- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN third party is connected to hub but not to spoke connected to HUB
i configured a site to site tunnel between Meraki HUB and another Firewall, Meraki HUB is connected and can ping the other firewall, but the Spoke connected to HUB cannot ping the other firewall . is there anyway to let the spoke also ping the other firewall via the site to site tunnel done on the hub ?
Solved! Go to solution.
- Labels:
-
3rd Party VPN
-
Auto VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think it is still not possible.
Check out this documentation
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings
The following part:
An MX that builds tunnels to both Auto VPN and Non-Meraki VPN peers will not route traffic between other Auto VPN peers and the non-Meraki VPN peers unless BGP routing over IPsec VPN is enabled for the latter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But as for other devices, can you access them via the tunnel or are you having problems too?
Site-to-Site VPN Troubleshooting - Cisco Meraki Documentation
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
from the hub i can access the other third party firewall but not from the spoke wich is connected to the hub via autovpn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm not referring to the Firewall, I'm referring to any other device. Can you communicate with any device other than the firewall?
I'm almost certain that the firewall itself won't be able to ping the LAN interface.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i created a VM beside this firewall so same problem i can ping this device from the hub but not from the spoke... note that the other firewall is not meraki
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, now I understand, the third-party VPN does not participate in the SD-WAN tunnel. So you won't be able to reach it via Spoke, the only way is to create a VPN tunnel between the spoke and another firewall.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you ..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think it is still not possible.
Check out this documentation
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings
The following part:
An MX that builds tunnels to both Auto VPN and Non-Meraki VPN peers will not route traffic between other Auto VPN peers and the non-Meraki VPN peers unless BGP routing over IPsec VPN is enabled for the latter.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gladly...I had the same problem with an installation once...I solved it with an extra MX. I connected the extra MX to the same LAN as the Hub and did static routing in betwenn. The extra MX I used only to set up the IPSec Tunnel.
Not sure if it now could be solved somehow with BGP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Another option is creating a VPN tunnel between the spoke and the third-party firewall.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the problem is that i have 10 spokes 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A very small number. If it were 50, then it would be a problem.
This way, you don't have to spend unnecessarily on another MX.
Another option is to create a Linux VM within the network and create tunnels between this machine and the third-party firewall. This way, you would be able to route through the Linux machine and create a route on the HUB and thus guess the route to the SD-WAN.
These are free options.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
we cannot do static route on the hub ?? to let all spokes connect ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You would need another MX to point the static route at, and have the NMVPN configured on that MX, as @rwiesmann was describing.
If you use Secure Connect you can have a NMVPN tunnel terminate there and be shared by all spokes, but unless you're already in that ecosystem it would probably just be easier to get the 3rd party to create VPNs to every spoke network.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, It's not going to work. Third-party VPN is quite limited on Meraki.
Please, if this post was useful, leave your kudos and mark it as solved.
