Regarding MX VPN tunnel

Solved
KSM
Here to help

Regarding MX VPN tunnel

Hi~
 
MX has Uplink WAN 1,2.
I'm going to configure tunneling between the Meraki MX95 and the vMX.
 
Connect Auto VPN to WAN 1
 
If WAN 1 goes down, can I IPSEC with AWS VPC GW on WAN 2 to create a redundant configuration?
1 Accepted Solution
rdominguez
Meraki Employee
Meraki Employee

Hello @KSM, as @GIdenJoe has indicated, the MX has a failover process when there are two different WAN links available. So, an IPSec VPN connection is not necessary. You can find information about the failover behavior in the link below. 

 

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Failover_Behavior

View solution in original post

8 Replies 8
CptnCrnch
Kind of a big deal
Kind of a big deal

Adopting the approach https://documentation.meraki.com/MX/Site-to-site_VPN/Tag-Based_IPsec_VPN_Failover should help you out here. The only difference is that this is based on two 3rd party S2S connections.

Thank you so much for your response.!!

GIdenJoe
Kind of a big deal
Kind of a big deal

You are talking about auto VPN between an MX and a vMX.  That means you can just choose 1 WAN or concurrently both WAN's.  You don't need to do anything.  That means you don't need an IPsec VPN as backup since the autoVPN is already redundant via your both WAN's.

Thank you so much for your response.!

rdominguez
Meraki Employee
Meraki Employee

Hello @KSM, as @GIdenJoe has indicated, the MX has a failover process when there are two different WAN links available. So, an IPSec VPN connection is not necessary. You can find information about the failover behavior in the link below. 

 

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Failover_Behavior

WAN port 1 connects with AUTO VPN between MX95 and vMX.

WAN port 2 is an IPSEC connection between MX95 and AWS.

If WAN 1 goes down, WAN 2 automatically takes over.

Is this possible?

And as an additional question, if I only use WAN 1, will it work if I use AUTO VPN and IPSEC at the same time?

PhilipDAth
Kind of a big deal
Kind of a big deal

>If WAN 1 goes down, can I IPSEC with AWS VPC GW on WAN 2 to create a redundant configuration?

 

No, you can't do failover between a VMX and an AWS VPC VPN.  As others have said, the VMX and the MX95 will fail over automatically between the links.

Thank you so much for your response.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels