Hi,
I'm trying to setup a small network of Meraki MX's as SDWAN to see if it makes the management of our branch network a bit easier. I've installed my Hub site, an MX100 in 1 arm mode and have it connected to the Meraki Portal. We are overloading all of our internal devices (PAT) behind the external interface of our Juniper SRX firewall. I've dropped an MX67 at a branch site which is connected via the internet and via our internal MPLS network.
When I set our hub Meraki MX100 as "Hub" in Site-to-site VPN config and my branch as a "Spoke", I can do the configuration, however my Hub Meraki says that it is behind a NAT unfriendly device. My spoke connects to the VPN registry because it's connected directly to the internet via it's WAN1 uplink. I saw that the VPN registry doesn't like to be behind devices that do port randomization and that there is an option to do Manual Port Forwarding and lock down the IP/Port that the Meraki will be using.
Has anyone got this working through a Juniper SRX and can share the Juniper configuration for this? We only have 1:1 or many:1 translations in our Juniper and I want to know the way that Meraki expects it to happen.
My branch Meraki can also route to the internet via the internal network. Does the WAN2 (internal via MPLS) interface on the branch Meraki also then need it's own static ip/port translation via the external firewall (via internal network) to be able to register that internal interface with the VPN registry to built an SD-WAN tunnel via the internal network? Is it an option to do 1:1 ip/port with the same external address ie Hub uses 172.30.19.50:35200 -> 45.36.16.12:35200, Branch1 uses 10.23.254.1:35300 -> 45.36.16.12:35300, Branch2 10.23.254.5:35310 -> 45.36.16.12:35310 etc?
Cheers,
Tom