MG21 and Non Meraki Site 2 Site

Solved
Patrik73
Getting noticed

MG21 and Non Meraki Site 2 Site

I have an MX65 with an MG21 connected to WAN-port.
The SIM-card is unlocked from NAT and has a static public IP.
 
I try to setup an non meraki site 2 site to our cloud.
Of course that fails.
Guess I need to add some port forwarding on my MG21.
Now I have added these.
MG21-port-forward.png
 
My MX has the following address from MG21.
MG21-mx.png
 
My IP on MG21 is
Address and public IP are the same.
MG21-publicip.png
My MX Site 2 Site is configured with.
MG21-vpn-settings.png
We are using VmWare Edge Gateway on the other side.
And these settings work when we only have an Meraki without MG21 onprem.
 
The logs in Meraki says.
MG21-log.png
 
Would really appreciate some pointers here.
 
EDIT1:
Did capture on Internet and the only thing I see from my remote VPN-site is this.
MG21-wireshark.png
1 Accepted Solution
Patrik73
Getting noticed

Meraki helped me with this one.


I needed to set the Peer ID as the MX IP-address that it got from the MG.
For example 172.31.128.4.
And the Peer Endpoint as the MG21 public IP-address.

Portforward on the MG21 to the MX.

Port 500 UDP and Port 4500 UDP.

Then it worked like a charm. 🙂

View solution in original post

2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

Take a look at these recommendations.

 

alemabrahao_0-1665776316064.png

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Patrik73
Getting noticed

Meraki helped me with this one.


I needed to set the Peer ID as the MX IP-address that it got from the MG.
For example 172.31.128.4.
And the Peer Endpoint as the MG21 public IP-address.

Portforward on the MG21 to the MX.

Port 500 UDP and Port 4500 UDP.

Then it worked like a charm. 🙂

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels