Cisco EZ VPN alternative

Solved
kima25
Here to help

Cisco EZ VPN alternative

Hello,

 

I'm working on a project for a customer who has ASA firewalls at headquarters and remote sites with Internet access. 
The sites don't have a fixed public IP address can't set up IPsec with the firewalls at headquarters, so he's using the proprietary Cisco EZ VPN protocol (which is enf of life). 
my question is, if we propose a sdwan meraki solution, can we set up VPN tunnels even if we don't have fixed IP addresses on the remote sites?
 
 
thanks for your help 
1 Accepted Solution
FabianSchleef
Here to help

Hi Kima,

 

all MX devices will connect to the Meraki Auto VPN Registry with their current Public IP address. The Registry will provide these information to all MXs in your organization also connecting to it. So yes, dynamic WAN IP addresses are not an issue.

 

https://documentation.meraki.com/MX/Site-to-site_VPN/Meraki_Auto_VPN_-_Configuration_and_Troubleshoo...

View solution in original post

4 Replies 4
alemabrahao
Kind of a big deal
Kind of a big deal

When you are talking about fixed IP, are you talking about public IP alright?

 

Yes you can.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
kima25
Here to help

hello @alemabrahao : yes right 

FabianSchleef
Here to help

Hi Kima,

 

all MX devices will connect to the Meraki Auto VPN Registry with their current Public IP address. The Registry will provide these information to all MXs in your organization also connecting to it. So yes, dynamic WAN IP addresses are not an issue.

 

https://documentation.meraki.com/MX/Site-to-site_VPN/Meraki_Auto_VPN_-_Configuration_and_Troubleshoo...

kima25
Here to help

Hi @FabianSchleef ,  thank you for your response 🙂 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels