Hi all, I´d like to ask you some questions about a MPLS Failover to Meraki Auto-VPN design! Note: please do not measure the sensibility of the deployment, I`m just thinking and try to get a better technical understanding how things could/would go 🙂 In my example topology two sites (Spokes) with MX security appliances (each in NAT-Mode) are connected over an MPLS connection as well as the Meraki site-to-site auto-VPN over Internet to their HQ-MX (Hub) also acting in NAT-Mode. The MPLS links are connected to LAN interfaces to prevent NATing of traffic. All Traffic (Corporate + Web) should utilize the MPLS connection, until a failure occurs, in which case the traffic will be sent over the Meraki auto-VPN. So in both cases the Internet Access should break out centrally! In BO-01 is a File-Server located which has to be accessed from the Internet via a Public-IP - which is 1:1 mapped on the HQ-MX... Q1-) when using the LAN Interfaces for the MPLS connection, is it possible to influence traffic (e.g. QoS re-marking, ACLs, etc.) - or would it be better for these requirements to use NO-NAT on the 2nd WAN-Interface which is yet a beta feature? Q2-) is it even possible to use the Hub MX (in NAT-Mode) to terminate the Auto-VPN Tunnels on the specified WAN-Link and also use that WAN-Interface for PAT the IP-Traffic from the Branch-LANs with all possible functionalites e.g. L3/L7-Firewall Rules, Content-Filtering, etc. without problems? Q3-) if the MPLS connection of the BO-01 fails and all traffic is routed over the VPN-Tunnel; is access to the file server still possible in this case or are there perhaps problems with intra-interface traffic or anything other?
... View more