I'm looking to use a Meraki router downstream in order to subnet our various branch offices that are connected via an MPLS like Private WAN (AT&T ASEoD product). The MX's Internet port is currently connected to a switch and is receiving an IP address that matches the IP scheme of the devices currently on that circuit. Devices behind the MX are able to communicate to devices back upstream in my Primary subnet just fine. However, devices in the primary subnet are unable to reach devices behind the MX. If I attempt to ping a device I see that it is trying to reach the device on the right IP but there is no response. I have a route setup on our primary router that points all requests to the MX subnet to the IP address on the WAN interface. I feel like this is more a firewall issue more than anything because I setup a Sonicwall device in almost the same exact manner with the same exact results. Except I was then able to on the remote branch Sonicwall create a firewall rule that allowed all connections from any source to come through. Since the WAN port on the branch Sonicwall is connected to a private WAN already it doesn't really need to firewalled, the edge router/firewall is dealing with that. What do I need to do to allow connections from my primary and for that matter all the other branch subnets to be able to reach devices behind the MX?
... View more