Cisco Secure Access Help

PDF

Cisco Secure Access Help

Enroll Meraki SD-WAN Sites with Meraki Auto-VPN Tunnels

Want to summarize with AI?

Log in

Understand how to enroll Meraki SD-WAN sites with Secure Access using Meraki auto-VPN tunnels.


Cisco SASE (Secure Access Service Edge) securely connects users, devices, and applications from anywhere with minimal effort. Meraki Auto-VPN tunnels can be enrolled to seamlessly connect Meraki sites as network tunnel groups in Secure Access.

For complete documentation of Cisco SASE with Cloud Managed Meraki SD-WAN and Secure Access, refer to SASE in Meraki documentation.

Before you begin

Before you begin, review the following prerequisites.

  • A Cisco Meraki MX/Z4 device (running Security and SD-WAN (MX,Z) version 19.1+ firmware). For more information, refer to Meraki Security and SD-WAN (MX,Z) Features Directory.

  • A valid Meraki SD-WAN license or subscription.

  • A valid Cisco Secure Access subscription.

  • An integration established between Secure Access and Security Cloud Control. For more information, refer to About Cisco Security Cloud Control.

  • A Cisco SASE integration established between Cloud Managed Meraki SD-WAN and Secure Access. For more information, refer to Integrate Cisco SASE with Meraki SD-WAN in Secure Access Integrations documentation and SASE in Meraki Integrations documentation.

Procedure

  1. In the Meraki dashboard, navigate to SASE > Sites.

    1. Click + Add Site.
    2. In the Assign regions to networks menu, select an unassigned Meraki branch.
    3. Click the Assign a region dropdown list and select a Secure Access region. The branch will now be listed under Newly assigned regions.
    4. Click Next.
    5. Under Review and confirm, verify your Meraki branch selection, then click Save and Finish.
      The Sites table displays the newly enrolled site.
    6. To verify the enrollment and monitor VPN status, navigate to Security & SD-WAN > Monitor > VPN Status. This page shows the cloud hubs and their VPN registry information.
  2. In Secure Access, navigate to Connect > Network Connections > Network Tunnel Groups.

    1. Search for your Meraki site by region to verify that the Auto-VPN tunnel connection created a network tunnel group in Secure Access.
    2. Click the tunnel group name to view details. The Meraki site name will match the Secure Access network tunnel names in the network tunnel group.
    For more information, refer to View Network Tunnel Group Details.

What to do next

Configure Access Policy

Once the Auto-VPN tunnels are connected, Meraki sites appear as network tunnel groups in Secure Access. Protect one or more Meraki sites by configuring Secure Access private and internet access rules.

For more information, refer to Manage the Access Policy in Secure Access documentation and Cisco SASE: Policy in Meraki documentation.