- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Multiple subnets through single port
We're testing a Meraki MX84 before we purchase. 3 days were spent setting up VLANS using configuration from the old Watchguard.
Finally, ready for cutover and everything worked EXCEPT-our internal web servers had no return path. The internal web server has 2 NICs. One goes to the Internet and has an IP address of 10.10.x.x and the other NIC's IP address is 20.10.10.x. The 20.10.x.x is NAT'd to our internal network. This allows the web team to perform updates without going out to the Internet then establish a tunnel back in.
The MX84 has 2 Internet gateways and 2 BOVPNs. The 5th port is connected to a core switch.
We were able to verify traffic passed internally from the core switch to the MX84 the on to the internal web server. However, traffic could not return through the same route. It defaulted to the 10.10.x.x network instead of 20.10.x.x.
The Meraki engineer claimed that the MX84 wasn't capable of handling the problem as this time and it's a future feature.
Can anyone help?
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm pretty sure the MX can only NAT from the outside (WAN) interface to an inside (LAN) interface, so I wouldn't expect the setup you're trying to do to work with an MX. It's not totally clear to me why you have this setup, so perhaps there's a workaround that's not clear to me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Below is the technician's notes:
In short the MX can not do internal 1:1 Natting
When traffic leaves the interface from the 172 network it is sent to the 20 network in the full 172 network space ip.
The Watchguard when traffic traverses to the other network interface allows it to appear as if it's coming from the 20 network IP of the watchguard (Similar to a router).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The Meraki technician is correct. You can only NAT from a WAN interface to a LAN interface. You can not NAT from a LAN interface to a LAN interface.
Two fixes:
- Configure a local hosts entry on the developer machines for the DNS name pointing to the internal IP.
- Configure an internal DNS zone matching the external zone, but change the server entry to point to the internal IP address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks to all that took time to reply.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm pretty sure the MX can only NAT from the outside (WAN) interface to an inside (LAN) interface, so I wouldn't expect the setup you're trying to do to work with an MX. It's not totally clear to me why you have this setup, so perhaps there's a workaround that's not clear to me.
