subnets in site to site vpn

Vishal07
Getting noticed

subnets in site to site vpn

Hello All,

 

I have created site to site vpn between Meraki (location A) and non meraki peers (location B) and its working as expected. However now i need to add subnets of (location C) having Meraki Mx to flow via Location A and then routed to location B using same above created site to site vpn. Here i have added subnets of location C into location A and B tunnel. Can anyone tell me what else i have to configure here ?

 

Do i need to configure tunnel between Location A and C ? or it will configure via auto vpn ?

4 Replies 4
Vishal07
Getting noticed

done via exit hub on location C

alemabrahao
Kind of a big deal
Kind of a big deal

Between sites A and B, you have configured a non-Meraki VPN or an Auto VPN.

If it's an Auto VPN, you only need to advertise the networks, and site C will automatically receive the routes. However, if it's a non-Meraki VPN, you need to configure a tunnel with site C, because non-Meraki VPNs don't participate in SD-WAN.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

This is actually getting a little bit more complicated now.  My head is still spinning with all the options.

 

You can now do this if you use BGP over IPSec (over a VTI).

https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Site-t...

 

"BGP peering over IPsec VPN tunnels can be enabled on the Meraki Security Appliance. This unlocks new dynamic routing solutions, including routing between AutoVPN and IPsec VPN peers"

 

 

ALSO, because 19.1 added VTI support, and you use static routes to route traffic over a VTI, you should be able to redistribute that over AutoVPN as well.

 

I have not used or tested either of the above configs.

alemabrahao
Kind of a big deal
Kind of a big deal

To be honest, I'm aware of those possibilities, but I haven't considered them because I haven't had time to test them yet.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.