- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
L3 core and MX AutoVPN question
Hi All,
Running into a scenario where we have an L3 9500 core with SVIs (Gateway) for user subnets for a given site. MX firewalls are going to replace a different vender firewall for outbound internet access and AutoVPN will be used to connect the sites together.
I suspect if a subnet's default gateway lives on the 9500 core (l3 core) then it cannot participate in AutoVPN if MX is intended to be at the Internet Edge in routed mode. Can you confirm my logic is true/false? Will the SVIs need to be migrated to the MX?
Has anyone run into this?
Solved! Go to solution.
- Labels:
-
Auto VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can set a static route from the mx to the 9500. And the static route you can advertise in the autovpn
https://documentation.meraki.com/MX/Networks_and_Routing/MX_Addressing_and_VLANs#Static_routes
In VPN: Determines whether the MX advertises this static route to site-to-site VPN peers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can set a static route from the mx to the 9500. And the static route you can advertise in the autovpn
https://documentation.meraki.com/MX/Networks_and_Routing/MX_Addressing_and_VLANs#Static_routes
In VPN: Determines whether the MX advertises this static route to site-to-site VPN peers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
+1 with @ww
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Very good. Thank you for the link and the explanation. Cheers!
