Site to Site VPN between 2 Meraki MX

Alain_Bensimon
Getting noticed

Site to Site VPN between 2 Meraki MX

In my Canadian HQ in Montrea, I have Meraki MX68 with some site to Site VPN, (one to Europe to the main HQ, another one to an old Cisco ASA in Toronto).

I have added a new network in Vancouver and have setup an MX64.

I just had to enable the mesh in the site to site VPN page of the MX64, and I can reach (ping, map network drives) all Montreal devices.

The only issue is that the DNS is not working properly.

Currently Vancouver gets the ISP's DNS, Internet is working fine, but it can't resolve the names of the Montreal devices, only IP's.

So I'm wondering how I can enable the DNS between Montreal and Vancouver.

Thank you

1 Reply 1
KarstenI
Kind of a big deal
Kind of a big deal

Three typical options here:

  1. Place a DNS-server in the Vancouver office and tell the devices to use this. This DNS server replicates with your Montreal DNS server
  2. Your Vancouver devices are configured to use the Montreal DNS-server
  3. With 2), the Internet-DNS requests are also sent to Montreal. I would order an Umbrella subscription for DNS-security (which is a good idea anyhow). The internal requests are sent to the Montreal DNS and the internet-requests are sent to Umbrella by the MX Umbrella Connector. This would be my preferred option. 
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels