- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
non meraki peers
Hello!! I have a issue and I don't know how to solve it. My question is: Can a meraki make a dialing to non-meraki peer? I mean, the non-meraki peer its configured as server, so the peers must to dial to make a connection, but. I checked the vpn log on the meraki appliance and it does not make any dialing to non-meraki peer. It seems like its only "hearing" to get the connection up. Does anybody has a similar case?
Thank you
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The Meraki MX will initiate a connection once it sees traffic matching the destination encryption domain.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki MX devices do support establishing IPSEC tunnels to non-meraki devices
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings#Non-Meraki_VPN_Peers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Brash, thank you for the link. Yes I've created VPN between non-meraki peers and meraki devices. There is not prolbem, I can connect to non-meraki peers when the non-meraki peer "dial" to the meraki appliance. In this case the meraki device has to "Dial" to the non-meraki peer. I don't find any option to "Dial" to the non-meraki peer from de Meraki device. Do you know how to make the dial from the meraki device?
Thank you
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The MX should be able to initiate the negotiation of the tunnel.
Do you see any events in the Meraki event log? Specifically using the following filter
If you do a packet capture outbound on the MX, do you see packets going out towards the destination?
If you're using FQDN, make sure that the MX can resolve the domain name.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello again Brash!!
Yes, I can see in the log table no activity from meraki device trying to connect to the non-meraki peer. It's so strange. I supposed that meraki device could make the dialing, but it's seems that is not happening. I'll try restarting the meraki device, but I don't think that it works.
Best regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Brash, the only message I've got after restarting the meraki device was "
msg: FIPS mode disabled" |
There is no activity to establish coonection with the non-meraki peer
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The Meraki MX will initiate a connection once it sees traffic matching the destination encryption domain.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Phillip!! You are right!! I sent pings to the non-meraki peer and the connection gots up.
Thank you to all of you for your help
Regards!!
