Hi @AndreasE,
Hoping I can help clarify a few things and maybe improve our documentation a bit while we're at it.
- Site-to-site VPN cannot be enabled for a security appliance template unless VLANs are enabled, and at least one VLAN emits unique subnets.
- By default cloning templates sets VPN to off to prevent subnet overlap within the Organisation.
- Config sync doesn't work for "network tags" or "Template networks" (containing an MX appliance and a MS switch)
1. The "VLANs enabled" bit is mentioned in the "IP Address Range Allocations" section, as @PhilipDAth pointed out, but I agree with you that the "emits unique subnets" bit could be a bit more clear.
2. This is not mentioned, and I agree that it should be.
I updated this section of the documentation with a couple notes to make these requirements a bit more clear.
3. As @PhilipDAth mentioned, the inability to clone combined networks is currently a shortcoming of the config sync feature. I can't personally speak much to our plans to address this, but we're aware that it is an issue.
1. "known issues": they never tell you, but just keep it under the blanket
2. software bugs: no bug bounty program, instead you get silly reply questions about settings they should better know about than we do (why are they asking for a device ref when they never look into the device whilst working on a case?)
3. really bad or aged documentation on the web
4. instead of an error message or at least a warning, the dashboard falls back into a default setting and doesn't tell you about the risks
1. It's not our intent to hide known issues, it's just difficult to always ensure that we're presenting them in a way that is helpful. Our support engineers use the same documentation site that our users do and help keep it up-to-date, so if it's not recorded, it is almost certainly not an intentional omission. I appreciate feedback like this when you notice we're missing something.
3. I'm personally working on cleaning up as much as we can. I agree that some items are a bit dated and deserve some attention. If something stands out to you as particularly misleading or inaccurate, I'll take a look if you let me know.
I realize that doesn't address everything you were concerned about, but hopefully that helps a bit with the things I'm able to speak to.
Thanks for the feedback!
Cameron Moody | Product Manager, Cisco Meraki