- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Third Party VPN - Hub-Spoke Auto VPN Availability
Question about third party VPN remote subnet availability....
My org is a hub-spoke setup....the data center is the hub for the Auto-VPN setup, and all the branch offices are the spokes. We do split tunnel on the Auto VPN, so only those advertised subnets on the Auto VPN go over the S2S VPN, and clients use the local internet connection for everything else.
We are setting up a third party IPSec VPN to an offsite network that is hosting some servers. We are going to peer the Hub MX in the data center to this IPSec tunnel. The clients in the various Spoke networks will need access to the servers being hosted on the remote side of this IPSec tunnel.
Question...how do we advertise the remote network's subnet to the Spoke networks over the Auto VPN, so that clients in the Spoke networks can connect to the servers in the remote network on the other side of the IPSec VPN tunnel? Is that possible with only the Hub MX peering this connection?
Solved! Go to solution.
- Labels:
-
3rd Party VPN
-
Auto VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is not possible, for that you need to configure the S2S VPN with another device on your network (eg Linux with Strongswan) and then create a static route to advertise within the SD-WAN.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is not possible, for that you need to configure the S2S VPN with another device on your network (eg Linux with Strongswan) and then create a static route to advertise within the SD-WAN.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, basically, another device like an ASA has to be doing the IPSec tunnel, and then a static route on the Hub MX would be then be advertised in the Auto VPN? Could it be another MX in VPN Concentrator mode?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can advertise a route on Auto VPN without problems, as for using another MX I believe it is possible as long as you point a static route to the LAN IP of that MX, but for that, both have to have a direct link.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki Support told me the same thing...impossible to do that kind of routing with a simple Hub-Spoke setup.
Yeah, I have a few solutions brewing. The remote MX in the offsite network (if they would even allow that), setup a limited number of Spoke networks as Peers to the same IPSec tunnel, or setup the tunnel on another router or MX on the same LAN subnet as the Hub MX and use static routes to advertise it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@alemabrahao is right on the money.
The other option is to put an MX in the offsite network. This would be the easiest solution.
If it is a public cloud (like Amazon AWS or Azure) you could use a vMX instead.
