cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PAT configuration

Highlighted
Conversationalist

PAT configuration

Hello all, new to the group.  I'm demoing the MX250 in my environment.  I have a special situation that requires me to PAT 2 of my internal VLANs to 1 external public IP address.  I do this easily with my ASA firewall, but can't figure out how to do it on the MX.  From what I understand from reading other posts in this forum, that 1:Many NAT setup would not work for my situation.  If anyone can point me in the right direction, I'd really appreciate it!

 

Thanks,

Tom

3 REPLIES 3
Highlighted
Meraki Employee

Re: PAT configuration

Hi @TJG 1:1 and 1: Many NATs will allow you to map a single or multiple clients (you cannot map more than 1 per a single port) to a public IP address but not an entire vlan. However, one way you can achieve this is to configure the public IP as your second Internet connection and then do flow preference so that all the traffic from those VLANs will use the secondary Internet IP and not the default primary

 

https://documentation.meraki.com/MX/NAT_and_Port_Forwarding/Troubleshooting_Port_Forwarding_and_NAT_...

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Load_Balancing_and_Flow_Preferen...

 

Cheers!

 

Raj

If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it
Highlighted
Conversationalist

Re: PAT configuration

Thanks Raj, my problem with that is I already have 2 internet connections coming into the MX.

Highlighted
Here to help

Re: PAT configuration

We have lost a lot of sales due to the lack of NAT functions on the Meraki and all we get told is "Maybe Meraki is not for you". I use the "wan2" work around a lot but there is not much you can do if you are using your Wan 2 as a wan port.

Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.