Hello everyone, this is my first inquiry here. I am having trouble setting up a management VLan on one of our sites. We have Meraki appliances on all our sites (Site A = MX100, Site B = MX80) connected via vpn in hub-mode. The appliance on site A is in single Lan mode (flat network on that site, no static routes into any subnets), and Site B is in Vlan mode. The switch interfaces are currently still in Vlan 1. I have created a management Vlan on Site B (Vlan 5) on the appliance and on the Switches - the switches also have ip interfaces on that vlan). Vlan 5 is also enabled on the VPN. Locally on site B I can access those switch interfaces in Vlan 5. However, I cannot access them remotely from site A.
From Site A (MX100 single Lan)
- I can ping the Vlan 5 interface on the Site B appliance
- I cannot ping or access the switch interfaces in Vlan 5
From Site B (MX80 vlan mode)
- I can access the switch interfaces in Vlan 5
- I can ping the vlan 5 interface on the appliance
- I can even ping my computer at Site A from which I intend to manage the Switches. So it works that way, but not from My computer to the switches at the remote site.
We have few and basic firewall rules at both sites. The traffic should not be blocked. Just in case I added "allow any" rules on both sites but no success - but then, I also know that firewall rules don't apply to vpn.
There are no blocking rules of any kind in the site to site vpn settings.
What am i missing? Any pointers are apreciated!