MR Teleworker VPN with MX250 : Connectivity failed

jbvt
Comes here often

MR Teleworker VPN with MX250 : Connectivity failed

Dear Merakers,

 

I try to configure "MR Teleworker VPN" but, unfortunately, I have problems to join the VPN concentrator from distant MR access point. When I "test connectivity" I have only failed results.

 

MR connectivity.png

My network architecture is quite simple and is the following :

 

MR-MX.png

 

I tried some ICMP requests from tools page :

   - From DC-VPN (MX 250 concentrator), I can ping the Meraki MR33 with its private IP address,

   - From Meraki MR33, i can ping public IP address from MX250 router,

But

   - From Meraki MR33, i can't join DC-VPN (MX250 concentrator) private IP address.

 

Did I forget something for automatic NAT ? Do I add some routes on any equipments ?

 

I read the following documentation but I couldn't find any precisions : https://documentation.meraki.com/MX/Site-to-site_VPN/Automatic_NAT_Traversal_for_IPsec_Tunneling_bet...

 

So, I hope you can help me 🙂

Thanks a lot,

JB. 

6 Replies 6
PhilipDAth
Kind of a big deal
Kind of a big deal

Is the NAT to the MX250 a 1:1 NAT or is a a shared NAT being used by all outbound devices?

 

Does the MX250 report that it has sucessfully connected to the VPN registry?

jbvt
Comes here often

The NAT is shared by all outbound devices. No forwarding rules have been defined.

 

forwarding_rules.png

 

How can I can find the information about VPN registry ?

 

And, after analysis with .pcap files, is it normal that the AP try to join <private DC-VPN IP @> AND <public IP @1 > ?

PhilipDAth
Kind of a big deal
Kind of a big deal

>And, after analysis with .pcap files, is it normal that the AP try to join <private DC-VPN IP @> AND <public IP @1 > ?

 

Yes, it tries to join anyway it can.

 

Check out this guide to make your for Meraki hub is correctly registering.

https://documentation.meraki.com/MX/Site-to-site_VPN/Troubleshooting_VPN_Registration_for_Meraki_Aut...

jbvt
Comes here often

Thanks for the answer 🙂

 

But, I already have read this documentation.
The only manner to verify the VPN connectivity is use the Test connectivity button next to the selected Concentrator in Wireless > Configure > Access control > Addressing and traffic section.

 

So, I did some captures on all parts of the network and, to the side of the routed MX, it seems that there are no packets from the MR to DC-VPN.

PhilipDAth
Kind of a big deal
Kind of a big deal

Have you enable VPN concentrator mode on your MX250 under Site to site VPN?

1.PNG

On the MX250 under "Security & SD-WAN/VPN Status" does it show as being connected to a VPN registry, and does it show the APs as being connected?

 

2.PNG

jbvt
Comes here often

Thanks, I didn't understand that I have to configure site-to-site VPN even for Teleworker mode !

So, I activated it but I still have not any hubs connected.

 

vpn_status_site-to-site.png

What do you think could still be forgotten ?

 

Get notified when there are additional replies to this discussion.