Hi guys, A customer wants to implement Meraki SD-WAN to connect several Headquarters/DCs of different countries, each with its own WAN topology. There are countries with MPLS, Internet, or both between HQ/DC and branches, the Design should be versatile. From a High-Level standpoint, I would consider any country as a hub-and-spoke topology, all the spokes should communicate with their hub through Internet, MPLS, or both, and all the hubs communicate through Internet. First question: would it be ok to implement a VPN Mesh inside countries if there are only a few spokes? Suppose to have HQ/DC and Branches connected through both MPLS and Internet connections. In the HQ/DC, we have dedicated firewalls at the edge and the MXes deployed in a One-Arm VPN Concentrator fashion, as Cisco suggests for Hubs. Let's suppose that in the Branch the MXes should provide both the VPN and the Security/Gateway functions. 1 - Would be the MXes in the HQ able to bring up multiple VPNs through the single-arm toward the internal transit? Should they be placed to the edge, in front of Firewalls, in a Dual-Arm fashion (The first WAN connected to the MPLS transit and the second WAN connected to the Internet transit)? 2 - Would be possible to deploy MXes in the Branch in a Dual-Arm fashion (as supposed before)? 3 - Suppose we have edge firewalls in the Branch, with the same logical topology as the HQ, would be right to use a One-Arm deployment also there (If it works as supposed in the first point)? Thanks all in advance for the support, Davide
... View more