Licensing

Solved
Eugenios
Conversationalist

Licensing

Hi team,

 

IHAC with an MX and advanced license at their HQ site

On a remote site they need a new one

The traffic will go through HQ, so I only need s2s

Do I need to purchase the second unity with, say an Enterprise License?

 

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Eugenios 

 

You will require an Advanced Security licence for the MX unit at your second site as you can't mix Enterprise and Advanced licences within a single Organisation.

 

You could create a secondary Org and place the second MX in that and run an Enterprise licence but you'll have to manually create the s2s VPN.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

5 Replies 5
Inderdeep
Kind of a big deal
Kind of a big deal

Have a look on the license FAQ

https://documentation.meraki.com/General_Administration/Licensing/Meraki_MX_Security_and_SD-WAN_Lice...

I think the basic license is enterprise license and you should need it. Meraki will not work without license.

 

 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Eugenios 

 

You will require an Advanced Security licence for the MX unit at your second site as you can't mix Enterprise and Advanced licences within a single Organisation.

 

You could create a secondary Org and place the second MX in that and run an Enterprise licence but you'll have to manually create the s2s VPN.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Eugenios
Conversationalist

Thank you - good point on the manually configuring the s2s VPN

DarrenOC
Kind of a big deal
Kind of a big deal

cost vs functionality/administration overhead. 😁

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
GreenMan
Meraki Employee
Meraki Employee

Secure traffic processing really happens on the local MX, where clients are connected - you will get limited protection, if you're relying on just the VPN Hub to (Advanced Security) process the traffic.   You most likely need Adv Sec for the Spoke.   This is one reason why we simplify everything to the same license level, per Org.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels