Meraki MX400 NAT Question
-
@dafyre said in Meraki MX400 NAT Question:
Is there a way to set this up on the Meraki? I have never seen a "business class" firewall unable to do this.
Well, due to market position, Meraki isn't really "business class". Business class has to be a moving target as defined by the market. And Ubiquiti, due to their pricing, kind of define the entry point of business class. Anything that falls below what a $65 home router can do, is a hobby product at best. And Meraki falls way below that point. Meraki, regardless of who owns it or how expensive it is, literally falls below the "home line" for a large percentage of people here.
-
I have a client with a MX64 and it looks to me like under Security appliance -> Appliance Status -> Uplink you would configure your WAN interface for the public IPs.
Then under Security appliance -> Addressing & VLANs Add a static route to take all the traffic for each VLAN and tell it which one of the public IPs to use going out.
-
@Mike-Davis said in Meraki MX400 NAT Question:
I have a client with a MX64 and it looks to me like under Security appliance -> Appliance Status -> Uplink you would configure your WAN interface for the public IPs.
Then under Security appliance -> Addressing & VLANs Add a static route to take all the traffic for each VLAN and tell it which one of the public IPs to use going out.
Hey Mike,
Thanks for the heads up. I'll have to see if we can work that out!
-
@Mike-Davis Thanks Mike! I talked to Meraki support yesterday and that's exactly what the tech told me. I was just surprised that it was the basically the only solution.
-
I had the same issue, same solution before Cisco owner meraki.
Cisco also has a habit of flat dropping features and whole products after acquisition. I had an engineering firm who was floored when they dropped wan caching the other year. They bacially said "it doesn't work very well so we quick". Same thing with rebadging of qnap devices. Same thing with Linksys. Same thing with Cisco webmail, which I actually loved. I could go on...
-
@Markferron said in Meraki MX400 NAT Question:
@Mike-Davis Thanks Mike! I talked to Meraki support yesterday and that's exactly what the tech told me. I was just surprised that it was the basically the only solution.
Behind the scenes, those settings are just creating Source NAT (SNAT) and Destination NAT (DNAT) rules for each subnet.
That is simply how NAT works. I can show you how to do the same thing on an EdgeRouter.
You always assign the ISP IP block to your WAN and then use SNAT/DNAT to tell things where to go internally.
-
@JaredBusch said in Meraki MX400 NAT Question:
@Markferron said in Meraki MX400 NAT Question:
@Mike-Davis Thanks Mike! I talked to Meraki support yesterday and that's exactly what the tech told me. I was just surprised that it was the basically the only solution.
Behind the scenes, those settings are just creating Source NAT (SNAT) and Destination NAT (DNAT) rules for each subnet.
That is simply how NAT works. I can show you how to do the same thing on an EdgeRouter.
You always assign the ISP IP block to your WAN and then use SNAT/DNAT to tell things where to go internally.
Sadly, they're stuck with the Meraki for the time being.
-
@dafyre said in Meraki MX400 NAT Question:
Sadly, they're stuck with the Meraki for the time being.
What makes them stuck?
-
@dafyre said in Meraki MX400 NAT Question:
@JaredBusch said in Meraki MX400 NAT Question:
@Markferron said in Meraki MX400 NAT Question:
@Mike-Davis Thanks Mike! I talked to Meraki support yesterday and that's exactly what the tech told me. I was just surprised that it was the basically the only solution.
Behind the scenes, those settings are just creating Source NAT (SNAT) and Destination NAT (DNAT) rules for each subnet.
That is simply how NAT works. I can show you how to do the same thing on an EdgeRouter.
You always assign the ISP IP block to your WAN and then use SNAT/DNAT to tell things where to go internally.
Sadly, they're stuck with the Meraki for the time being.
Man, for the price of a license refresh you could get an even more powerful router from another vendor.
-
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
@JaredBusch said in Meraki MX400 NAT Question:
@Markferron said in Meraki MX400 NAT Question:
@Mike-Davis Thanks Mike! I talked to Meraki support yesterday and that's exactly what the tech told me. I was just surprised that it was the basically the only solution.
Behind the scenes, those settings are just creating Source NAT (SNAT) and Destination NAT (DNAT) rules for each subnet.
That is simply how NAT works. I can show you how to do the same thing on an EdgeRouter.
You always assign the ISP IP block to your WAN and then use SNAT/DNAT to tell things where to go internally.
Sadly, they're stuck with the Meraki for the time being.
Man, for the price of a license refresh you could get an even more powerful router from another vendor.
A better one
-
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
-
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
-
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Can't save something that's already spent.
-
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Yepp. AFAIK, the license and maintenance were all rolled together. But this was after I left, so I dunno.
-
@Dashrender said in Meraki MX400 NAT Question:
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Can't save something that's already spent.
But you can save against future costs. For instance a 3-year renewal.
-
@coliver said in Meraki MX400 NAT Question:
@Dashrender said in Meraki MX400 NAT Question:
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Can't save something that's already spent.
But you can save against future costs. For instance a 3-year renewal.
Sure, but that's years from now...
-
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Why? If you are saving them money, what would make them unhappy?
-
@Dashrender said in Meraki MX400 NAT Question:
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Can't save something that's already spent.
But what's already spent?
-
@dafyre said in Meraki MX400 NAT Question:
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Yepp. AFAIK, the license and maintenance were all rolled together. But this was after I left, so I dunno.
Ah, well two things...
- Is it STILL saving them money? Check it out.
- It should make them unhappy with whoever selected the Meraki, not you.
-
@Dashrender said in Meraki MX400 NAT Question:
@coliver said in Meraki MX400 NAT Question:
@Dashrender said in Meraki MX400 NAT Question:
@coliver said in Meraki MX400 NAT Question:
@dafyre said in Meraki MX400 NAT Question:
Gotta convince the bean counters, and they'll be unhappy for the next 2 to 3 years, lol.
Even if you're saving them money?
Can't save something that's already spent.
But you can save against future costs. For instance a 3-year renewal.
Sure, but that's years from now...
In the meantime, saving against additional technical debt risks and unnecessary effort.