- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Full or partial site to site tunnel with non Meraki VPN
I am trying to create a tunnel between a Meraki MX84 and a Cisco ASA 5510 which contains 3 different subnets, e.g a 10.0.0.0, 192.168.1.0 and 192.168.2.0. The tunnel seems to come up fine but only the 10 network actually works.
Can anyone think of something i might have missed? Or something thats weird in the way Meraki Deals with multiple subnet VPNs that i may have missed?
Thanks
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I worked it out. I had missed a NAT exemption rule on the ASA.
Thanks for the help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the settings for the VPN on the MX84, under the section VPN settings/Local networks, are the 192.168.1.0 and 192.168.2.0 networks listed?
I've just setup something similar but to a ASA 5525 and only with 1 subnet. I'd expect any other subnets to therefore appear under the above VPN settings/local networks section and give you the option to Use VPN or not.
rgds
Gary
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the reply,
Sorry i should have said that the subnets are all at the ASA end. The Meraki just has a single subnet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what does a tracert show from ASA side 192.168.x.0 to the MX84 side?
Is the ASA side set to route those subnets over vpn?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I worked it out. I had missed a NAT exemption rule on the ASA.
Thanks for the help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
great stuff - thanks for letting us know the outcome 🙂
Gary
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any pointers?
