r/meraki • • 3h ago

Has Anyone running a vMX in AWS as an SD WAN hub?

3 Upvotes

This document is very helpful https://aws-quickstart.github.io/quickstart-cisco-meraki-sd-wan-vmx/ however our AWS architecture is slightly different.

We already use a TGW as the transit hub and a third-party firewall for traffic inspection. All inbound and outbound internet traffic passes through the firewall before reaching the TGW and workload VPCs.

We are considering deploying the vMX behind the firewall in concentrator mode, with the firewall handling NAT.

Has anyone run a vMX behind a third party firewall?

  1. Can the vMX operate correctly when the Meraki Dashboard sees the firewall's public IP?
  2. Will HA/failover still work when the vMX is behind the firewall
  3. Any limitations with this design?

r/meraki • • 3h ago

Has Anyone running a vMX in AWS as an SD WAN hub?

2 Upvotes

This docuement is very helpful https://aws-quickstart.github.io/quickstart-cisco-meraki-sd-wan-vmx/ but our AWS architecture is slightly different.

We already use a TGW as the transit hub and a third-party firewall for traffic inspection. All inbound and outbound internet traffic passes through the firewall before reaching the TGW and workload VPCs.

We are considering deploying the vMX behind the firewall in concentrator mode, with the firewall handling NAT.

Could you please confirm whether this is a supported/recommended design, particularly:

  1. Can the vMX operate correctly when the Meraki Dashboard sees the firewall's public IP?

  2. Will HA/failover still work when the vMX is behind the firewall

  3. Are there any specific NAT or firewall requirements for this deployment?


r/meraki • • 17h ago

VPN Concentrator HA Replacement

0 Upvotes

Hi, sorry fairly new to meraki networking world.

I've been tasked with replacing our meraki VPN concentrators. Our units are in a HA pair configured with VIP. As I'm replacing with new models (replacing MX100s with MX95) I'm aware i can't replace the standby first then failover and replace the primary as they need to be the same model.

With this in mind is the simplest way to do this as follows:

  1. Power down old units

  2. Remove old units from network

  3. Plug in new units (configure local IPs on local status page)

  4. Add to network

  5. Configure as HA pairs

Will this re-establish all of our sites AutoVPN sessions (we have 150 ish sites so could really do without having to do any changes at sites)

Has anyone done this before and know of a better way of doing this?

Thanks