i everyone, I’m working on a network setup where I have a Meraki MX firewall connected directly to the internet. Due to government security requirements, I need to add a second firewall between the LAN and a dedicated server segment. In this design: The Meraki MX 67 is the edge firewall connected to the internet. -> average client: 250 user The second Mx 85 firewall will sit between the LAN and the internal servers. Number of server 2 hp del 380 g10 with 2 vm erp system? From the server side, this second firewall will act as the "internet gateway" (via the MX). I’m concerned about NAT behavior, routing, and potential visibility issues (like client tracking, traffic shaping, etc.) when Meraki is not the final hop to the server. I noticed the “NAT Exceptions” / “Manual NAT” feature on Meraki, and I’m trying to understand if it can help in this case. Question: What’s the recommended best practice for this kind of deployment using Meraki MX?Any advice or design considerations to avoid double NAT issues, maintain security, and preserve Meraki’s visibility? Thanks in advance!
... View more