MX Placement with Cisco Firewall

Solved
Wooten
Conversationalist

MX Placement with Cisco Firewall

 

I have a pair of MX450 Hubs configured in routed mode, while running in single VLAN addressing mode.  They have connectivity back to our L3 Cores.  This has worked well with a couple test branch sites with only MX67s.

 

Now, I am planning to implement MX85's at approximately 20 branch sites.  However, although the MX has a firewall, security requires that each branch site retain the existing Cisco firewall.  While most sites have fiber with dual ISPs with /28 or /29 IP ranges, some sites have a primary ISP with a DSL or LTE backup.

 

Each site will have an L3 core.  The Meraki will be utilized only for SD-WAN/AutoVPN/spoke connectivity back to HQ.  Internet for IOT/Guest will remain local and dump to the local ISP.

 

My primary questions surround where to logically place the Meraki?  Should it be behind the firewall or parallel with the firewall?  Is it possible to have an MX as a spoke in concentrator mode?  Or would it function better in routed mode?

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Wooten 

 

Best practice would be to place the MXs (concentrators) behind your Corp firewall. They should not be at your internet edge.

 

https://documentation.meraki.com/日本語/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Des...

 

if each site already has a L3 core I would go for Passthrough mode.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

1 Reply 1
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Wooten 

 

Best practice would be to place the MXs (concentrators) behind your Corp firewall. They should not be at your internet edge.

 

https://documentation.meraki.com/日本語/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Des...

 

if each site already has a L3 core I would go for Passthrough mode.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels