Can't connect MX with Site to Site VPN

Dipen
Getting noticed

Can't connect MX with Site to Site VPN

We are configuring MX and did create Site to site VPN tunnel between 2 MX's but some how under VPN status they are still RED and none of the traffic is being sent to each other. We can access machines through teamviewer that means they are connected with the internet but because of the VPN they can't access drives and profiles. 

 

We have 2.1 network which is where our servers are and we have 3.1 network our users are. (Both are at the Separate locations).

 

Does anyone know why VPN status is RED or what can we do to make it green?

6 Replies 6
cmr
Kind of a big deal
Kind of a big deal

@Dipen can you access the local status pages of each MX, is everything there okay?  Also can you please explain what a 2.1 and 3.1 are?  On the dashboard what does the VPN status page for each appliance say?

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Dipen
Getting noticed

@cmrYes i can access Local page the appliance is online. We have two MX device first one has set vlan to be as 192.168.2.1 and another MX device in different location set as 192.168.3.1.

 

Now i conifgured Site to Site VPN inorder to access things, but when on VPN status it shows disconnected on 192.168.3.1 MX. It seems to me like device can't connect with Cisco cloud.

 

However 192.168.2.1 can connect to cloud.

cmr
Kind of a big deal
Kind of a big deal

Do the two MXs have different public IPs?  Does the local status page of the MX with a local IP address of 192.168.3.1 look okay, if it does then it is talking to the Meraki dashboard.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Dipen
Getting noticed

@cmryes they have different public ip because they are at different location lets say for example one in NY and other in LA... Also appliance is online i can see white light on MX and on the dasboard as well it says online. Still can't access another location.

Dipen
Getting noticed

@cmr 

Dipen_3-1636767228458.png

 

Ryan_Miles
Meraki Employee
Meraki Employee

To confirm on the static WAN IP's. They both show in the same subnet, but one has a /24 mask and the other a /29. Is that correct or is there a typo on the /24 one?

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels