Using a bridged network with multiple MX68s on it

OK2BNice2
New here

Using a bridged network with multiple MX68s on it

Hello members, 

I have attached a photo of a layout visualizing what I need to do. I have been unsuccessful so far and would appreciate any help. Imagine an ethernet bus with three locations linked via wireless bridges. Everyone can see each other at the ethernet layer. Connectivity is like this: Locations: 1---wireless---2--wireless----3 and it's all bridged together on licensed radios across a city. There are current Sonicwall routers at all three locations connecting the local LANs and allowing/disallowing traffic onto that network. (Mostly disallowing, as that is a private network without Internet connectivity.) The current Sonicwalls, of course, don't care that there is the same subnet attached to a different router.

What I want, is for the Merakis to use the microwave link when it is up, and if a microwave line is down, route traffic to the remote sites through the VPN tunnels. (Or maybe load balance, but that's out of this scope of conversation.)

I have not been successful on my test bench and I must be approaching it incorrectly. W1 is connected to 5G and connects to the Meraki registry, no problem. On the far ends of the wireless bus, W2 is connected to the wireless net. In the middle location, W2 is connected to a local LAN with a default route to the corporate firewall and a VLAN has the Microwave net on it. 

The dashboard correctly will not let me create VPNs with the same subnets that exist on the other Merakis, but they all need to have access to that same subnet when the bridge is active. I tried to put them all (W2 ports) in a VLAN but I don't see how they would export as a VPN without configuring a port for each, and them I run into the same wall. Any kind input is appreciated.

Microwave.jpg 

2 Replies 2
cmr
Kind of a big deal
Kind of a big deal

We have a similar setup but have a L2 MPLS network instead of your microwave links, but logically it is the same.  At the central site we terminate that service on a L3 switch and have the MX in VPN concentrator mode connected to the same L3 switch only via WAN1.  The Inet Firewall then has the second internet connection (5G modem in your case) connected as backup.

Thank you, I'll look more into the VPN concentrator mode.

Get notified when there are additional replies to this discussion.