Need to share resources from 2 networks, 2 meraki firewalls next to each other

Solved
ThrivePet
Just browsing

Need to share resources from 2 networks, 2 meraki firewalls next to each other

Have 2 Meraki firewalls in the same building with different subnets and not sharing any resources in different Meraki organizations.

 

Need to be able to share resources between the 2 networks but unable to use site to site VPN since there is an overlapping subnet in one of the organizations (and won't be able to use subnet translation since they're in different organizations).

 

Was thinking about creating a L3 interface in each firewall (New existing VLAN) and build a static route to direct specific traffic.

 

This is a live environment and want to make sure this is ok before I configure it

1 Accepted Solution
Mloraditch
Kind of a big deal

That would work since you have physical connectivity. Make sure you if you have security needs that you setup appropriate group policies on the new L3 interfaces to firewall the traffic

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.

View solution in original post

3 Replies 3
Mloraditch
Kind of a big deal

That would work since you have physical connectivity. Make sure you if you have security needs that you setup appropriate group policies on the new L3 interfaces to firewall the traffic

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
rhbirkelund
Kind of a big deal
Kind of a big deal

What @Mloraditch says.

 

A new VLAN with a transit network and static rout should work just find. Also make sure to also have the return routes configured, and with a group policy you can limit traffic to and from the resource that you need to share. 

LinkedIn ::: https://blog.rhbirkelund.dk/

Like what you see? - Give a Kudo ## Did it answer your question? - Mark it as a Solution 🙂

All code examples are provided as is. Responsibility for Code execution lies solely your own.
DTellez
Here to help

You can use the site-to-site VNP functionality only by advertising specific networks you need. This way you avoid propagating the duplicate network. You can even set restrictions with the outgoing site-to-site firewall.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels