I've been tasked to prepare an MX250 to provide "WAN" access to an MX64, and this has me wondering, will it work? I'm not a network expert but I know the basics and manage a handful of networks, so any input or corrections would be greatly appreciated. Essentially the team that owns the MX64 would like to use our internet connection, MS, and MR devices to support their team while they work within our site. So far I've taken the below steps: Created a separate VLAN we intend to use between the two MX's to supply them a WAN connection. The external team has set the MX64 WAN port to DHCP and will plug into a port on our MX250 set to that dedicated VLAN. Created a new SSID dedicated to this team. We intend to use VLAN tagging on this to keep them separate from our clients. Walking through this setup has me asking a few questions that I'm trying to get answered before we try this out: Would their client devices be able to use our MRs if we plugged their MX64 LAN port into one of our MS ports? I assume we would set the only allowed VLAN on that trunk port to whatever VLAN they decided to setup on their MX64 for clients. Do I need to create the same VLAN on our MX250 to make firewall rules? They will be creating the VLAN on their MX64 to handle DHCP for their clients, but I can't seem to make a rule referencing a VLAN not present on our device. Will they be able to set up their own site-to-site VPN on their MX64? I don't see why not, but I could see Meraki not liking that. Once we know what VLAN they will be using for clients we plan to make firewall rules to deny any traffic between their network and ours. If anyone has experience with this type of setup I'd love to hear what other steps were taken for security purposes, or overall quality for both networks to coexist.
... View more