S2S split-tunnel exception

Solved
anjisan
Conversationalist

S2S split-tunnel exception

In my setup I have a S2S AutoVPN between  MXs. 

 

The VPN tunnel is using Split-tunnel, but I want to force (static route) certain internet IPs or internet subnets to be announced from the main hub so the branch MX will send traffic to the main hub and break out to the internet there.

 

I try to add a static route on the main hub and enable it for VPN, in the 'next hop' I add my MXs Gateway (ISP gateway)

But I get the error '...invalid next hop IP. The IP address x.x.x.x is not on a configured subnet.  

 

What am I doing wrong and what should I do ito make this work?

1 Accepted Solution
GIdenJoe
Kind of a big deal
Kind of a big deal

If the hub is routing for those remote public hosts via some other device that does the NAT towards there then you could share these routes over the AutoVPN.

Alternatively if you have the SD-WAN plus licensing you can have full tunnel to the hub and then locally breakout most internet applications.

View solution in original post

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

That doesnt work,

 

I do know its possible with a one armed concentrator-hub design

GIdenJoe
Kind of a big deal
Kind of a big deal

If the hub is routing for those remote public hosts via some other device that does the NAT towards there then you could share these routes over the AutoVPN.

Alternatively if you have the SD-WAN plus licensing you can have full tunnel to the hub and then locally breakout most internet applications.

PhilipDAth
Kind of a big deal
Kind of a big deal

This above.  You need an SD-WAN licence, use full tunnel, and then specify excepts to get routed out the local Internet gateway.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels