MX Site to Site VPN Tunnel Count

Solved
Jonathan_Galvez
Here to help

MX Site to Site VPN Tunnel Count

 

Hi team,

I am checking the sizing principles of MX and I want to ask what "Maximum Site to Site VPN Tunnel Count" means. Does it refer directly to the site-to-site peers? Is it only important for the MX in hub mode?

 

I am referring to this information:

https://documentation.meraki.com/MX/MX_Sizing_Information/MX_Sizing_Principles => MX-Series

 

Many thanks and regards,

 

Jonathan

 

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

The “Maximum Site to Site VPN Tunnel Count” refers to the maximum number of VPN tunnels that can be established between different sites.

 

meraki.cisco.com/product-collateral/mx-sizing-guide/?file&ref=1a0sAbk

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

6 Replies 6
alemabrahao
Kind of a big deal
Kind of a big deal

The “Maximum Site to Site VPN Tunnel Count” refers to the maximum number of VPN tunnels that can be established between different sites.

 

meraki.cisco.com/product-collateral/mx-sizing-guide/?file&ref=1a0sAbk

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Hi,

thanks! That is what I thought, that means a site-to-site peer is also a VPN tunnel between sites.

 

Jonathan_Galvez
Here to help

It is still not clear to me what a VPN Tunnel is on the Meraki Dashboard.
If I have a connection between 3 sites, 1 Hub, and 2 Spokes:
On the Hub, I see 2 site-to-site peers and 16 VPN Participants. How many tunnels am I using, 2 or 16?

It's all the tunnels you have between HUB and Spokes, if you go to Security & SD-WAN > Monitor VPN Status, you can see the number of S2S VPN peers.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Two, the 16 VPN participants likely represent the individual subnets across all 3 of your sites that are being advertised over the VPN.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

@Jonathan_Galvez  Here are some visual examples of how to calculate the tunnels

 

https://docs.google.com/presentation/d/1S0eX10RrKAWqW229tw7Q2YUUAaNUzskbvM6uYrLQ2zk/edit?usp=sharing

Ryan / Meraki Solutions Engineer

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.