Question on VPN Exclusion with SD-WAN + license

Solved
ToryDav
Building a reputation

Question on VPN Exclusion with SD-WAN + license

When using an MX as a branch spoke connecting to a concentrator in the data center, we need to implement a full-tunnel design to send all wired traffic on the network through the Corperate firewalls located in the data center.

However, I also have a requirement to send the local office wifi traffic (both office user and guest) out to the internet directly at the spoke level.

When I choose to send the default route to a spoke MX creating a full tunnel, am I correct that I then need an SDWAN + license to enable Local Breakout for a couple of wifi vlans to not use the default route through the tunnel?

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

All MX licenses support local Internet breakout based on port/IP

https://documentation.meraki.com/General_Administration/Licensing/Meraki_MX_Security_and_SD-WAN_Lice...

 

Only layer 7 (application) based local Internet breakout requires the sd-wan plus license

View solution in original post

3 Replies 3
Brash
Kind of a big deal
Kind of a big deal

All MX licenses support local Internet breakout based on port/IP

https://documentation.meraki.com/General_Administration/Licensing/Meraki_MX_Security_and_SD-WAN_Lice...

 

Only layer 7 (application) based local Internet breakout requires the sd-wan plus license

ww
Kind of a big deal
Kind of a big deal

You could use source based default route for this. (In case you dont advertise the default route in the vpn globaly)

 

https://documentation.meraki.com/MX/Networks_and_Routing/Source_Based_Default_Routing

RaphaelL
Kind of a big deal
Kind of a big deal

Wouldn't selecting these vlans and put them 'vpn off' already solve that issue ?

 

RaphaelL_0-1703197861091.png

 

Get notified when there are additional replies to this discussion.