MX and Zscaler

Aamir
Here to help

MX and Zscaler

Hi,

 

I have a customer in process of deploying MX and Zscaler. The MX will have dual internet links with one IPSEC tunnel to Zscaler Node (ZEN's). My understanding is the IPSEC tunnel will be formed via the primary link connected to MX. What happens if the primary link goes down, will MX automatically create IPSEC tunnel to Zscaler Node (ZEN's) via the secondary internet link?

2 Replies 2
PhilipDAth
Kind of a big deal
Kind of a big deal

These are the instructions for configuring Zscaler.

https://documentation.meraki.com/MX/Security_Service_Edge_Integrations/Zscaler_Internet_Access_(ZIA)... 

 

Correct, the MX will try to build the VPN from the backup connection.  You'll want to use the "UserFQDN" approach for authenticating the VPN to make this work.

Aamir
Here to help

thanks do we know how much time it would take it to make IPSEC tunnel via the backup internet link once primary link goes down?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels