Question on VPN Exclusion with SD-WAN + license

Solved
ToryDav
Building a reputation

Question on VPN Exclusion with SD-WAN + license

When using an MX as a branch spoke connecting to a concentrator in the data center, we need to implement a full-tunnel design to send all wired traffic on the network through the Corperate firewalls located in the data center.

However, I also have a requirement to send the local office wifi traffic (both office user and guest) out to the internet directly at the spoke level.

When I choose to send the default route to a spoke MX creating a full tunnel, am I correct that I then need an SDWAN + license to enable Local Breakout for a couple of wifi vlans to not use the default route through the tunnel?

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

All MX licenses support local Internet breakout based on port/IP

https://documentation.meraki.com/General_Administration/Licensing/Meraki_MX_Security_and_SD-WAN_Lice...

 

Only layer 7 (application) based local Internet breakout requires the sd-wan plus license

View solution in original post

3 Replies 3
Brash
Kind of a big deal
Kind of a big deal

All MX licenses support local Internet breakout based on port/IP

https://documentation.meraki.com/General_Administration/Licensing/Meraki_MX_Security_and_SD-WAN_Lice...

 

Only layer 7 (application) based local Internet breakout requires the sd-wan plus license

ww
Kind of a big deal
Kind of a big deal

You could use source based default route for this. (In case you dont advertise the default route in the vpn globaly)

 

https://documentation.meraki.com/MX/Networks_and_Routing/Source_Based_Default_Routing

RaphaelL
Kind of a big deal
Kind of a big deal

Wouldn't selecting these vlans and put them 'vpn off' already solve that issue ?

 

RaphaelL_0-1703197861091.png

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels