Hoping for some help in setting up an MX in an MPLS environment.
For now, there is only an MX at Head Office while this is trialled. If all goes well, we would add them everywhere but I am having trouble getting it going.
I am after DHCP, Client VPN and some content filtering features so I have to have it in "Routing Mode", not Passthrough. We also have 2 VLANs (data and voice) that I need on the LAN side.
Reading some other posts I am reluctant to try the Beta No Nat feature as it seems there are some minor issues?
I found and read through this article: https://documentation.meraki.com/MX/Deployment_Guides/MPLS_Failover_to_Meraki_Auto_VPN
but can't seem to get this working.
From the diagram, it seems the MPLS connection has an interconnect range of 192.168.128.0/24 and an actually used range (on the LAN) of 10.15.10.0/24.
I have tried a similar approach but with a /28 range on the interconnect.
Due to having 2 ranges, the MX would have to have VLAN ID's assigned to each, I have chosen VLAN1 for the LAN and VLAN5 for the MPLS range. The MPLS Cisco router also has VLAN 5 configured.
Port 1 on the LAN of the Meraki is set to Access Native VLAN5 however the 2 devices can't see each other.
i'm also not sure how I can add routes to send everything out the MPLS link. There is already a 0.0.0.0/0 route in for the WAN which can't be removed.
Trying to add 2x /1 ranges instead fails as well since they then overlap my 192.168 LAN range.
Am I overthinking this? I really just want the DHCP etc. control on the MX and then a WAN of the MPLS. Long term though we will possible add a local internet break out but that will be a future issue.
@General-Zod is right.
Meraki is made for and environment where the Internet plugs directly into the MX and it is your firewall.
In your case, you have a provider giving you a firewall and Internet sevice via the MPLS cloud.
You may be better trialling this at home, as your network will need to be chanegd completely. You may well not end up using MPLS at all.
This is a shame as I wanted to take control of some of the things we rely on the Telco for such as DHCP (which is on the router at some sites).
We also want some Client Traffic visibility.
I'm guessing the No Nat though in the end would do what we want?
I would use pass through mode if you are not ready to make the big jump.
Having a no NAT function would certainly open up more possibilities, which is why I’m stinging for the gold release with this feature.
i have many use cases for this feature but have had to re-engineer accordingly with alternate products.
hopefully we don’t have to wait too long
cheers