I have a situation where I want to replace my ASA with our MX68 "HUB" to what will be approx 300 AutoVPN connections (two pictures of ASA attached - I need to replicate this on my MX68) but one of the things the ASA has is a Site-to-Site VPN to another company which we use to connect to some cell routers in the field. Part of that connection is that we must NAT our traffic destined for 10.80.20.224/27 (Cell Routers) to come from source 172.16.7.112/29. Our normal subnet is 192.x.x.x and our VPN subnet is 192.x.xx.x I'm trying to plan out pulling the ASA to make the MX68 our firewall but I can't see where I would create these rules related to the non-meraki s2s? Alternatively - all 300 Z3s connected to our MX68 will have a single subnet we would like to reach directly from our main MX68 LAN. This works if I'm on the MX68 via clientVPN or locally. If i keep my ASA as my firewall what sort of rules would I have to create to route particular traffic from behind the ASA to these Meraki subnets? Several static routes basically so if we are on the ASA LAN and we want to hit a Meraki subnet the ASA sends that traffic to the MX68? *Email support said call in. I have been on hold for 45 minutes to talk to a human so here I am asking you good folks for assistance! We are a small company with a lot of "sites" we are putting these Z3s at. We enjoy the simplicity of the dashboard vs. the ASA and would be in a better position to manage our networks if we could stay in Meraki, I think.
... View more