auto vpn port

ehsan2305
Comes here often

auto vpn port

port need to only allow for auto vpn in meraki mx

3 Replies 3
BrechtSchamp
Kind of a big deal

Refer to the following page for the ports Meraki devices use to communicate:

https://documentation.meraki.com/zGeneral_Administration/Other_Topics/Firewall_Rules_for_Cloud_Conne...

 

AutoVPN uses hole punching so the port will dynamically be chosen. More info about whole punching here:

https://documentation.meraki.com/MX/Site-to-site_VPN/Automatic_NAT_Traversal_for_IPsec_Tunneling_bet...

 

The ranges used:

To contact the VPN registry:

  • Source UDP port range 32768-61000
  • Destination UDP port 9350 

 

For IPsec tunneling:

  • Source UDP port range 32768-61000
  • Destination UDP port range 32768-61000 

 

If this is an issue, you could opt for manual NAT traversal:

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Settings#NAT_Traversal

 

AutoVPN troubleshooting info here:

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Troubleshooting

 

Hope that helps.

 

If I block all ports for outgoing traffic and allow only the ports that you mentioned below than auto vpn between meraki mx will work and there will be no outgoing internet traffic.

 

Actually my requirement is to only allow vpn between meraki mx device with their local subnets, but user should not allowed internet browsing.

 

You don't need to add exceptions to the firewall for the VPN tunnels to work. The MX allows its own VPN tunnels automatically.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels