensure that devices remain fully functional after January 28, 2023. 

Troubleshooting firewall blocking new IP ranges

Cisco Meraki is adding two new IP ranges to the list of IP addresses that devices use to contact the cloud. Devices will additionally connect to IPs in the 216.157.128.0/20 and 158.115.128.0/19 subnets. 

Other addresses required for devices to operate correctly generally remain the same. Reference the Help > Firewall info page in the Meraki dashboard to identify the firewall rules required to allow devices to contact the cloud. 

Troubleshooting steps

Reference the Help > Firewall info page  in the dashboard at any time to do the following to check if your device is affected:

  • Identify the firewall rules required to allow devices to contact the cloud. To ensure the best performance from devices, create each of the firewall rules listed on this page. 
  • Identify which specific Meraki devices are failing firewall tests in the section titled "Firewall Test Failures" and downloading the CSV file that will have the details of the nodes and the tests that have failed. 
    • Only org admins will be able to view this section
    • This section will only be visible if the org has nodes failing firewall tests.
    • Tests run every 4-6 hours. If you update your firewall rules to fix all nodes failing firewall tests, then the nodes will not show as failed after the next test is run.

Below is a screenshot of the section referred to

Automated test results showing how many devices in the organization failed to connect to the Meraki cloud using the meraki new IP ranges

Expected outcome 

Once you've updated your firewall rules to match the Firewall Info page and do not see any devices with failed firewall tests, no further action is needed. If you update your firewall rules to fix all nodes failing firewall tests then the nodes will not show as failed after the next test is run every 4-6 hours.

Warning: Failing to update any upstream firewall rules to accommodate these new IP address ranges may limit the functionality of your Meraki Devices. Your devices will continue to operate and pass traffic, however they may become unable to contact the cloud to receive configuration updates and report usage information for your network. Additionally, splash pages which utilize customer-provided external authentication and other features, such as SNMP traps and CMX push, may not function properly.

Escalation 

For questions or concerns about this maintenance, contact Meraki Support for assistance. 

Troubleshooting after receiving a firewall notice email 

If you received an email asking you to update firewall rules, follow the steps in Troubleshooting steps for firewall blocking new IP ranges of this article. 

Expected outcome 

Once you've updated your firewall rules to match the Firewall Info page and do not see any devices with failed firewall tests, no further action is needed. 

Warning: Failing to update any upstream firewall rules to accommodate these new IP address ranges may limit the functionality of your Meraki Devices. Your Meraki Devices will continue to operate and pass traffic, however they may become unable to contact the Meraki Cloud to receive configuration updates and report usage information for your network. Additionally, splash pages which utilize customer-provided external authentication and other features, such as SNMP traps and CMX push, may not function properly.

Will this maintenance require any downtime? 

Downtime for this maintenance is unlikely. Much of the maintenance does not require temporarily disabling access to the dashboard or any other part of the cloud.

If a brief period of downtime is necessary, or if maintenance may result in an unexpected loss of connectivity to the cloud, a maintenance notice will be posted in advance to notify users of a potential brief disruption in access to the dashboard. Devices will continue to function and pass traffic, even if the connection to the cloud is temporarily disrupted.

A banner showing that there is an upcoming maintenance on a specific time and date

To learn more about Meraki cloud and out-of-band management, refer to the Meraki Cloud Architecture. If devices are experiencing issues contacting the cloud, or the dashboard is inaccessible outside of scheduled maintenance windows, contact Meraki Support for assistance.

How will I know when this maintenance is complete? 

This maintenance is ongoing over a period of several months and occurs largely in the background. Notifications will not be sent when maintenance for specific customers is completed. After maintenance is completed, devices may begin communicating with the cloud using the 216.157.128.0/20 and 158.115.128.0/19 subnets. 

Meraki Support cannot provide specific dates for scheduled maintenance. Do not contact  Support to request specific maintenance timelines. If maintenance may result in a disruption to the cloud, a maintenance notice will be posted in advance above all pages in the dashboard. 

Additional questions 

  • Help > Firewall info page within the dashboard — Reference for all firewall rules required for your devices to contact the Cloud. 

  • For questions or issues outside of scheduled maintenance windows, contact Meraki Support