Hi There
Looking to replace a customer who has a Pair of firewalls (Checkpoint) connecting into their MPLS WAN in an active/standby HA configuration. For reference these existing Checkpoints do very little part from some basic FW rules.
The Checkpoints are not NAT'ing traffic and are effectively acting as routers.
I need to ensure that a pair of Meraki MX appliances operating in HA can replace the Checkpoints. I gather that:
1. I need to log a support ticket with Meraki for them to enable the NAT Exempt feature on WAN
2. Obviously need to ensure that the WAN subnet can communicate with Meraki Cloud
I've attached 2 diagrams. First Diagram has the Meraki with a transit LAN and the second has all internal VLAN Gateways terminating on the MX LAN. I assume both are supported and from what I gather there is only a requirement to configure IP addresses and VRRP VIP on the WAN links and just a singe IP per Subnet on the LAN side.
Is the WAN NAT Exemption fully supported (I'm a little dubious to recommend a solution that relies on having to ask support to enable such a basic feature)?
What are typical failover times (based on real world examples)
See attached options.
Any feedback greatly appreciatedOption 1 - Transit LANOption 2 - VLAN GW