Meraki VPN to Non-Meraki VPN (Cisco ASA)

Holli69
Conversationalist

Meraki VPN to Non-Meraki VPN (Cisco ASA)

Hi all,

 

is it possible to build a VPN tunnel using IKEv2 from Meraki MX100 with FW 15.44/16.12 to a Cisco ASA 5516-X FW 9.12 ?

What about the remote-ID, mandatory or optional ?

Should NAT-Traversal (NAT-T) also be enabled on ASA if I wish to use it on MX100 ?

 

regards

Roland

 

 

2 REPLIES 2
Inderdeep
Kind of a big deal

Re: Meraki VPN to Non-Meraki VPN (Cisco ASA)

@Holli69 : Check this out 

https://documentation.meraki.com/MX/Site-to-site_VPN/MX_to_Cisco_ASA_Site-to-site_VPN_Setup 

Regards
Inderdeep Singh
www.thenetworkdna.com ( Awarded by Cisco IT Blogs award 2020)
PhilipDAth
Kind of a big deal

Re: Meraki VPN to Non-Meraki VPN (Cisco ASA)

Yes.

 

The remote ID should be the public IP address of the remote ASA.

Leave NAT-T enabled.

 

Note that you can usually only have a SINGLE subnet in the source and destination encryption domains.  If you include two then only one tends to work at a time.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels