vMX Deployment in Azure

Comes here often

vMX Deployment in Azure

Coming across an issue where I cannot traverse network traffic initiated from Azure VM after vMX deployment.


Current vMeraki Config:

Mode: Routed

Client tracking: IP Address

Subnet VLAN-Management - next hop


Static route "Azure Servers": next hop


I have the route table configured in Azure pointing branch office traffic to virtual appliance of with my Azure server subnet associated to the route table.


After testing and configuring my Azure environment, from my branch offices I can reach my Azure resources perfectly fine (ICMP, RDP, Etc.) however, if I am initiating anything from the resources (virtual machine) in Azure to my branch office everything fails. From the vMX stand point I can get across the auto vpn and ping resources in branch offices.


For example, my MX is and my azure resources are on My Azure VM can communicate to the vMX just to nothing over the tunnel. I have the vNets peered and have allowed the two subnets over the AutoVPN.  Am I missing a route?

4 Replies 4
Kind of a big deal
Kind of a big deal

Have you allowed communication inside the azure firewall?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
A model citizen

When vMX (Virtual MX) is in Routed Mode (Limited NAT mode), there is no reachability from the Azure side to the branch office side.
This behavior is similar to a typical Router or Firewall, where communication from the WAN (Internet/Untrust) to the LAN (Trust) is discarded.
Please consider using Passthrough or VPN Concentrator Mode.


[Related Documents]
vMX NAT Mode Use Cases and FAQ - Cisco Meraki


vMX Setup Guide for Microsoft Azure - Cisco Meraki


That sounds hard to believe.  So you are saying that traffic that is initiated on the Azure side can't be routed to a VMX in NAT mode and over an AutoVPN tunnel?

That would make this mode terrible.

Meraki Employee
Meraki Employee

@nlatta42 What was the resolution? I don't see anything in the case other than you closed it.

Get notified when there are additional replies to this discussion.