parallel site-to-site vpn

Alcon-Greg
Conversationalist

parallel site-to-site vpn

We have 2 sites.

Site 1 has 2 WAN circuits, MX80

Site 2 has 2 WAN circuits, MX64

 

we have a site-to-site VPN but it only utilizes 1 of the WAN circuits.

Is there a way in Meraki to establish a site-to-site VPN on both WANs and load balance between the two for site to site traffic? Trying to get more site-to-site bandwidth without increasing circuit cost.

 

 

3 REPLIES 3
Alcon-Greg
Conversationalist

I may have figured it out.

The answer seems to be yes!!

And set up a performance class of 100ms max latency, 100ms max jitter, 10% max loss.

After setting up the AutoVPN, I went to Traffic Shaping and set up a VPN preference of load balance referencing the above performance class.

 

Traffic is now going site-to-site over both WAN1 and WAN2 per packet sniffing.

 

This is great!!

 

jdsilva
Kind of a big deal

Hey. All you have to do is enable load balancing globally under Security appliance > Traffic shaping and the MX will use both. You don't have to set up any performance classes or VPN flow preferences unless you want apply rules to specific traffic. The global setting will apply to all traffic.

+1 @jdsilva ; the VPN registry takes care of identifying possible participants in a tunnel and sort out multiple combinations to set them up, so when you enable VPN they are all ready to be used.

For example:

MX1:

- WAN1: 1.1.1.1

- WAN2: 1.2.2.2

 

MX2:

- WAN1: 2.1.1.1

- WAN2: 2.2.2.2

 

VPN registry will store:

a) 1.1.1.1 > 2.1.1.1

b) 1.2.2.2 > 2.2.2.2

c) 1.1.1.1 > 2.2.2.2

d) 1.2.2.2 > 2.1.1.1

 

When both WANs are active, you will automatically have two active tunnels between the two WAN1 (a) and the two WAN2 (b). 

Once you enable load balancing globally, the traffic will be automatically divided between the two tunnels, so no further configuration will be needed; sit back, relax and enjoy your coffee! 🙂 

 

Giacomo

Please keep in mind that what I post here is my personal knowledge and opinion. Don't take anything I say for the Holy Grail, but try and see!
Appreciate who helps and be respectful of every opinion and every solution offered.
Share the love, especially the Meraki one!
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels