Azure S2S VPN

Solved
charles07
Getting noticed

Azure S2S VPN

Does Meraki MX supports Azure VPN with Basic SKU VPN Gateway.

 

Azure VPN Gateway configuration has an option to select SKU - https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways

 

From my observation if Basic is selected, Meraki would not form S2S tunnel.

If any SKU above Basic is selected, Meraki MX forms S2S tunnel successfully.

 

Any idea why Meraki MX is not able to form S2S tunnel with Azure for Basic SKU.

 

Azure VPN SKU mentioned here - https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways under "Gateway SKUs by tunnel, connection, and throughput"

1 Accepted Solution
charles07
Getting noticed

After hours of troubleshooting we identified the issue.

Meraki MX does not form VPN with Azure Basic Gateway SKU

Azure VPN gateway SKU should be VPNGW1 or higher

 

Our Azure SKU was Basic. Somehow Meraki was not forming tunnel with it.

 

https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings

View solution in original post

3 Replies 3
PhilipDAth
Kind of a big deal
Kind of a big deal

I think it should work.  Just make sure you configure it as a policy-based VPN, and note that you can only have one policy-based VPN.

 

Another option (which we have used lots) is to deploy an Ubuntu machine running StrongSwan and terminate the VPN on that.

https://www.ifm.net.nz/cookbooks/meraki-vpn-to-azure.html 

charles07
Getting noticed

After hours of troubleshooting we identified the issue.

Meraki MX does not form VPN with Azure Basic Gateway SKU

Azure VPN gateway SKU should be VPNGW1 or higher

 

Our Azure SKU was Basic. Somehow Meraki was not forming tunnel with it.

 

https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings

Hello.

 

Just to mention that on my side I have a lot of customers with a dr site in Azure and all of them are with the Basic SKU. I haven't had a problem with the MX68, 84, 85 and 100.

 

I think it should work.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels