MX68 LAN static route or default route.

SOLVED
dhayes89
Comes here often

MX68 LAN static route or default route.

MX64 Hub not using static route 0.0.0.0/0 to send all traffic from spoke to internal network. The spoke tracert tool for a public IP address 8.8.8.8 , the hub recieves the traffic vie the vpn tunnel but sends the traffic to its WAN interface instead of using the static route for the internal network.

 

dhayes89_0-1621954858125.png

 

dhayes89_1-1621954932931.pngdhayes89_2-1621954970546.pngdhayes89_3-1621955029937.png

 Spoke tracert

dhayes89_4-1621955159345.png

 

1 ACCEPTED SOLUTION
ww
Kind of a big deal
Kind of a big deal

Only if you first select the default route at the hub. To participate  in vpn. Then the spokes learn that default route in the vpn

 

So if you select that static 0.0.0.0 route at the hub. Then set it, in vpn

View solution in original post

8 REPLIES 8
ww
Kind of a big deal
Kind of a big deal

Do you advertise the static default route at you hub into vpn?

 

If you do,

can you unselect the "Default route" checkbox at the spoke vpn settings.

 

 

 

 

dhayes89
Comes here often

No,the Spoke is using the HUB as default route.  The traffic makes it to the HUB.

dhayes89_0-1621956600699.png

 

ww
Kind of a big deal
Kind of a big deal

So if you do select to select the  static default to use vpn and remove the checkbox it should work

dhayes89
Comes here often

Are you saying un-select the Default route for site to site VPN

 

dhayes89_1-1621957863404.png

 

Then advertise the static route on the VPN, instead of this.

dhayes89_0-1621957775906.png

 

ww
Kind of a big deal
Kind of a big deal

Only if you first select the default route at the hub. To participate  in vpn. Then the spokes learn that default route in the vpn

 

So if you select that static 0.0.0.0 route at the hub. Then set it, in vpn

dhayes89
Comes here often

Ok, will try that later today after the office is closed.

Thanks , that works.

dhayes89_0-1621974763530.pngdhayes89_1-1621974815329.png

HUB

dhayes89_2-1621974924312.png

 

dhayes89
Comes here often

Thanks. 😁

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels