Hello I'm new here. We have an MX100 router and five MS120 switches at our hospital with multiple VLANs (all 192.168.x.x ranges). We are trying to connect an external Cisco router from our EMR vendor and use a static route to send all traffic to and from their company over that static route.
We have the router plugged into one of the front ports (not the WAN port) of the MX100. We assigned a separate VLAN under "Security & SD-WAN > Addressing & VLANs" with the subnet range 172.16.173.144/29 with a MX IP of 172.16.173.150. We assigned the uplink port to that VLAN.
Whenever we try to switch to the router and set a Static Route (also in the Addressing & VLANs screen) with its gateway being either a load balancer or the IP of the router itself (172.16.173.146), it seems to work and we can ping IPs on the other side of their network. They can also confirm they can ping us. But our Active Directory trust fails between the two, and we try to load their applications through their Citrix environment and they stall and fail and act like they can't find the servers (which ping fine).
What makes no sense is we temporarily have a site-to-site Non-Meraki VPN with them on the same MX100 and all works fine with that, including the Active Directory trusts But once we delete that VPN and try the static route they fail.
I'm not even sure if we are even setting this up right to begin with. What is the best way to set up a 3rd party router and make sure it can fully communicate both ways?