Skip to main content

 

Cisco Meraki Documentation

How to Enable Wired WAN Mode (WWM) or Safe Mode on Meraki MG

Overview

This article explains how to enable Wired WAN Mode (WWM), also known as Safe Mode, on Cisco Meraki MG cellular gateways. Safe Mode was renamed to WWM starting with firmware MG 3.0. 

Understanding WWM

WWM or Safe Mode configuration lets MGs come online using a wired connection when they lose an active cellular connection, so Meraki Support can troubleshoot the device. WWM or Safe Mode also provides additional troubleshooting options when a valid cellular connection is not available.

MGs can be configured to use port 1 as a WAN uplink. When you enable WWM or Safe Mode, port 1 converts to a WAN port and allows a connection to a switch, router, or ISP. Similar to an MR access point, when plugged into a switch device it will attempt to obtain a valid IP address and reach the dashboard after you connect it to a switch. When there is a valid wired network connection on port 1, the wired interface will take priority over the cellular interface even when the cellular interface is functioning properly.

Step-by-step instructions 

Enabling WWM

image of the MG LSP Configure tab showing option to enable WWM

Enabling Safe Mode (firmware prior to MG 3.0) 

On firmware versions prior to MG 3.0, WWM was called Safe Mode as seen in the below screenshot. 

  1. Go to the Safe Mode section in the Configure tab. 

  1. Check the box to enable Safe Mode

  1. Select Save

image of the MG LSP Configure tab showing option to enable Safe Mode

When using WWM it is recommended to have access to a valid working internet-accessible network to allow the cellular gateway to check in and pull configurations and firmware. Additionally, the MG cellular gateway is not intended to be used in this mode for production. This mode is reserved as a troubleshooting tool for Support to assist with cellular interface issues and to allow the cellular gateways to pull firmware upgrades without using cellular data. 

Verification

LED indicator 

Once the WWM/Safe mode is enabled, the LED on the MG will begin to rainbow. Once the MG detects the wired connection on port 1, the LED will turn white. This provides confirmation that the device is using the wired connection on port 1 as the primary uplink. 

The right graphic shows the port 1 configuration in the role of a WAN1 interface when WWM is enabled. 

image showing when WWM is enabled LAN1 port role changes to WAN1

physical image of an MG highlighting Port1

 

Dashboard alert 

The dashboard displays an alert when the MG is configured in Safe Mode

 

image of Dashboard from an MG showing the Safe Mode Detected alert when WWM is enabled

Uplink tab 

When WWM mode is enabled, the Cellular Gateways > Uplink Tab will show the details of the Wired Wan as shown in the below screenshot.  


 

image of Dashboard from an MG showing the Uplink tab when WWM is enabled detailing the WAN information

Accessing the local status page

The local status page of any Meraki device is accessible through the web browser of a host machine. By default, users must log in to pages that provide configurable options. The local status page uses digest authentication with Message Digest Algorithm 5 (MD5) hashing for the connection between the administering computer and the Meraki device to protect these sensitive settings.

The username for MGs that have default authentication credentials or have not fetched configuration will be the serial number (uppercase letters and dashes) with no password. After initial use, change the authentication credentials to a strong password.  If client traffic passes through the device, you can access MGs by DNS name at http://mg.meraki.com

Troubleshooting

Cannot connect to the local status page URL when wired

If a client is unable to resolve the local status page, be sure to check the following:

  • Client is connected to the network and is within the same subnet as the Meraki device.
  • DNS is set to the Meraki device IP or to a DNS server that will route through the Meraki device
  • Try all relevant local status page URLs (see top of this article)
  • Try incognito or private browsing to eliminate potential caching issues 

If the local status page URLs are still unreachable for some reason, the local status page can also be reached by going to the LAN IP of the device through a web browser. For more information about connecting to the local status page using a static IP, see the Accessing the Local Status Page section above.

  • Was this article helpful?