Connecting an MX84 on WAN1 to a Private IP Address

Solved
mcoomber
Getting noticed

Connecting an MX84 on WAN1 to a Private IP Address

Hi all,

I'm trying to do something I'm not sure will work.

 

I've got an Internet service from a home network that issues IP addresses on the 192.168.x.x. 

I have an MX84 SDWAN connected to a different service provider with a public static IP Address. 

The Public Static IP address is configured on WAN2 on the SDWAN. All traffic currently flows through WAN2. 

Now I want to connect the home network to the SDWAN on WAN1 and then configure an SSID on the APs to have all Android, iPhones, and other OS transfer traffic through WAN1. 

 

Is this possible? 

 

When I connect the home network to WAN1 and configure it to get its IP from the home network, or when I configure it with a static IP, I get a status FAILED. 

 

1 Accepted Solution
Mloraditch
Kind of a big deal

In theory this should work, but it sounds like something is blocking the connection.

You can check the upstream device against the Meraki firewall rules as documented here: https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Clo...

Once you get that resolved, you can use Flow preferences to send traffic from the specific SSID out that WAN: https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Load_Balancing_and_Flow_Preferen...
The traffic will need to be on a unique subnet.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.

View solution in original post

8 Replies 8
Mloraditch
Kind of a big deal

In theory this should work, but it sounds like something is blocking the connection.

You can check the upstream device against the Meraki firewall rules as documented here: https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Clo...

Once you get that resolved, you can use Flow preferences to send traffic from the specific SSID out that WAN: https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Load_Balancing_and_Flow_Preferen...
The traffic will need to be on a unique subnet.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
mcoomber
Getting noticed

Thanks. I've got WAN1 to become active when I used dynamic IP instead of Static.

The IP on WAN1 uplink is 192.168.x.x.

Just one more question. 

I've configured the SSID to be OPEN while I do the test and the flow preference to allow traffic on 10.0.0.0/8 since I have configured the SSID to use Meraki AP assigned (NAT mode). 

It shows connected on the client devices but no Internet.

 

alemabrahao
Kind of a big deal

I think it won't work for NAT mode, since the traffic that goes out to the internet is from the AP's IP.

You will need to change to bridge mode.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal

Check it out.

 

https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/NAT_Mode_with_Meraki_DHCP

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
mcoomber
Getting noticed

I just realised that the devices are not transmitting out that WAN. I created the subnet and assigned the meraki to issue out DHCP to that subnet. I then configured the SSID to use the VLAN ID tag associated with the subnet.  When I try to connect I get the message: Couldn't get IP address

alemabrahao
Kind of a big deal

I think it would be interesting to open a new discussion since this is a different issue.

Please provide more information and screenshots of the configurations you made and, if possible, a topology in the new discussion.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
mcoomber
Getting noticed

I have opened a new discussion. Thanks for the advice. 

 

alemabrahao
Kind of a big deal

Yes, it is.

 

https://documentation.meraki.com/MX/Other_Topics/Static_IP_Assignment

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.