I have setup quite a few AutoVPN networks normally split tunnel with Adv. Sec on MX's.
But in this case the customer wants to run Full tunnel (only enterprise license) for networks (and that's fine) but they want ONE network to just have local internet breakout (no security , or as much as the Enterprise lic can give them, and of course no access through AutoVPN).
This should be pretty simple, just set that network to disable on the Site-to-Site page right ? ... right ?
The problem is that when i take this network out of AutoVPN (set that specific network to disabled) and try to ping from the MX (source "the internet only VLAN") I see these packets on the central HUB MX (in a packet capture).
I have NO idea why, this should not happen right ?
Or is this because I use the MX status page to test out connectivity (some random issue no-one was aware of).
Just wondering.
Or have I missed something ?
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings
Documentation seems to agree with "how I think this should work".
Thanks
Thomas