Hi, were are deploying a Wireless solution for a nationwide restaurant chain customer in Spain. Around 600 sites.
We have from 2 to 4 Meraki APs at sites and we concentrate them all on a 2-unit Meraki MX600 cluster. Customer wireless guests are connected to our MPLS network and then we deliver their navigation traffic to BT Internet Service.
According to this deployment guide:
https://documentation.meraki.com/MX-Z/Deployment_Guides/Configuring_VPN_Concentrator_for_the_Data_Ce...
There are two possible options: VPN concentrator (one-armed internet1 port connection, lan port disconnected and no nat)
or NAT mode.
However, this other document:
https://documentation.meraki.com/MX-Z/Networks_and_Routing/Addressing_and_VLANs
says concentrator mode is deployed in passthru like a bridge between LAN (so it is used) and Internet ports.
So it seems to me that concentrator mode has 2 flavours. Am I right?
Can we deploy NAT model for AP's VPN concentrator, bridging between lan (from where traffic comes) and Internet1 ports? Internet1 addressing would be private for security purposes.
We have already applied this config in our lab and it seems to work fine for one AP site. I mean, both NAT model at MX600 side and
VPN tunnel to MX600 concentrator at AP side. Is this a supported topology from Meraki? I do not have this point clear even after reading your deployment guides.
We would also have to be sure it is appropiate in terms of scalability (specially in terms of max number of NAT entries on the MX600).
According to https://meraki.cisco.com/lib/pdf/meraki_whitepaper_mx_sizing_guide.pdf, this box would fit well as it supports 5000 VPN tunnels.
What would be nat session limit and nat timeout timer in this particular scenario?
Thanks for your support.
Regards.