Unable to connect Client VPN

Solved
Mad_Dog_82
Here to help

Unable to connect Client VPN

Hi All,

 

Cisco Meraki Model MX65.

I try to connect VPN from iPhone and Windows 11.

On both devices I get:

 

vpn error.jpg

 

IMG_0064.jpeg

 

Below is the configuration on Windows 11 laptop.

 

w11 vpnsettings.jpg

 

Compared VPN client configuration on Meraki with another device.

VPN account details are correct.

Pre-shared key is correct.

 

Could you please help to investigate why VPN doesn't connect.

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

So the server IP is wrong or this MX is behind a NAT.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

8 Replies 8
alemabrahao
Kind of a big deal
Kind of a big deal

Check the connection properties.

 

https://documentation.meraki.com/MX/Client_VPN/Client_VPN_OS_Configuration#Windows

 

alemabrahao_0-1711103479979.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal
Kind of a big deal

You can also check this.

 

https://documentation.meraki.com/MX/Client_VPN/Guided_Client_VPN_Troubleshooting

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Mad_Dog_82
Here to help

Hi @alemabrahao 

I tried VPN Connection Properties as on your screenshot but still the same error.

As I mentioned in the first post there is another Meraki router with identical VPN configuration and Client VPN works like a charm on that router.

Could it be related to the device or Meraki OS being faulty or Client VPN license is absent.

May be some firewall rules should be added?

 

P.S. I tested Client VPN on another Meraki (same MX65 model) that belongs to the same organization just branch office and was able to connect VPN.

alemabrahao
Kind of a big deal
Kind of a big deal

So the server IP is wrong or this MX is behind a NAT.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Mad_Dog_82
Here to help

Hi @alemabrahao 

I think you may be right.

This looks like the Meraki device behind a provider's router.

 

Screenshot 2024-03-24 062612.png

 

In this case can I use dynamic hostname instead or it wouldn't work either?

Amin_Costa
Conversationalist

Hi @Mad_Dog_82,

 

I would suggest that your request the provider to configure a port forward on his router to your device using the ports 500 and 4500.

 

There's another solution that you may use, the Cisco Anyconnect that may be more simple to configure.

 

Hope that helps.

Shubh3738
Building a reputation

Server address missing

PhilipDAth
Kind of a big deal
Kind of a big deal

If your MX is sitting behind a NATed connection, you'll need an extra registry entry to allow the VPN to work.  I have a VPN config wizard which creates a powershell script.  Run that to configure client VPN on any Windows machines machine you want.  They should make it work.

https://www.ifm.net.nz/cookbooks/meraki-client-vpn.html 

 

The iPhone - if it is using a carrier doing CGNAT it may never work.

 

 

If you want a solution that will work 99.999% of the time, but a licence for Cisco Secure Client (used to be called AnyConnect), and use that instead.

ps. AnyConnect licences are "honesty" based so you can try it out first to verify that it will work.

https://documentation.meraki.com/MX/Client_VPN/AnyConnect_on_the_MX_Appliance 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels