Summary Running log of all note creations, updates, and deletions in this vault. Updated automatically each time a note is created or edited.
KBA-050 - Meraki Switch Stacks — Stack Order, Port Numbering, and Member Failure — corrected the Port Numbering section, which was written from classic MS behaviour and was wrong for Meraki-managed Catalyst. Split into separate treatments: classic MS keeps ports numbered 1 to N with no member prefix, while Catalyst switches retain IOS-XE interface names including the StackWise switch number. Documents that three numbering schemes coexist and need not agree — physical position, dashboard stack member number, and IOS-XE switch number — with the stack-splitting example that leaves a new stack numbered 5 to 8, and the absence of switch renumber in Meraki-managed mode. Configuration binding to the switch serial is unaffected and is now sourced rather than inferred.
KBA-050 - Meraki Switch Stacks — Stack Order, Port Numbering, and Member Failure — added two sections. "Does Port Configuration Move on Reboot?" works through a three-member VLAN example and explains why an Active re-election cannot migrate port configuration between physical switches: config is bound to the serial, and there is no member number for it to be bound to. "Catalyst Switches in Meraki Mode" covers MS390 and C9300-M/X/L behaviour — whole-stack reboot and factory reset, the Standby role, single management IP, local status page redirection, and the management container reinitialisation that delays recovery. The former "Reboot Behaviour Differs by Platform" section was absorbed into the Catalyst section.
KBA-007 - Cisco IOS-XE AAA Overview — added reciprocal links to KBA-008, KBA-029, KBA-013, and KBA-019, completing the cross-reference review (the file was unreadable when the rest of the vault was updated).
Vault-wide cross-reference review — audited every note's See Also section and added missing links across 37 notes. Added reciprocal links where a note was referenced but did not link back (KBA-041/KBA-042, KBA-004/KBA-038, KBA-043/QRG-014, KBA-045/KBA-046), and connected the newer notes (KBA-041 to KBA-046, QRG-013, QRG-014) into the older topic clusters they relate to. Twelve previously unreferenced notes now have inbound links; no orphaned or broken links remain.
KBA-046 - DHCP Snooping on IOS-XE — New KBA covering the trusted/untrusted port model, the snooping binding database and its role underpinning DAI and IP Source Guard, and the IOS-XE defaults that most often cause outages — all ports untrusted on enable, Option 82 insertion on by default with giaddr zero, and bindings held in memory only.
KBA-045 - DHCP — Lease Process, Renewal, and Helper Addresses — New KBA covering the DORA lease acquisition exchange, the client lease state machine (T1 renewing at 50%, T2 rebinding at 87.5%, expiry), DHCP relay operation and the role of the giaddr field, the eight UDP services ip helper-address forwards by default, Option 82, and common relay misconfigurations.
QRG-014 - IEC 60320 Cable and PDU Visual Reference — New visual reference QRG showing photographs of all five cable types and both PDU types covered in KBA-043.
KBA-043 - IEC 60320 Power Connector Identification — New KBA covering IEC 60320 connector numbering convention (odd = female, even = male), physical identification of C13, C14, C15, C19, and C20 connectors, common cable combinations, and PDU types (BS1363 and C13).
KBA-042 - Meraki AutoVPN — VPN Registry and Route Distribution — New KBA explaining the VPN registry as AutoVPN's control plane; how hubs and spokes register subnets and learn routes via the registry rather than dynamic routing protocols; hub mesh non-transitivity; the distinction between registry (control) and DPD (liveness); cloud dependency model and behaviour during cloud outages.
KBA-041 - Meraki AutoVPN — Spoke Site Failover and Non-Identical Route Tracking — New KBA covering AutoVPN route tracking defaults, the non-identical route failover problem (why black-holing occurs when specific-prefix hubs fail despite covering supernet routes), the hidden backend flag that enables fallback to less-specific routes, scope considerations, questions for Meraki support, and design guidance.
_#N suffix for duplicate-purpose segments; _LAN/_WIRELESS/_TRANSIT suffix conventions; DMZ01-style numbering for DMZ zones).decommission-checklist-template.xlsx and updated the download link.EDGE_IT_TRANSIT to WAN_IT_TRANSIT; renumbered the DMZ VLAN example to start at 401 (v0.2). Changed the DMZ naming convention to DMZ0X_<TECHNOLOGY> format (v0.3). Added a note explaining the LAB_LAN expansion zone — VLANs 14–20 spaced by 2, names increment by 1 (v0.4).KBA-040 - Cisco Catalyst and Meraki MS Switch Comparison — New note comparing Catalyst 9300 vs MS250/MS350 and 9200 vs MS225; verified against Meraki MS Family Datasheet. Stacking bandwidths corrected (MS225/MS250 = 80 Gbps, MS350 = 160 Gbps); MS225-48FP PoE corrected to 740W.
STN-DRAFT - Meraki Network Tagging Standard — New draft standard defining mandatory site_code:, region:, and environment:staging tags for all Meraki networks.
