Source based router to Concentrator non meraki VPN

brianpmcp
Here to help

Source based router to Concentrator non meraki VPN

We have a VMX concentrator in Azure connected to an AutoVPN. We also have a non meraki site to site VPN for non meraki management traffic. We would like to "redistribute" the non meraki site to site vpn remote subnet into the AutoVPN. It seems this is not supported by Meraki. We had thought of the following options. Just wondering if anyone else has got something similar working. We can't terminate the non meraki site to site vpn to all sites as there are too many and are using TAGs to limit this to the concentrators.

 

1. Advertise a supernet /23 for the management traffic from the concentrator to pull traffic centrally and then route that to the /24 from the non meraki site to site VPN. This doesn't seem to work

 

2. Use a source based VPN route to redirect management vlan traffic to the concentrator and then onward to the non meraki site to site VPN. Initial testing doesn't seem to work

 

3. Use an Azure VPN gateway or firewall to terminate the non meraki VPN and send to the concentrator with BGP. Not tested yet.

2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

In my opinion it will not work, what is recommended in this case is to configure the S2S VPN with each location.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ww
Kind of a big deal
Kind of a big deal

That setup of using a vpn termination point behind physical mx and then using static routes or bgp works.

 

I supose it could also work on a vmx. 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels