MX-65 designate ports to not use auto VPN?

Solved
ry8s
Conversationalist

MX-65 designate ports to not use auto VPN?

Hello,

 

We have an MX-65 that we want site-to-site VPN only for a few ports.  When you configure site-to-site VPN, is that all or nothing?

 

Thank you

1 Accepted Solution
ww
Kind of a big deal
Kind of a big deal

You can create another vlan. Dont make it part of the vpn. Assign that vlan as access vlan to the ports you dont want to use vpn.

View solution in original post

6 Replies 6
alemabrahao
Kind of a big deal
Kind of a big deal

You can create a L3 firewall rules on VPN.

 

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Firewall_Rule_Behavior

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ww
Kind of a big deal
Kind of a big deal

You can create another vlan. Dont make it part of the vpn. Assign that vlan as access vlan to the ports you dont want to use vpn.

ry8s
Conversationalist

Something like this is what I assumed we could do - thanks!

alemabrahao
Kind of a big deal
Kind of a big deal

So you are talking about physical ports, I thought that you were talking about logical ports like (80, 443, etc).

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ry8s
Conversationalist

Sorry I should have clarified, yes - physical ports.

ry8s
Conversationalist

Follow-up question if you happen to know, if we have a 250mbps connection at the main office, and the MX65 can handle a VPN connection of 100mbps, I assume even if we don't have the VPN on certain physical ports, the base connection is still at that 100mbps?  Would ports not on the VPN get that 250mbps speed?

We're just trying to map out what's possible right now

Thanks in advance!

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels