Site-to-Site VPN limits

Chris_Net
Conversationalist

Site-to-Site VPN limits

I am trying to find information on Site-to-Site VPN connection limits.  Our company uses Site-to-Site VPN and we have a concern about reaching a possible limit on sites as we continue to expand and add new locations.

Thank you in advance for any information on this.

 

-Chris

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

No hard limits but here are the tested and recommended max. https://meraki.cisco.com/product-collateral/mx-sizing-guide/

 

Tunnels count /calculation can be found here  https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/...

GreenMan
Meraki Employee
Meraki Employee

Remember also that MXs can have a number of functions and the load is cumulative;   a routed mode MX in a HQ  handling (say) 150 concurrently connected VPN clients, whilst also providing Layer-7 firewalling with IPS & AMP protection for a 100 clients on the LAN will practically be able to support fewer site-to-site VPN tunnels and/or provide a lower level of throughput for all those users.

Make sure to use the recommended maximum number of site-to-site VPN tunnels in your calculations, too.

It is possible to monitor overall MX load using Organization > Summary report
https://documentation.meraki.com/MX/Monitoring_and_Reporting/Device_Utilization

Chris_Net
Conversationalist

Thank you both for your answers as well as providing links to information.  This was very helpful. We went through the recommended amounts and also calculated our ‘Mesh’ type of current connections.  The utilization advice really gave us a way to understand where we are with this and allow us to project forward our grow.

 

On a minor separate note, the link where the device utilization shows an equation…after scratching my head a bit, I realized that the Meraki documentation has a mistake on the listed equation….they should review that section and correct it.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels