Advertise a static route through a third party VPN

JayHylander
Just browsing

Advertise a static route through a third party VPN

My Org has about 24 different networks for our various sites all connected hub and spoke to our main data center.  We have a vendor hosting a service that needs to be accessed via third party VPN but who is constrained by the number of end points they are able/willing to add to their VPN solution.  Is it possible to set up a third party VPN to them on the main data center MX appliance and advertise that route to all of the sites in my org.  I currently have the third party tunnel running at the data center, and the connection works fine from that site. I can't figure out if there is a way to allow other sites to connect through that tunnel.

13 Replies 13
alemabrahao
Kind of a big deal
Kind of a big deal

When you configure a non-Meraki VPN, an entry will be created in the routing table called IPSec Peer. Assuming you configure it in the HUB the route will be announced to all Spokes automatically.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
JayHylander
Just browsing

I am not seeing a subnet for the destination that I can enable for auto-vpn and nothing in the routing table is configurable.

 

JayHylander_0-1668113352140.png

 

alemabrahao
Kind of a big deal
Kind of a big deal

Take a look on route table after configure S2S VPN.

 

alemabrahao_0-1668113624295.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
JayHylander
Just browsing

Where do you then configure that to be advertised to the spokes?  I don't see that anywhere.

JayHylander
Just browsing

Right, but where do you configure that to be shared to other sites?  It isn't showing up on any of my other appliances.

alemabrahao
Kind of a big deal
Kind of a big deal

I'm not sure but I was thinking maybe you have to create an S2S VPN with each site.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
JayHylander
Just browsing

No, that would just mean the vendor would have to create an endpoint for each of my sites, and they aren't willing to do that.  They claim they are unable to do it but haven't given me a reason why.

alemabrahao
Kind of a big deal
Kind of a big deal

I found this information, but I have never tested It:

 

alemabrahao_0-1668114881505.png

 

https://help.cloudi-fi.com/en/articles/3177550-cisco-meraki-mx-routing-tunnels-deployment

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
JayHylander
Just browsing

No, unfortunately that is just how to make a third party VPN tunnel on one appliance.  I'm just going to open a case with support and see what they say.

alemabrahao
Kind of a big deal
Kind of a big deal

but in my understanding, in that part specifically, if you want the Spokes to reach that network you need to set the HUB as the default route. I'm going to test this here in my lab.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal
Kind of a big deal

just give me a few minutes.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ww
Kind of a big deal
Kind of a big deal

You need a tunnel from every mx. Or use another device at the lan side on hq to build the tunnel. And set a static route on hq mx to that device/subnet and advertise that route into vpn

alemabrahao
Kind of a big deal
Kind of a big deal

@JayHylander I agree with @ww 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels