Good Day
Can anyone help me please ... I configure a VPN CLIENTE on a MERAKI MX84, I connect with no problem to the vpn, but i can´t access to the offiece Internal LAN. did i miss something else to configure?
What's your home subnet vs. the subnet at the office? I.E. is your house 192.168.1.0/24 and is the office the same?
Do you have ACLs in your network that need to have the VPN subnet added to them?
This is mi home subnet 192.168.1.0/24, mi office subnet are many for example 192.168.11.0/24
192.168.10.0
192.168.8.0
... etc...
I don’t have ACL, but the meraki is conected to a Juniper Switch, the juniper switch works like a core
Can you ping devices on the office LAN by IP address?
If you are trying to access device by name, have you got something to do name resolution like an Active Directory server? If you have, can you ping the active directory server by IP address? Can you ping it by name?
Also note Windows firewall often blocks ping. So you can get cases where you can't ping a host but you can RDP to it.
I cannot ping by name or by address to any subnet or domain controller
What OS are you using for the client VPN?
On mac and windows
Are the machines you are trying to access in the office using the MX as their default gateway, or is their something else doing layer 3 routing?
Each subnet has there on gateway but all of them point to the meraki gateway , for example
IP ADDRESS: 192.168.13.0/24
GATEWAY: 192.168.13.35
MERAKI NEXT HOP IP GATEWAY: 192.168.200.1
I'd tackle the problem in phases.
Start simple. My first step after establishing the tunnel would be to ping the IP-address of your MX. I'd also try to make sure that it actually is the MX responding by accessing the local web page.
Once that works, work your way from there. Try pinging the Juniper. If it's not working, setup port mirroring and a packet capture on the interface of the Juniper and have a look at what's going on. If nothing arrives, then there's something wrong with the routing on your MX. If something arrives, but no reponse is sent, something is wrong in the Juniper.
Then move to a device in one of the subnets of the Juniper and repeat the process.
Things to keep in mind: