Hi everyone,
I'm working on putting our HQ on Meraki. We have a few things happening in our topology so I will explain it here, so it could be long but I will try to keep it short.
We have about 90 remote branches, many of which have an MX and are VPNed into our HQ with our MX250 in our HQ (configured on HQ as Hub, all others as spokes). We also have around 5 MPLS locations (because of still active contracts) and I have the MPLS to our HQ connected to our MX250 (so all the MPLS networks are sent over the provider network and terminates on our MX250 to be routed where ever needed). We also have a NG-Firewall connected to the MX250 and some static routes on the MX250 for our server network, that way all spokes have a route to the HQ MX250 for the servers and the HQ MX250 just sends it on to the firewall.
All this being said, we have 2 major points that has non-Meraki L3 devices: one being the MPLS connection, the other being the firewall and the server network. So we have clients appearing in the MX250 network from these other networks and the Meraki Network is configured for client tracking with IP Addresses, because that's what Meraki docs say to do in this situation. Until recently, our HQ Client network was not in Meraki, but also behind the firewall like the server network. We recently moved all the HQ L2 devices onto the MX250 (as the default router), so now our entire end-user client network is on Meraki, and to reach the server network they have to first go through the MX250 then is routed to the firewall, which currently works well.
I'm now in the process of changing out our old access points with Meraki as well. When I tried to add an MR to our HQ network, it gave me an error because of clients being tracked with IP addresses. So my question is: what do I need to do in this situation? Should I change the HQ MX250 client tracking to MAC, or will that break our MPLS and server network? Or should I just create a new dashboard network for our access points with client mac tracking? Would that even work with the default router being on another dashboard network?