This is going to be a very specific question, but Meraki support has been giving me the run around without solid solutions, so I am going to ask here to see if anyone has any recommendations. My company is cutting ties from a MSP managing our MXs (SD-WANs) at all our locations (networks). We purchased all new devices and licenses to replace our current set-up. The goal is to replace all our current devices and licenses owned by the MSP with these new devices and licenses owned by my company. In addition, our MSP set our organization up as a per-device licensing model. We would like to switch to what the majority of users have, co-termination license model. From speaking with Meraki support, it is not possible to switch a an Organization, within an account, from a per-device license model to a co-termination license model, even if purchasing all new licenses for every device. The solution posited from support is to create an identical Organization, configured the same as the current Organization, and migrate all the devices over. After having done this and labbing the transition, I have found that Meraki requires VPN set-ups between Organizations to be created as "Non-Meraki VPN peers" even if they are both Meraki MX devices. They are not able to use the AutoVPN feature between Organizations. The problem I run into with this is that we are hoping to slowly migrate our Organization over one network at a time, as our I.T. team is centrally located and cannot be at all locations within my company at once. This creates the main problem; the "Non-Meraki VPN peer" does not account for MXs that use dynamic public IPs, and therefore have changing IPs. We have a few locations that are not static IPs, and I do not want to lose connectivity when they switch IPs. Our sites have to be able to VPN with each other. I admit that this could come down to me not fully understating the IKEv2 ability to connect via hostname. I've read the KBAs but it still is not clear to me how to use Local ID and Remote ID. In addition, this can get very complicated trying to handle the two Organizations with same subnets not conflicting with each other. Right now I feel stuck. I am not sure how to move forward with this migration. If anyone has any recommendations, I would greatly appreciate it.
... View more