In site to site VPN detach hubs vpn tunnel

Solved
Hank_Huang
Comes here often

In site to site VPN detach hubs vpn tunnel

Hi Guys,

If I management MXs on same organization.
I need create site to site VPN between this MXs.
But VPN Group A and Group B did not create VPN tunnel.
The diagram like below.

Hank_Huang_1-1583826152591.png

 

 

In documentation is say "If the MX is configured as a Hub, it will build VPN tunnels to all other Hub MXs in the Auto VPN domain ".
Did it's possible, do not build VPN between hubs?

 

Thanks.

1 Accepted Solution
PhilipDAth
Kind of a big deal
Kind of a big deal

I believe a recent beta firmware has an option for this.  I think you have to open a support ticket to get this option.

 

Another easy option is to create VPN firewall rules to only allow what you want.

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Firewall_Rule_Behavior 

View solution in original post

3 Replies 3
PhilipDAth
Kind of a big deal
Kind of a big deal

I believe a recent beta firmware has an option for this.  I think you have to open a support ticket to get this option.

 

Another easy option is to create VPN firewall rules to only allow what you want.

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Firewall_Rule_Behavior 

I think VPN firewall isn't bester solution on this case.
This can't solve this problem when more spoke site use same subnet.


The best way is waiting Meraki release new feature.

>This can't solve this problem when more spoke site use same subnet.

 

If that is the actual issue it sounds like the networks should actually be separate orgs.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels