Community Record
3
Posts
0
Kudos
0
Solutions
Jul 30 2024
3:28 AM
Hi All, Just wanted to run a few questions into the forum to see if anyone can help or has experienced the same issue: I currently have a vMX, configured within Azure with its own Static IP (Basic SKU) and no NSGs attached. The vMX is in Passthrough mode with a peered vNET hosting my servers and a route table. I am trying to configure the client VPN however there seems to be an issue when trying to connect a client machine to the VPN. Would the Client VPN Config work on the Meraki being in passthrough mode? I can see that IPsec phase 1 was successfully established between the vMX and client but was subsequently deleted for unknown reasons. If the Client VPN feature should work in passthrough mode, any help in advising how to setup the Azure side would be appreciated.
... View more
Labels:
- Labels:
-
Azure
-
Virtual firewall
Jun 12 2024
3:47 AM
Hi Josh, So currently the vMX is working in that it has 4 active site to site VPN tunnels to subsites to which a route table is set so that the private IP of the vMX is the the next hop. The Server vNET is peered with the hub which allows conenctions. It just seems as though it is just the client VPN traffic to which is not reaching the vMX. I can ping the vMX but cant tracert to the vMX. Just seems as though when I try and connect a laptop to the client VPN the PCAP shows no traffic from the Client VPN logs. Would it still be worth asking Microsoft whether their upstream azure config is forwarding the VPN ports?
... View more
Jun 12 2024
2:47 AM
Hi All, Just wondering if someone could point me in the correct direction as so far speaking to Cisco support has been a pain and no one seems to have any documentation on the vMX's. I currently have a vMX, configured within Azure with its own Static IP (Basic SKU) and no NSGs attached. The vMX is in Passthrough mode with a peered vNET hosting my servers and a route table. I am trying to configure the client VPN however there seems to be an issue when trying to connect a client machine to the VPN. Upon running a PCAP, I've noticed that it doesn't look like the vMX is receiving any traffic as there was no logs or connection attempts. Cisco Support have asked me to speak to Microsoft to ask if they are blocking VPN traffic even though this is a static IP with no NSGs or Firewalls. Also with regards to setting a new subnet in the Client VPN, would I need to create a vNET in Azure with the same subnet and peer this to the vMX vNET? Any help would be appreciated 🙂
... View more
Labels:
- Labels:
-
Azure
-
Virtual firewall