Z3 Split tunnel

ChrisB
Here to help

Z3 Split tunnel

Hey all, wondering if any one can assist. 

 

At present we use Meraki Z3/Z3C for quick ad-hoc deployments to a short term location, where we require an urgent presence. As part of this we can offer our WLAN solution, which uses a external RADIUS service which needs to have a known public IP address for authentications. 

So with unknown public addressing (via an internet connection provided by a 3rd party site or via cellular) we can't always get a known static public address, so for a quick fix have resorted to building a VPN for all traffic back to our MX250.

What I would like to do is just VPN back the RADIUS (1812 & 1813) traffic only, so we are not brining back all the public internet traffic in to our HQ just to direct back out. Is there a way to be able to achieve this?

3 REPLIES 3
GIdenJoe
Kind of a big deal
Kind of a big deal

That design is probably not supported.
You can easily have split tunnel traffic by just not putting the MX250 as default route.

But all the subnets the MX250 injects into the SD-WAN will be made available through the tunnel.  That means all private traffic flowing between that Z3 local network and the networks and routes the MX250 knows and injects as VPN available.

 

All other traffic will break out locally to the internet at the Z3.

 

To further block traffic from the Z3 to the MX250 you can add the VPN acl to only allow radius traffic from the remote Z3 subnets towards the local MX250 networks.

KarstenI
Kind of a big deal
Kind of a big deal

I would implement it the follwong way:

  • Configure the Teleworker gateways for Split tunnel
  • Place a RADIUS-Proxy into your headquarter. This RADIUS-Proxy forwards the RADIUS requests to the external RADIUS.

This way you never have to touch the external RADIUS again to change any IPs and if the Teleworker gateways always use the same internal addresses for the APs, also the Proxy does not have to change.

 

PhilipDAth
Kind of a big deal
Kind of a big deal

I wouldn't have thought of @KarstenI 's answer - but that is a very good solution.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels