Hi All,
I'm planning to setup a Meraki campus using two tier firewall for a branch office, would be happy to get some ideas, if Meraki MX platform can support, what I am planning to do.
1. MX as external internet firewall (NAT mode)
2. Cisco platform as internal firewall
3. MS 410 as L3 transit switch with MPLS link to access internal LAN through Cisco firewall from other branch & DC.
4. MS 410 as Core/Aggregation switch.
5. MS 120 as Edge switches.
The design is not a HA setup,
MX will be gateway for Guest WiFi network.Cisco Firewall will be gateway for Inside LAN network.
Guest Wifi Vlan will by-pass internal Firewall and go directly to MX for internet access.
All Inside LAN traffic will go through Cisco internal firewall for inter-vlan routing and pass through L3 transit switch for internet access. L3 MS 410 transit switch will have default route for internet through MX firewall.
Would like to clarify, the connection mode between MX to downstream.
1. Can I have trunk link between MX to Core for guest vlan and Access link (transit vlan) between MX to L3 transit switch for L3 connectivity default route to MX for internet?
2. Else should I keep MS core switch as gateway for Guest Wifi and have L3 (transit vlan) link between both Core switch to MX and transit switch to MX?
What is the recommended setup.
Thanks,