Client VPN limitation?

EITnetworks
Conversationalist

Client VPN limitation?

I have a MX75 that my users connect to using the client VPN. Never had an issue until last week. We are in Florida and many employees were temporarily displaced because of hurricane Milton. I had 4 employees all in the same home trying to connect to the VPN from their Windows laptops. The first 2 were able to connect while the other 2 were getting denied. Is there a limitation to how many client VPN's can connect from the same WAN IP? I only have 30 remote users, so I'm well under the VPN tunnel limitations. Anyone have an idea on why it wouldn't allow more than 2 client VPN connections?

2 Replies 2
PhilipDAth
Kind of a big deal
Kind of a big deal

This is not a limitation on the MX side.

 

This most frequently occurs due to either bugs or limitations in the router the users are sitting behind.  You could try upgrading the firmware on that device.

 

The best solution is to buy Cisco AnyConnect licences, and change over to using that.  It is more reliable and superiod in every way.

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance

 

AnyConnect licencing is honesty based, so you could give it a little test before committing the money.  It's realtively cheap though.

Brash
Kind of a big deal
Kind of a big deal

This is a known limitation of most (if not all) L2TP implementations.

You can typically only have 1 connection from a single public IP address (I've seen times where 2 have connected but actually connecting to internal applications had big issues).

 

As @PhilipDAth mentioned, you would need to use a different VPN technology. Cisco Anyconnect doesn't have this issue. Similarly, SSL VPN's or IKEv2 VPN's also don't have the issue.

 

Re: How many concurrent client VPN connections from 1 public ip? - The Meraki Community

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels