Meraki client vpn with private ip adrress

Solved
JJM
Here to help

Meraki client vpn with private ip adrress

Hi all,

 

I have a question regarding client vpn of meraki. If i use private ip address (FTTH) for WAN link, can i use client vpn service with that WAN ip? 

 

Thanks much!

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

no problem @JJM  - hope that makes sense?  

 

Just think, if you're outside your firewall/MX (at another site etc) can you ping/reach the IP of the device you want to VPN to?  If you can't then the client VPN won't be able to connect to it.

 

All the best

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

7 Replies 7
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @JJM , the MX WAN IP/Hostname needs to be accessible via the internet so I would say the answer is no

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
JJM
Here to help

Thank you, DarrenOc.

DarrenOC
Kind of a big deal
Kind of a big deal

no problem @JJM  - hope that makes sense?  

 

Just think, if you're outside your firewall/MX (at another site etc) can you ping/reach the IP of the device you want to VPN to?  If you can't then the client VPN won't be able to connect to it.

 

All the best

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
GreenMan
Meraki Employee
Meraki Employee

Maybe set up some NAT / PAT on the firewall that sits between the MX and the Internet, so that you initiate the tunnels from your clients to a public address that lives in the firewall, but which the firewall then translates to reach the private address on the MX.

DarrenOC
Kind of a big deal
Kind of a big deal

??? Eh??  I can’t picture that one.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
ww
Kind of a big deal
Kind of a big deal

@JJM you have a modem/router that has the public ip from your ISP?

JJM
Here to help

No public ip, i just get DHCP address from ISP which get access internet.

Get notified when there are additional replies to this discussion.