site to site VPN and client VPN

Solved
jay_b
Getting noticed

site to site VPN and client VPN

Hi,

 

I have 2 sites. Site A and Site B with MX250s. Site to site tunnel is configured between these 2 sites. Site A also have site to site tunnel configured to AWS tunnel. Site B don't have AWS tunnel.  On site A, we have client VPN. 

 

If someone on Site B want to access AWS stuff, can they connect to Site A's client VPN ?

1 Accepted Solution
RaphaelL
Kind of a big deal
Kind of a big deal

They could. The Client VPN flow will be over the internet and not in the S2S VPN.      Client VPN on Site B -> ( Internet ) Site A  -> AWS. 

 

In that case having or not the S2S between Site A and Site B is irrelevant

That would be one way to do it.

View solution in original post

12 Replies 12
RaphaelL
Kind of a big deal
Kind of a big deal

They could. The Client VPN flow will be over the internet and not in the S2S VPN.      Client VPN on Site B -> ( Internet ) Site A  -> AWS. 

 

In that case having or not the S2S between Site A and Site B is irrelevant

That would be one way to do it.

jay_b
Getting noticed

Great. Thanks @RaphaelL  I will give a try.

jay_b
Getting noticed

I just tried Client VPN and site to site tunnel enabled and I am not able to connect client VPN from Site B to site A. As soon as I disable site to site tunnel , client VPN works. 

RaphaelL
Kind of a big deal
Kind of a big deal

You are probably in full tunnel mode. Your  Client VPN flow is going thru your VPN tunnel and not over the internet. 

jay_b
Getting noticed

@RaphaelL  What do you mean by full tunnel mode? I don't have client VPN subnet and subnet which client is connected to at site B is in site to site tunnel.

 

I only have site to site configured for management VLAN only. 

jay_b
Getting noticed

I think what's happening here is when client VPN requests from Site B to Site A, Site A thinks this is from S2S and responding on S2S. I don't see any phase 2 traffic on pcap

jay_b
Getting noticed

jay_b_0-1646857807633.png

 This is what I am trying to achieve. Just did diagram in case there is confusion.

 

S2S tunnel is only between mgmt vlan 192.168.23.0/24 and 10.0.23.0/24

 

UserVLAN  172.10.0.0/16 is not included in s2s.

RaphaelL
Kind of a big deal
Kind of a big deal

Hi ,

 

"As soon as I disable site to site tunnel , client VPN works" this was a good indicator that you were in full tunnel and lan trafic from 172.10.0.0/16 is routed through the S2S. 

 

If thats not the case , do you have a firewall rule to allow the outbound trafic ( on Site B )

jay_b
Getting noticed

jay_b_1-1646866904127.png

 

 

@RaphaelL This is what I have in tunnel

 

I don't have firewall allow outbound rule traffic on site B. 

RaphaelL
Kind of a big deal
Kind of a big deal

Are you not using auto-vpn between your 2 Meraki products ? I'm so confused...

jay_b
Getting noticed

Sorry I got wrong screenshot. Ignore that SS.

jay_b
Getting noticed

@RaphaelL   I think I found solution. There was some old configuration it was blocking it. It's working now. You're absolutely right, S2S shouldn't affect client VPN. Thank you!!

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels