Client VPN software for L2TP over IPSec

OmAr7
Here to help

Client VPN software for L2TP over IPSec

Hi there,

 

I manage more than 100 active Meraki networks. Recently, I had a discussion with some cybersecurity specialists, and they asked if there is a good client L2TP/IPSec VPN software to use with our MX/Z appliances. I used to install Smart Client VPN, but I would like to know your opinion in this community. This client should primarily work on mobile devices (BYOD).

 

Thanks in advance

5 Replies 5
alemabrahao
Kind of a big deal
Kind of a big deal

For mobile you can use the device's native client.

 

https://documentation.meraki.com/MX/Client_VPN/Client_VPN_OS_Configuration

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal
Kind of a big deal

Smart Client is also supported on mobile devices.

 

https://www.draytek.com/products/smart-vpn-client/

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
OmAr7
Here to help

Thank you so much!

 

PhilipDAth
Kind of a big deal
Kind of a big deal

Going sideways, have you considered upgrading to AnyConnect and using SAML to something like Entra ID?

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance/AnyConnect_Azure_AD_SA...

 

It offers so many more security options through things like Entra conditional access.

Brash
Kind of a big deal
Kind of a big deal

One thing to note is that most vendors are phasing out L2TP VPN.

AnyConnect is a far better and more secure experience.

 

Additionally, Android no longer natively supports L2TP VPN since Android version 12.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels