Meraki to Azure for multiple sites

MerakiStig
Conversationalist

Meraki to Azure for multiple sites

I have 3 sites that currently link via a VPN.

 

In addition i want to connect them to Azure through a non meraki VPN peer.

 

In Azure i have created a virtual network, a virtual network gateway, 3 local virtual networks and a connection for each local virtual network.

On this virtual network is a virtual machine

 

In meraki i created a non meraki VPN peer for site 1 which connected.

I can also RDP connect to the virtual machine. 

This is working

 

The issue im having is then when i setup a non meraki VPN peer for site 2 it breaks the connection for site 1.

 

From my understanding its because the connection is exactly the same, Same Public IP going to the same private subnet, I've just done it on a different network on the Meraki portal.

I thought being done on a different site network in meraki wouldn't impact the other.

 

Anyone done this before any know how to resolve it?

 

 

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

You need a tunnel for each site, it means 3 tunnels on Azure.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Can you elaborate?

 

I already have 3 local networks setup in Azure each with their own connection.

 

Issue is all 3 local networks connect to the same virtual gateway network so the non meraki vpn setup is to the same public IP and subnet.

 

Site 1 is connected from meraki to azure

I can not connect the other 2 without breaking site 1 

Resolved my own issue...

Set site 1 form spoke to hub

Tagged all networks

Changed each Meraki to Azure VPN connections from all networks to their own tagged network.

I now have 2 sites working, connecting to Azure without breaking

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels