Good Morning!
I'm sure this question has been asked. But, I did some searching and couldn't find the answer I'm looking for.
A high level view of our topology at our datacenter/NOC level is as follows:
Firewall
|
Content Filter
|
Layer 3 core router
|
Distribution layer
|
Access layer
We are adding a small branch. We have two option to do this in my understanding. Form a VPN peer with our existing firewall (not a Cisco or Meraki firewall). Or our preferred option is use a MX security appliance in the NOC along with a MX security appliance at the branch. We don't need redundancy or hot spares, so just the one MX on each side of the VPN tunnel. So, I have three questions.
1.) In our topology, it looks to me like the MX on the NOC side would plug into our layer 3 switch in our NOC (or even one of the layer 2 switches) and use an internal IP address. We would just need to make sure it's allowed through the firewall. Is this correct?
2.) I've read conficting options on if I'll need do any routing on the MX appiance in the NOC, but if it's forming a VPN peer with the other MX, I'm not seeing why I would?
3.) Can you mix and match the models of MX appliances that work together? For instance we have an MX84 and a MX65 that we would like to use together :).
Apologize if my questions are redundant!
Thanks for the assistance!