KBA-039 - Meraki MX75 and MX85 — Model Comparison — New note comparing the MX75 and MX85; fully verified against MX Family Datasheet (October 2025). MX75 is desktop/wall-mount (not rack), VPN throughput differs significantly (1 Gbps vs 2.5 Gbps), max VPN tunnels 75 vs 200, MX75 has 2× LAN PoE+, MX85 has 1× WAN PoE+. Licensing tiers corrected to SD-WAN Plus / Advanced Security / Enterprise.
KBA-037 - Cisco Enterprise Agreement — New note explaining the EA model, True Forward consumption mechanism, covered product families, and how it compares to per-device licensing.
KBA-038 - Cisco Secure Client VPN Authentication — SAML and Active Directory on FTD — New note explaining the architecture of SAML and AD-based VPN authentication on FTD, covering authentication vs authorisation, PHS/PTA/AD FS IdP modes, LDAP authorisation, DAP, and FMC configuration overview.
auth sha256 (SHA-256) instead of auth sha (SHA-1, deprecated per NIST SP 800-131A). Added IOS-XE 16.9+ version requirement note. Strengthened minimum password guidance.KBA-034 - Meraki Firmware Lifecycle and Upgrade Management — New KBA covering firmware release tracks, upgrade scheduling, maintenance windows, firmware lock, upgrade behaviour per device type, and best practices.
KBA-035 - Meraki Dashboard — Cloud Management Architecture — New KBA covering cloud management architecture, control/data plane separation, protocols and ports, certificate-based device authentication, configuration delivery, cloud outage behaviour, and management channel security controls.
CFG-001 - IOS-XE NTP Configuration — First note in new Config Snippets section. Covers NTP server config with and without authentication, verification commands, and key considerations.
Config Snippets/ created. CFG-NNN prefix and cfg tag registered. section_for_path() updated in wikijs_publish.py to route Config Snippets to the ## Config Snippets index section. CLAUDE.md updated.kba, qrg, stn, or draft) to frontmatter of all 42 notes that were missing it.meraki-uac-obsidian-note.md deleted from vault root. Republished to wiki.js._remove_old_index_link() function; called after a successful pages.move to remove the old index link immediately, preventing dead links when a note is renamed.cisco-ios-xe-common-security-configurations, ios-xe-device-admin-mfa-ise-33-and-duo-integration, tacacs-best-practices-for-cisco-ios-xe-deployment.QRG-006 - Tailscale Network and Firewall Guide — Renamed from 'QRG-006 - Tailscale — Network and Firewall Quick Reference'. Wikilinks updated in 0 note(s).
QRG-001 - Active Directory Firewall Rules — removed redundant 'Quick Reference Guide' suffix from title. Wikilinks and wiki.js updated.
QRG-004 - Meraki Packet Capture Filters — removed redundant 'Quick Reference Guide' suffix from title. Wikilinks and wiki.js updated.
QRG-007 - Wireshark Display Filters — removed redundant 'Quick Reference Guide' suffix from title. Wikilinks and wiki.js updated.
STN-DRAFT to approved standard. Status set to Approved, version bumped to 1.0, Approver set to Mike Jones, Approved Date 2026-04-29. Draft callout removed. Moved from Draft Notes/ to Standards/. wiki.js page moved to new slug and republished.Draft Notes/. Published to wiki.js.section_for_path() updated: General Technology folder now maps to ## Knowledge Based Articles index section.## General Technology section renamed to ## Knowledge Based Articles.Applied KBA/QRG/STN numbering scheme to all 41 vault notes:
insert_link_in_index() to accept a section parameter and added section_for_path() to derive the correct index section from the vault subfolder. New notes now route to ## General Technology, ## Quick Reference Guides, ## Draft Notes, ## Standards, or ## Release Notes automatically. The stray ## Published Notes section was removed from the wiki.js index and the MPOE note link moved to ## General Technology.Draft Notes/. Published to wiki.js.Cisco and Meraki/: Quick Reference Guides (5 notes), Draft Notes (1 note), General Technology (32 notes — includes all former Standards notes). ! Changelog.md remains at the vault root. default route change.tcl moved to General Technology/. Obsidian wikilinks are unaffected — Obsidian resolves [[wikilinks]] across subdirectories automatically. Publish scripts (wikijs_publish.py, vault_rename.py, vault_health_check.py) updated to search the vault recursively. Wiki.js index page updated to group notes by category. CLAUDE.md workspace layout and inventory updated.powershell fence to text. Updated wikilinks in six notes that referenced the old hyphenated filename.powershell fences to text.pages.move.aaa new-model (required before all other AAA commands); replaced default authorization and accounting lists with named lists (VTY_MFA, CON_LOCAL) to keep console break-glass fully independent of TACACS; applied authorization lists explicitly to line con 0 and line vty configs; updated break-glass username to use algorithm-type scrypt rather than default MD5 hashing.Native VLANs on trunk ports.md to Title Case.> **Summary\n> text callouts to single-line > [!INFO] Summary text format for correct wiki.js rendering.**obsidian_to_wikijs() regex to handle both one-line and two-line INFO callout formats.technical-notes/). Contains agent roster, workspace layout, vault conventions, wiki.js setup, working preferences, note inventory, and session history.pages.move mutation; index link updated.