Hello! We are currently using an MX60 to concentrate an SSID for remote sites using "VPN: tunnel data to a concentrator". I'm interested in changing the subnet on which the MX60 reside, but I'm having trouble understanding exactly what will happen if I do so. The main thing which is confusing me is the original design (which I didn't do), which has the DHCP server assign the clients using the tunneled SSID an IP address on the 10.44.44.0/24 subnet. I'm suspecting that this design simply didn't consider the monitoring aspect. Been reading this: https://documentation.meraki.com/MR/Client_Addressing_and_Bridging/SSID_Tunneling_and_Layer_3_Roaming_-_VPN_Concentration_Configuration_Guide For starters, I'm a bit confused about "3) Optional:", there is no list of VLANs displayed on the page where I configure the SSID to tunnel to the MX60, there is however a field where I can manually enter a VLAN ID (simply a mistake in the documentation?). I'm also however, unsure what to expect from what I think is the solution, so any help or clarification would be much appreciated. Edit: I found this post which also helps in clarifying: https://community.meraki.com/t5/Security-SD-WAN/VLAN-Config-on-Singled-Armed-concetrator-for-SSID-Tunneling/m-p/66929#M16845 Consider above network sketch, everything is currently set up this way with the MX60 operating in Passthrough mode. The MX100 is acting gateway for the SSID and forwards DHCP requests to the central resources etc. The only thing which is not currently active in the sketch is the "green subnet", this is what I'm trying to achieve. The reason for the change is monitoring, which we cant do for the 10.44.44.0/24 subnet. If I tag the SSID at Remote site X with vlan 100 on the page where I configure it to tunnel to the MX60, what exactly will happen. Is the traffic tagged locally on Remote site X, or when the traffic exits the concentrator? If it's tagged exiting the concentrator (which I'm suspecting), if I then change the switchport which connects the MX60 from access vlan 100 to a trunk and permit both vlan 10 and 100. Following I place the MX60/MX100 on the new "green subnet"/vlan 10 (with MX100 still operating as .1 in Vlan 100). Will the user traffic still continue to flow as currently?
... View more