Advertising Anyconnect client subnet to EBGP

Darren88a
Conversationalist

Advertising Anyconnect client subnet to EBGP

Setup, vMX in Azure running in one-armed conncentrator mode with AutoVPN to other sites.  Uplink to Azure DC via eBGP.  I have configured AnyConnect on the vMX which I am able to authenticate to but query is can I advertise the Anyconnect Client network to Azure?  The Anyconnect Network/subnet is currently not being received in Azure via BGP so Azure does not know how to route back therefore any servers host in Azure are not reachable.  Is there a way to advertise it dynamically or must you add a static in Azure pointing back to the vMX?

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

You should have to advertise the route on the SD-WAN.

 

 

alemabrahao_1-1720604715064.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Darren88a
Conversationalist

Thanks, I can advertise it on the SD-WAN, but will this allow it to be advertised via eBGP to Azure?  The BGP to Azure is built on the same vMX so thinking it may follow the same rules as local networks where these are not advertised to eBGP peers?

alemabrahao
Kind of a big deal
Kind of a big deal

I believe you will need to create a static route in this case, but I would open a support case instead.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels