VLAN Config on Singled Armed concetrator for SSID Tunneling

Solved
S_Remella
Conversationalist

VLAN Config on Singled Armed concetrator for SSID Tunneling

Is it possible to configure multiple vlans on one armed VPN concentrator. 

we need a SSID tunneling from MS access point to MX at DC which suppose to allocate a subnet based on SSID. 

5 different SSID's distributed across spoke end sites, when users connected these are to be centrally switched. 

 

As per documentation, AP must connect to MX only on VPN concentrator mode, however in this mode i didnt see options to enable VLANS

1 Accepted Solution
jdsilva
Kind of a big deal

Hey @S_Remella ,

 

You can do what you're asking, but you do not have to configure SSIDs on the MX. You set this under the SSID, and when traffic exits the tunnel on the MX it will be tagged accordingly. 

 

So you set the SSID to VPN tunnel mode and then below you specify the VLAN tag you wish traffic to be tagged with when it exits the MX. Optionally, you can specif the VLAN via RADIUS attributes in the Access-Accept message. 

 

image.png

You don't need to set anything on the MX at all for this as it's just layer 2 for whichever VLANs you specify in the SSID config. Just make sure that the appropriate VLANs are trunked to the WAN interface of the MX and it should work. 

View solution in original post

3 Replies 3
jdsilva
Kind of a big deal

Hey @S_Remella ,

 

You can do what you're asking, but you do not have to configure SSIDs on the MX. You set this under the SSID, and when traffic exits the tunnel on the MX it will be tagged accordingly. 

 

So you set the SSID to VPN tunnel mode and then below you specify the VLAN tag you wish traffic to be tagged with when it exits the MX. Optionally, you can specif the VLAN via RADIUS attributes in the Access-Accept message. 

 

image.png

You don't need to set anything on the MX at all for this as it's just layer 2 for whichever VLANs you specify in the SSID config. Just make sure that the appropriate VLANs are trunked to the WAN interface of the MX and it should work. 

S_Remella
Conversationalist

Thank you jdsilva!! 

Toby
Getting noticed

Good answer!


I'm wondering if this is documented by Meraki somewhere?

 

Been trying to getting a good grip on exactly how this works, but either the documentation which do exist explains this poorly or I'm just failing at finding the correct documentation.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels