Hey all,
Hopefully this question hasn't already been asked but looking for some insight / advice on the following. I am being tasked with installing a pair of Meraki firewalls in high availability at a client site, and we are going to be using the clients switching infrastructure for our hosts on the network, and the firewalls themselves will live at the campus edge.
The client uses almost no Layer 2 and are running almost solely with VRF's to segment traffic. They mentioned that they wish to create as many VRF's as necessary to mirror our VLAN scheme we presently use in other sites (CORP, IOT, Surveillance).
I have little to no understanding as to how I should be configuring the firewalls to support this passoff of VRF's to the Meraki MX. On the MX I see I can create virtual interfaces tied to VLAN IDs so am I still to configure that in this scenario? Then do I just ensure that the client connects an Ethernet handoff configured for the CORP VRF they create to an access port on the MX configured for the CORP VLAN? When I create a VLAN virtual interface it automatically adds that route to that configured subnet to the route table so I don't think I need to do any static routing either to get this to work I wouldnt think.
Also side note, if my thinking above is correct, does this also mean I could technically use a single ethernet handoff to a port on the MX I configure as a trunk to carry all the VLANs? Or will this not work because with VRF's traffic will not have a VLAN tag when it enters the trunk from the clients Layer 3?
Any tips or recommendations are greatly appreciated.