VMX-s setting a static ip address for the public ip? Change SKU from basic to standard on IP address

Gord719
Here to help

VMX-s setting a static ip address for the public ip? Change SKU from basic to standard on IP address

Microsoft suggested they are dropping the basic skus for public ip addresses. 

 

VMX-s devices deploy a public ip address with a basic sku. How do we upgrade this to standard sku? 

 

The resource group that the ip is deployed to wont let you change it. It throws a permissions error. 


Is it supported to create a new public ip address in azure in a completely different resource group and bind that back to the VMXNIC interface in azure? I would suspect you could 1. set a static ip address and 2, it would deploy a proper standard sku. 

 

What happens to all the existing vmx appliances deployed in azure when they drop those basic skus? 

 

Has anyone upgraded from a basic sku ip address to a standard sku and if so, how? What is the officially supported way?

 

An email from MS was released:

 

Says we have until Sept 2025 but mostly want to get a jump on this to upgrade all instances before that time. I am deploying a new VMX right now and cant seem to change anything about the basic sku.....even disassoicating the ip and upgrading and and trying to re-associate it back to the vmx interface generates a permssions error about the VMX resource group.

8 Replies 8
alemabrahao
Kind of a big deal
Kind of a big deal

Have you checked this article?

 

https://documentation.meraki.com/MX/MX_Installation_Guides/vMX_Setup_Guide_for_Microsoft_Azure#Befor...

 

I don't know if It can help.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
MyHomeNWLab
A model citizen

When deploying vMX in Azure, the SKU depends on the Availability Zone (AZ) setting.

 

* If AZ is set to None, the Public IP SKU is deployed as Basic. Client VPN works when SKU is Basic.
* If AZ is set to 1 - 3, the Public IP SKU is deployed as Standard. Client VPN does not work when SKU is Standard.

 

I know about it from the following topic.

 

https://community.meraki.com/t5/Security-SD-WAN/vMX-and-Client-VPN-on-Microsoft-Azure/m-p/103379

 

In addition, vMX (Azure) is a managed Resource Group and its settings cannot be changed.

MyHomeNWLab
A model citizen

Memo: Microsoft's official announcement about Public IP SKU

 

Upgrade to Standard SKU public IP addresses in Azure by 30 September 2025—Basic SKU will be retired | Azure updates | Microsoft Azure
https://azure.microsoft.com/en-us/updates/upgrade-to-standard-sku-public-ip-addresses-in-azure-by-30...

jimmyt234
Building a reputation

Did anyone ever sort this? It's just coming across my radar now and we have several deployments for customers that appear to be using the Basic Public IP SKU in Azure.

jimmyt234
Building a reputation

For anyone reading, I have been able to convert the public IP SKU from Basic to Standard by doing the following:

 

Turn off vMX virtual machine

Disassociate the public IP from the NIC

Set IP assignment type to static from dynamic (this step may or may not be required)

Do the upgrade from basic to standard by clicking the banner in Azure

Associate IP back to the NIC of the vMX

Turn on vMX

ygurra
Here to help

Did you encounter any problems with the establishment of VPNs (site-to-site or client VPN) when upgrading to Standard SKU ? 

We had some disconnections from our spokes which was not resolved until we reverted back to the BASIC SKU. 

jimmyt234
Building a reputation

Did not experienced this - have only done it on 1 vMX though...

Kobus78
Comes here often

I've done this over the weekend and followed exactly what you suggested on how to do it - caveat - Client VPN no longer works.

Get notified when there are additional replies to this discussion.