Hi All,
After a few tips for the next stages of our Meraki Journey and WAN topology.
We started as a 200 user org with a Meraki Full Stack (MX, MS, MR, MV, MDM)
We are now at 500 users and the MX100 is squeeling and hitting 100% utilization on CPU frequently!
We have 3 sites,
MX100 (HA pair) at HQ with Production virtual servers
MX84 at DataCentre (DR/failover site)
MX84 at remote branch (no servers just users)
All 3 sites are connected via Auto VPN. This has served us well for 3 years.
We used to use the MX100 as a client VPN server and then played with Meraki Anyconnect but had no luck so we were sold 2 vFTD (Virtual Cisco Firepowers) to do the Anyconnect piece in a more reliable manner than Meraki.
The MX's now NAT VPN traffic to vFTD's.
I'm looking to re-design this all as I think we need bigger hardware and more bandwidth.
- Do I get a p2p (LAN extension between the HQ and DC) and leave the MX for Internet and VPN only - this will make DR better as no-re-ip'ing of VMs)
- Do I get a MX 250 or 105 and add second leased line
- Do i use the virtual firepowers and retire the MX's as let's face it the MX isn't the best Meraki product
- DO I get a rebate on the vFTD's and buy a physical FTD appliance?
- Do I do something completely different?
- Ideally I'd also like the anyconnect VPN to flip between sites if a heart beat is lost or we have an outage - i've been looking at cloudflare for DNS failover.
Anyone have any better solutions/ideas?