cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Multiple external IP addresses

AlexanderDrago
Getting noticed

Multiple external IP addresses

Hello, everyone!

I have one question. If Meraki can configured multiple external IP addresses ? Example i have guest wifi and want that network use another external ip different of main.

1:NAT and 1:1 NAT dont work(i found some advices). Because it dont understand all subnet, only 1 lan ip.

14 REPLIES 14
Adam
Kind of a big deal

Re: Multiple external IP addresses

I've also tried to accomplish this and I'm fairly certain it isn't possible.  The NAT will only be for external traffic coming in.  Everything going out will go through the MX WAN IP.  Depending on your use case, the only real option would be to put an L2 switch outside of your MX WAN interface.  Have one cable going to the MX WAN interface and another going to your switch VLAN or device and then you could give those devices the WAN IP directly although they will not be going through the MX.  I guess conceptually if it is for a guest network you could also have a separate, cheap, router that is connected to the WAN that you route traffic to/through.  

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
jdsilva
Kind of a big deal

Re: Multiple external IP addresses

What @Adam said. Inbound only 😞

 

But... If you were to use the second WAN port and assign a second external address to that, then you could use Internet flow preferences to steer some traffic out the second IP (and in) giving you two public IP's. 

 

It's not how it's meant to work, and not clean by any stretch, but if you absolutely needed to second IP for say, have one specific server use a specific IP outbound, it could work. 

 

Disclaimer, I haven't tried this directly, but I don't see why it wouldn't work.

John2
Here to help

Re: Multiple external IP addresses

Meraki doesn’t currently support this. One way you might also be able to get around this is by placing a router on your network, doing a 1:1 NAT on the MX to this router. Then NATing the guest WiFi traffic through this router. It does add another device and double NAT but should achieve what your trying to do.

Ben
A model citizen

Re: Multiple external IP addresses

We are currently struggling with this as well since the provider NAT public traffic to a private address. 

Response from Meraki 

its a heavily requested feature its not really got a alternative im afraid
 
I think it's ridiculous that such a future proof firewall does not support sourcenat... 
 
 
Darrell
Just browsing

Re: Multiple external IP addresses

So just to clarify, if I have a block of IP addresses associated with my Internet connection, the Meraki is incapable of using any but the IP address of its external interface?

If that's the case, what is Meraki's suggestion/recommendation for doing this functionality that Cisco ASA's have had since the Pix was introduced?

jdsilva
Kind of a big deal

Re: Multiple external IP addresses

@Darrell Not exactly. It can use multiple IP's for inbound traffic. So you can do DNAT on inbound traffic. What you cannot do is SNAT on outbound traffic. 

AlexanderDrago
Getting noticed

Re: Multiple external IP addresses

One of solution you can use this in Security appliance - Traffic Shaping and chose for you network wan portScreenshot from 2018-08-01 14-48-35.png

Ben
A model citizen

Re: Multiple external IP addresses

let's get this topic back from the dead. 

since IkeV2 is in beta (other topic) perhaps we should get the attention of Meraki to have a look at sourcenat. 

Neil_S
Conversationalist

Re: Multiple external IP addresses

Okay.. this can be done by... 

 

Create a VLAN on your MX..

 

Subnet: 212.1.1.0/29

MX IP: 212.1.1.2

VALN ID: you choose. 

 

 

Set your client PC with the blow.. 

 

IP 212.1.1.3

Mask: 255.255.255.248

Gateway: 212.1.1.2

 

Set 1:1 NAT 

 

 

Public IP:212.1.1.3

LAN IP: 212.1.1.3

 

This will then show your second IP when access the internet, not the IP of the MX. 

 

admin24-7
Just browsing

Re: Multiple external IP addresses

Hello Neil_S,

I have tested your suggestion and it worked.

However, I have found one Downside, that is that it is no longer possible to reach our public addresses from inside the LAN, after setting up the VLAN.

Are there any other side effects you experienced?
Are you using this workaround in a productive environment?

Neil_S
Conversationalist

Re: Multiple external IP addresses

Hi 

 

I haven't seen any other downsides and yes I have this is a production environment for a customer. 

 

 

 

thomasthomsen
Getting noticed

Re: Multiple external IP addresses

Sorry to wake this old tread 🙂

Im interested in what you did here (because to me its not quite clear).

But does your solution give you the option to route a guest vlan out another public IP then the one the MX has for itself ?

AlexanderDrago
Getting noticed

Re: Multiple external IP addresses

Hello!

Yep, in guest vlan we have another external ip

You can try test on your guest vlan

thomasthomsen
Getting noticed

Re: Multiple external IP addresses

But how did you do this ?

Did you use Flow preferences ? (because here I can only select WAN1 or WAN2 in the prefered uplink).

Or did you do the NAT thing as described somewhere above here ?

 

Im curious. 

 

Thanks

Thomas

Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.