Routing help with MX100

framosCTLink
Here to help

Routing help with MX100

Hi Guys,

 

Im quite confused right now if I was able to configure everything correctly. For any routing expert out there, may I seek help please?

 

My issue is I want Branches A, B & C talk to Branches XYZ back-to-back thru Meraki having different network provider with different physical circuits. (please see connections below)

 

Meraki MX100.jpg

 

If this might help explain the issue much further:

 

Provider 1 Routing table sample is below:

192.168.100.0/24 next hop 192.168.0.246

192.168.110.0/24 next hop 192.168.0.246 and so on..

Meraki Routing table
192.168.100.0/24 next hop 192.168.100.1

192.168.110.0/24 next hop 192.168.100.1

192.168.10.0/24 next hop 192.168.0.1

192.168.20.0/24 next hop 192.168.0.1

 

Provider 2 Routing table

192.168.10.0/24 next hop 192.168.0.1

192.168.20.0/24 next hop 192.168.0.1 and so on...

 

after configuring allow rule on L3 Firewall on MX100, Branches ABC cant still see Branches XYZ, am I missing something?

also for the port on meraki, should I switch it to Trunk?

Franco Ramos
3 Replies 3
KarstenI
Kind of a big deal
Kind of a big deal

Actually, I don't really get what you are trying to achieve.

Most important is, that your MX-Ports in use are two LAN-Ports and not the WAN-Ports. For these two LAN-Ports, Access is perfectly fine.

 

EDIT:

You say "ABC can not see XYZ". Does this mean the other direction is working? Or in general: What is already working? ISP1 to ISP2, ISP2 to ISP1, any Branch to MX, any Branch to the other ISP?

How do you test? Are your test-packets allowed on the target-devices?

Thank you for this, got totally confused yesterday and forgot to test both sides of the network, will update my post later. Thanks again!

Franco Ramos
Claes_Karlsson
Getting noticed

To see dynamically learned routes on a router you need some kind of dynamic routing protocol. Have a look at this link to achieve dynamic learned routes from/through a MX. 

 

https://documentation.meraki.com/MX/Site-to-site_VPN/Using_OSPF_to_Advertise_Remote_VPN_Subnets

 

/CK

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels