Cisco Secure Access Help

PDF

Cisco Secure Access Help

Configure Tunnels with Meraki MX

Want to summarize with AI?

Log in

Understand the methods that you can use to configure network tunnels between your Meraki MX and Secure Access.


You can configure tunnels from your Meraki MX to Cisco Secure Access, using one of the following methods:

  1. Single Manual Tunnel (non-Meraki VPN with no BGP).

  2. Primary and Secondary non-Meraki Tunnels with BGP.

  3. Integration of Meraki SD-WAN Auto-VPN Tunnels with Cisco Secure Access.


Prerequisites for Tunnels with Meraki MX

You can check firmware compatibility by navigating to Product Firmware Version Restrictions.


Caveats and Considerations

This section discusses important caveats and considerations associated with the Meraki Third Party (non-Meraki) VPN tunnel configuration to Secure Access.

  1. There is no stateful failover to a Secure Access secondary tunnel.

    1. The MX only supports active/cold standby to a single headend.

    2. Traffic from a failed site is required to reestablish the tunnel.

  2. Static routing and BGP are both supported. For more information, see the Prerequisites in Configure Tunnels with Meraki MX.

  3. Requires traffic to be generated from the LAN side of an MX through the non-Meraki VPN to establish connection.

    1. Remote application access on Meraki networks through an MX is not possible until traffic is initiated from the application side of the MX through the non-Meraki VPN.

    2. Traffic will also need to be consistently generated from the LAN side of the MX over each non-Meraki VPN to keep the tunnel from timing out.

  4. ECMP/Load balancing is not supported. Only a single IPSec tunnel is supported between a single Meraki network and a Secure Access network tunnel group.

  5. A unique public uplink IP is required for each network.

    1. The public uplink IP is used as the MX peer device IP, and this cannot be changed.

  6. In the Secure Access dashboard, the network tunnel group will display the status as Warning. This is because the Meraki network cannot build a standby tunnel to the Secondary Hub in the network tunnel group that is provided for intra-region redundancy.

Restrictions for health check

The integration between Cisco Secure Access and Meraki MX uses static routing IPsec tunnels. Meraki MX establishes primary and secondary IPsec tunnels to Cisco Secure Access, and leverages its built in uplink health checks to perform automatic failover between tunnels. This provides a resilient and high-availability configuration for branch connectivity.

These limitations apply to health checks:

  • Due to Meraki limitations in health check IP flexibility, only one tunnel group is supported in Private Access mode. If multiple Meraki MX devices need to connect to Secure Access for Private Access, you must either use BGP for dynamic routing, or configure static tunnels.

  • Only one Network Tunnel Group can support health checks and high availability. Additional tunnels operate without health monitoring or redundancy.


Supported Use Cases and Requirements

The following sections describe supported use cases for Meraki Third Party (non-Meraki) VPN tunnel configuration to Secure Access.

Remote Access VPN and ZTA

Single Manual Tunnel (No BGP):

  • The Meraki networks will need to be tagged.
  • Use the Umbrella IKEv2 configuration.
  • No default exit hub.
  • No spokes.

BGP Tunnels, see Cisco Secure Access Meraki BGP Configuration Guide.

Branch-to-Branch through Secure Access

One of the following options is required to enable Secure Access policy enforcement to apply to branch-to-branch communication. Otherwise, all traffic will traverse Meraki AutoVPN between Meraki networks directly.

  1. Each network hosting applications is in a separate org; or
  2. All networks are in a single org. Note: If this is the case, contact Support to have hub-to-hub communication turned off.

Secure Internet Access with Non-Meraki VPN

The following are requirements for this configuration:

  • No AutoVPN default route.
  • Local route configuration 0.0.0.0/0.

Step 1: Add a Network Tunnel Group in Secure Access

Secure Access enables fast, reliable, and secure private network connections to your applications through IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels.

Tunnels and tunnel groups are core concepts in managing connections between your data centers and Cisco Secure Access. A network tunnel group provides the framework for establishing tunnel redundancy and high availability. Connect tunnels to the hubs within a network tunnel group to securely control user access to the Internet and private resources.

Procedure

  1. Follow the steps in Add a Network Tunnel Group.

  2. Make note of the Tunnel ID and Passphrase you enter when configuring the network tunnel group. These values are needed when you configure your Meraki IPsec tunnel.

    Note
    Secure Access provides the option to download a CSV file with the network tunnel group details.
  3. Remember to select Static routing under routing options.

What to do next

The new network tunnel group appears in the Secure Access dashboard as Disconnected, and with the Primary Hub and Secondary Hub status showing as Hub Down. The network tunnel group status is updated once it is fully configured and connected with Meraki MX.


