Meraki client vpn with private ip adrress

Solved
JJM
Here to help

Meraki client vpn with private ip adrress

Hi all,

 

I have a question regarding client vpn of meraki. If i use private ip address (FTTH) for WAN link, can i use client vpn service with that WAN ip? 

 

Thanks much!

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

no problem @JJM  - hope that makes sense?  

 

Just think, if you're outside your firewall/MX (at another site etc) can you ping/reach the IP of the device you want to VPN to?  If you can't then the client VPN won't be able to connect to it.

 

All the best

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

7 Replies 7
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @JJM , the MX WAN IP/Hostname needs to be accessible via the internet so I would say the answer is no

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

Thank you, DarrenOc.

DarrenOC
Kind of a big deal
Kind of a big deal

no problem @JJM  - hope that makes sense?  

 

Just think, if you're outside your firewall/MX (at another site etc) can you ping/reach the IP of the device you want to VPN to?  If you can't then the client VPN won't be able to connect to it.

 

All the best

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
GreenMan
Meraki Employee
Meraki Employee

Maybe set up some NAT / PAT on the firewall that sits between the MX and the Internet, so that you initiate the tunnels from your clients to a public address that lives in the firewall, but which the firewall then translates to reach the private address on the MX.

DarrenOC
Kind of a big deal
Kind of a big deal

??? Eh??  I can’t picture that one.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
ww
Kind of a big deal
Kind of a big deal

@JJM you have a modem/router that has the public ip from your ISP?

JJM
Here to help

No public ip, i just get DHCP address from ISP which get access internet.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels