- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Advertise a static route through a third party VPN
My Org has about 24 different networks for our various sites all connected hub and spoke to our main data center. We have a vendor hosting a service that needs to be accessed via third party VPN but who is constrained by the number of end points they are able/willing to add to their VPN solution. Is it possible to set up a third party VPN to them on the main data center MX appliance and advertise that route to all of the sites in my org. I currently have the third party tunnel running at the data center, and the connection works fine from that site. I can't figure out if there is a way to allow other sites to connect through that tunnel.
- Labels:
-
3rd Party VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you configure a non-Meraki VPN, an entry will be created in the routing table called IPSec Peer. Assuming you configure it in the HUB the route will be announced to all Spokes automatically.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am not seeing a subnet for the destination that I can enable for auto-vpn and nothing in the routing table is configurable.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Take a look on route table after configure S2S VPN.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where do you then configure that to be advertised to the spokes? I don't see that anywhere.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Right, but where do you configure that to be shared to other sites? It isn't showing up on any of my other appliances.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not sure but I was thinking maybe you have to create an S2S VPN with each site.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, that would just mean the vendor would have to create an endpoint for each of my sites, and they aren't willing to do that. They claim they are unable to do it but haven't given me a reason why.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I found this information, but I have never tested It:
https://help.cloudi-fi.com/en/articles/3177550-cisco-meraki-mx-routing-tunnels-deployment
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, unfortunately that is just how to make a third party VPN tunnel on one appliance. I'm just going to open a case with support and see what they say.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
but in my understanding, in that part specifically, if you want the Spokes to reach that network you need to set the HUB as the default route. I'm going to test this here in my lab.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
just give me a few minutes.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need a tunnel from every mx. Or use another device at the lan side on hq to build the tunnel. And set a static route on hq mx to that device/subnet and advertise that route into vpn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@JayHylander I agree with @ww
Please, if this post was useful, leave your kudos and mark it as solved.