Secure Access dashboard displaying the status of the new network tunnel group, including the primary and secondary hubs

See the Verification and Troubleshooting section for additional information about how to evaluate the network tunnel group status.


Step 2: Configure a Tunnel in Meraki MX

Configure a Meraki Third Party (non-Meraki) VPN tunnel to connect a Meraki MX/Z4 series device to Cisco Secure Access.

Procedure

  1. In the Meraki MX dashboard, navigate to the Organization > Monitor > Overview page.

    If the page is not expanded by default, expand the Networks list by clicking the left-facing arrow at the top of the network list.


    Navigation path to the Overview page
  2. Select the desired network from the networks Name list. Select only the network that will connect to the Secure Access Network Tunnel Group.


    Networks section with an option to select the desired network toconnect to the Secure Access network tunnel group
  3. Add a Network tag to the selected network. Select the Tag dropdown menu from the top left. A tag can be created by typing into the field and then clicking Add.

    Note
    It is recommended that the same name is used for the Meraki Network Tag as the Secure Access Network Tunnel Group.

    Adding a network tag to a selected network
  4. While in the Meraki dashboard, navigate to Security & SD-WAN > Site-to-site VPN, and choose Hub (Mesh).


    Site-to-site VPN page with an option to select the VPN tunnel type
  5. Next, in the same section, find the VPN settings and choose Enabled for the VLANs that will use the new Secure Access network tunnel group.


    VPN Settings page with an option to enable VLANs to use the new Secure Access network tunnel group
  6. Scroll down to find Organization-wide settings to locate the Non-Meraki VPN Peers section. Click Add a peer and then add the tunnel ID and tunnel passphrase that you created in Step 1: Add a Network Tunnel Group in Secure Access.

  7. Configure the IPsec parameter settings:

    • Name—Provide a meaningful name for the tunnel.

    • IKE Version—Select IKEv2.

    • IPsec policies Choose the predefined Umbrella configuration; see Supported IPsec Parameters.


      Configuration screen for settings IPSec parameters
    • Public IP—IP address to connect to Secure Access Network Tunnel Group Primary Data Center IP.

    • Local ID—The Primary Tunnel ID for the Network Tunnel Group.

    • Remote ID—Leave this blank.

    • Private subnets—There are 2 common configurations for Private Subnets:

      • If the desired behavior is to use Secure Internet Access and Secure Private Access to access applications on tunnel-enabled vlans/subnets, then the only entry here should be 0.0.0.0/0. This will route all traffic to Secure Access for either Secure Internet Access, Remote Access VPN, or ZTA clients.
      • If only Remote Private Application access is required, then all subnets that are used by the Secure Access infrastructure must be entered:
        1. CGNAT 100.64.0.0/10
        2. RA VPN and Management IP Pool subnets.
    • Preshared secret—This is the Passphrase for the Network Tunnel Group created in Secure Access.

    • Availability—Enter the Network tag you defined earlier for the MX appliance that builds the tunnels to Secure Access.

    Do not leave this field blank. Ideally this field should match the Network tag entered in Step 3 above. Leaving this field blank, "All Networks", or entering a tag that is associated with multiple networks could cause one or more tunnels to become unstable. This could lead to unexpected behavior and cause an NMVPN tunnel to not be established.

    Tunnel configuration for Meraki MX
  8. Click Save.

    Upon completion of these steps, you should have a functioning tunnel routing your traffic as intended.


Verification and Troubleshooting

Procedure

  1. The Secure Access Network Tunnel Group will move from Disconnected Status to Warning. This change could take several minutes and may require a test ping described in step 2 below.


    Network Tunnel Groups page displaying the status transition of the Secure Access Network Tunnel Group from Disconnected to Warning
    Note
    Network Tunnel Group Status

    The Network Tunnel Group will never move from a Warning status to Connected. This is because the Network Tunnel Group is designed to have a Primary and Secondary tunnel connected to each Hub for failover. Traffic will pass to the Primary Hub even if the Network Tunnel Group status is Warning.

  2. Run ping tests from the new VLAN to the internet. For more information, see Using the Ping Live Tool.

  3. Check the status of the VPN tunnel. For more information, see VPN Status Page.

  4. Follow the VPN troubleshooting procedures. For more information, see Troubleshooting Non-Meraki Site-to-site VPN.

    Note
    Cisco Meraki does not support policy based routing. It is not possible to do client side routing to determine if specific traffic belongs inside or outside the tunnel. However, it is possible to choose if an entire VLAN is tunneled to Secure Access.

Optional Configurations