The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About muhammed_haque
muhammed_haque

muhammed_haque

New here

Member since Dec 23, 2021

‎12-23-2021

Community Record

1
Post
0
Kudos
0
Solutions
Latest Contributions by muhammed_haque
  • Topics muhammed_haque has Participated In
  • Latest Contributions by muhammed_haque

Vmx in Nat Mode - not routing over vpn tunnel correctly

by muhammed_haque in Security / SD-WAN
‎12-23-2021 05:00 PM
‎12-23-2021 05:00 PM
Hi,   I am using a vmx in AWS in nat mode.   So MX -> VMX -> AWS Subnets   It seems that any traffic that has it source ip from a subnet defined as a static route and is enabled in vpn does not get routed back by the vmx over the site2site tunnel but egresses over the wan / internet interface.   So:   VMX - advertises 10.1.1.0/24  (via static route) MX advertises 10.100.0.0/24 both are seen in the site-2-site as local networks / remote vpn participants   so i ping from 10.1.1.1 -> 10.100.0.1 it gets natted over the interface using the public ip.  I was assuming any IP destination for a subnet in the vpn would be sent over the vpn tunnel and not natted out as being external to vpn.   This seems incorrect for me.   Can anyone confirm this behaviour as being correct ?   Thanks. ... View more
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Cookies
  • Terms of Use
© 2023 Meraki