- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Multiple non Meraki VPN connections
Hi,
I want to establish independent non-Meraki VPN connections to the same destination with multiple MX68 devices.
Are the Site-to-Site connections configured globally in Meraki and not on each MX itself, right?
Do I need to create a separate network tag for each MX, set up a tunnel for each MX, and then assign the individual MX tag to each tunnel?
Thanks
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agreeing with PhilipDath's answer. Typically you will be using different tags only if you want any of the PSK, phase-1 or phase-2 settings different for any of the MX68s. If that's the case, you can configure the same peer again and use different settings as you want with the new tag created for those MX68s in the 'availability' section.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is a good idea to create TAGs, otherwise you will try to establish a tunnel with each MX in the organization.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
>Are the Site-to-Site connections configured globally in Meraki and not on each MX itself, right?
Correct.
>Do I need to create a separate network tag for each MX, set up a tunnel for each MX, and then assign the individual MX tag to each tunnel?
Typically you would use a single tag for each destination. As long as you use the same PSK, phase-1 and phase-2 settings, you can then just apply this one single tag to every MX network that will be connecting to the same destination.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agreeing with PhilipDath's answer. Typically you will be using different tags only if you want any of the PSK, phase-1 or phase-2 settings different for any of the MX68s. If that's the case, you can configure the same peer again and use different settings as you want with the new tag created for those MX68s in the 'availability' section.
