Hi Everyone,
I have established a site to site vpn between MX 68CW and AWS. the tunnel is up on AWS and Meraki Dashboard. The problem is that I can't ping my DNS server which is on AWS. It looks like something is missing . The routing is enabled on AWS and Meraki . I suspect something to add on security group but I am not sure.
My local Lan is 10.200.45.0/24 and the vpc is CIDR is 172.31.0.0/16. Could you help me please , I am kind new .
Make sure you don't have any ACLs in Azure that are blocking ICMP (this is most likely).
https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html
I've already checked that , nothing blocked my ICMP packets
How about routes?
Have you tried disabling your server's local firewall?
Otherwise, open a support case.
By the way check this.
Hello,
I did use this link to setup my site to site vpn. the tunnel is up but still the ping is unseccessfull.
I have checked the ACL everything looks fine.
Don't forget that you can restrict both ACLs and the security group. If you don't have an ACL, review the security group, otherwise open a support case as suggested previously.
More specifically on inbound rules.
Ok so it's better to open support case with AWS because I do not think it's meraki issue ?
Yes
You have to check with Cisco TAC and Your AWS support Person jointly.
Surely, his issue with AWS side.
And Which Firmware version are you using in MX Meraki ?
Hi, Current version: MX 18.107.2
Hi Nabil,
Have a look at this tshoot guide from Meraki and AWS . There has been some known road blocks with IKEv1 with "one unique security association per Tunnel".
https://docs.aws.amazon.com/vpn/latest/s2svpn/your-cgw.html
Cheers,
Ivan Jukić
The #1 issue I run into when investigating these is - Windows Firewall. Try disabling it temporarily.
It's disabled
Hello, Nabil
Did you enable the LAN under Addressing & Vlans? Also check if under DHCP to what your DNS nameservers are set to and what IP's were assigned for Customs nameservers.
Thanks.