IPSec Peer not available when connecting via Client VPN

StarZen
Here to help

IPSec Peer not available when connecting via Client VPN

We have an IPSec peer connected to our MX

 

all is find when connected to the MX but when we connect to the MX via client VPN (laptops out of office etc) the IPSec peer network is not available

 

guessing this is some routing issue but not sure where to even look

 

any help greatly appreciated

 

Mike

 

 

 

3 Replies 3
Mloraditch
Kind of a big deal
Kind of a big deal

I do not believe you can access a third party VPN when connected via the Client VPN. 

The caveat here under IPSec VPNs, applies to clients as well: https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Networ...

You either need to remote into a device that client VPN can access or you could put the third party VPN on another device and use static routing from the MX to route to it, or you may be able to use BGP as noted at the link. Someone else may be able to confirm if that will work or not. I don't use it so am not certain.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
alemabrahao
Kind of a big deal
Kind of a big deal

It should work if you use BGP.

 

https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Site-t...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

At a minimum, you would need to ensure the client VPN subnet was included on both ends of the VPN to ensure it works.

 

But I like @alemabrahao BGP IPSec answer best.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels