MX64 Conenction Issues

NW
New here

MX64 Conenction Issues

Hi guys, 

We are using a MX64 to provide our clients with Client VPN on the main internet port and then on the other internet port we are providing a guest network. 

 

This works fine at the customer and we have it set so the internal IP address of the MX64 is set as the default gateway on the servers. Everything works internally and externally. 

 

Recently the client has had an additional class opened at another site and the local authority who provide the connections have created a VPN connection that goes from the main site to the second site. When we have the client vpn up and running neither site are able to talk to each other. All they can do is ping the default gateway of each remote site. So site A can ping site B's default gateway and site B can ping site A's default gatway. From site B we are able to ping the MX64 internet ports IP address and thats it as soon as you guy higher we are unable to ping anything. I have been on the phone with support and they have told me nothing is being blocked on the Meraki. The MX is set up in Routed Mode. All firewall rules are off all outbound and inbound rules are all set to Allow and Any.

 

Any help would be great. 

2 Replies 2
KarstenI
Kind of a big deal
Kind of a big deal

I'm not really sure if I understand you right. You are saying:

When a Client-VPN is connected, then A and B can not reach each other. Does that mean if there is no Client VPN connected that the reachability is given? That would truly not make any sense ...

Or are you talking about reachability from the Client-VPN to the remote site? If the VPN between A and B is not Meraki AutoVPN, then this would be a restriction of the platform.

PhilipDAth
Kind of a big deal
Kind of a big deal

What type of VPN is connecting the two sites, and what devices are providing this VPN connection?

 

The remote site needs a route back to your site for your client VPN pool.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels