The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About pwallace10
pwallace10

pwallace10

Comes here often

Member since Mar 4, 2021

‎04-21-2021

Community Record

2
Posts
0
Kudos
0
Solutions
Latest Contributions by pwallace10
  • Topics pwallace10 has Participated In
  • Latest Contributions by pwallace10

Re: VPN Between MX250 and PF Sense Firewall with Multiple subnets

by pwallace10 in Security / SD-WAN
‎03-04-2021 12:26 PM
‎03-04-2021 12:26 PM
Hi, thanks for the input..   Its not NAT or rules, they logs are clear, also a tract to the LAN IP of the MX got into the tunnel, the trace to anything else does not.   It has to be that the PFS box is not getting the advertised routes or I need to statically add a route to the other LAN subnets but I cant on PFS.  Any other ideas ? ... View more

VPN Between MX250 and PF Sense Firewall with Multiple subnets

by pwallace10 in Security / SD-WAN
‎03-04-2021 06:15 AM
‎03-04-2021 06:15 AM
I am hoping someone can spot something I am missing... We have a corporate MX installation with a MX250 at the Data Centre, the spokes are a mix of 67's and 100's which all connect via the Dashboard defined VPN's.   I have a few small sites for which we did not but MX's, I want to use the PF Sense firewall appliances that we have there. The VPN part is done it was simple enough with the non-meraki VPN config in the dashboard.   The issue is that we do not ever terminate our routers onto the local LAN, we always make use of a Isolation LAN, so in the case of the MX250 the LAN address is 10.10.10.9/29 and the PFS box its 10.20.92.2/28   The VPNs are setup to have the branch LAN subnets as P2 and from the DC I can ping anything on the branch side.  My problem is the other way, from the branch I can only ping the MX LAN interface. None of the other traffic goes into the PFS firewall IPSEC tunnel.   The MX seems to advertise the remote side inward but the PFS box doe snot seem to have a route for anything except what is in the P2 of IPSEC.   I see on the PFS I can create a routed VTI but on the MX I cant terminate a routed VTI.   Has anyone battled with something like this, what is the work around or what am i missing?   There has to be a way to route additional subnets into the PFS box VPN...   Peter ... View more
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Cookies
  • Terms of Use
© 2023 Meraki