hairpinning Meraki MX?

hmc250000
Here to help

hairpinning Meraki MX?

Is hairpinning (traffic making a u turn in and out of the WAN interface) supported out of the box on MX appliances? 

 

On Cisco ASA this has to be configured.

4 REPLIES 4
Nash
Kind of a big deal

Re: hairpinning Meraki MX?

PhilipDAth
Kind of a big deal

Re: hairpinning Meraki MX?

You'll need to be more specific.

 

If you are using AutoVPN this this is automatic.  Remote branches can talk to each other routing via the hub.

Ken_Kane
New here

Re: hairpinning Meraki MX?

I would like to Hair Pin via the "Non-Meraki" VPN peers. can that be accomplished? we set up an ASA in AWS and use that for Any Connect. the Any Connect is accessed via one port on the ASA and then we have an IPsec Tunnel to our Corp office MX via a second port.  the MX also has an IPSec Tunnel to our office in Japan. I would like to have Any Connect users access the office in Japan with the existing tunnels. The MX would perform the hair pin from one tunnel to the other.

Bruce
Kind of a big deal

Re: hairpinning Meraki MX?

I don’t believe you will be able to do what you intend, the way you are describing. The MX won’t pass the traffic between the two third party VPN tunnels.

 

Probably the best approach would be to establish a VPN tunnel between the device in Japan and the ASA in AWS so that traffic can take that direct path, instead of via the Corp Office MX.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.