VPN ports

JonathanC
Here to help

VPN ports

Why do we need (Or do we need?) ports 32768-61000 open for site to site VPN?

 

The IT guy who controls the network our Meraki is sitting on doesn't like having that number of ports open. Believes it is a security risk.

Is there a different option?

Thanks

2 Replies 2
Ryan_Miles
Meraki Employee
Meraki Employee

It's explained HERE. AutoVPN uses UDP hole punching with high number ports. In most cases as the article states you don't need to open anything on the upstream firewall.

Ryan / Meraki SE

If you found this post helpful, please give it Kudos. If my answer solved your problem click Accept as Solution so others can benefit from it.
PhilipDAth
Kind of a big deal
Kind of a big deal

If everything has static public IP addresses, then you could configure manual port forwarding:

https://documentation.meraki.com/MX/Site-to-site_VPN/Automatic_NAT_Traversal_for_Auto_VPN_Tunneling_... 

 

BUT, you are missing out on the benefit of automatic AutoVPN.  Could you maybe point out that the MX is a firewall, and doesn't require another firewall to protect it?  Otherwise how many layered firewalls do you need do you need to add to protect the existing firewalls?  The discussion becomes circular quickly.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels