Clinet VPN question

athan1234
A model citizen

Clinet VPN question

Hi,

I have a question regarding the client VPN. An external provider wants to access the central VoIP system.

My initial idea was to check where the network is configured in the voice VLAN to assign the IP address, but it doesn’t

My question is: what IP should I assign in this case?

 

 

athan1234_0-1733836488850.png

 

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

Any private address that is not in use on your network, when configuring the VPN client, will automatically be added as a route to the MX routing table.

 

Configuring MX for Client VPN

To enable client VPN, choose Enabled from the Client VPN server drop-down menu on the Security & SD-WAN > Configure > Client VPN page. The following client VPN options can be configured:

  • Hostname: This is the hostname of the MX that client VPN users will use to connect
    • This hostname is a Dynamic DNS (DDNS) host record correlating to the public IP address of the MX
    • For more information on managing the hostname, see Dynamic DNS (DDNS)
  • Client VPN subnet: The subnet that will be used for client VPN connections
    • This should be a private subnet that is not in use anywhere else in the network
    • The MX will be the default gateway on this subnet and will route traffic to and from this subnet
    • The MX utilizes LCP (Link Control Protocol) to assign IPs to clients, thus DHCP and Static Assignment are not supported

 

https://documentation.meraki.com/MX/Client_VPN/Client_VPN_Overview

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
athan1234
A model citizen

@alemabrahao  thanks for your reply

So, if I understand this correctly, the Client VPN subnet is just the IP range that will be assigned to a client when they connect through this VPN. Is that correct?

alemabrahao
Kind of a big deal
Kind of a big deal

Yes, correct.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels