Firewall swap/VPN concentrators

RANT
Comes here often

Firewall swap/VPN concentrators

Currently running a pair of MX100s in passthrough mode, sitting inline between my internet firewalls and core switches (utilizing IPS functioanlities). Purchased an MX105 pair, which are currently installed in passthrough mode, with single leg connection on WAN port to core switches. The 105s are not yet set to accept VPN connections.

 

Looking for suggestions for the following end results (with minimal downtime):

1. Transition Meraki VPN connections from the 100s to the 105s (~200 networks)

2. Remove 100s and insert 105s inline to internet firewalls.

3 Replies 3
cmr
Kind of a big deal
Kind of a big deal

@RANT are the MX105s in passthrough mode, or single ended concentrator mode?

RANT
Comes here often

They are currently in single-ended concentrator network config, but i want to put them inline.

cmr
Kind of a big deal
Kind of a big deal

I think you will have to do a cold swap.  It involves removing the existing MXs from the network and then adding the new.  You will need to re-set any static IPs if you have set them on interfaces and re-enable the site to site VPN, but pretty much everything else moves over.  The only other thing that normally needs doing is mapping old to new ports, but you are not in routed mode with VLANs, so that shouldn't be needed AFAIK.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels