Unable to connect to resources via site to site vpn using Meraki VMX100

%3CLINGO-SUB%20id%3D%22lingo-sub-1803974%22%20slang%3D%22en-US%22%3EUnable%20to%20connect%20to%20resources%20via%20site%20to%20site%20vpn%20using%20Meraki%20VMX100%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1803974%22%20slang%3D%22en-US%22%3E%3CP%3EHi.%3C%2FP%3E%3CP%3EWe%20have%20established%20a%20site%20to%20site%20vpn%20between%20our%20Azure%20Meraki%20vmx100%20(managed%20Azure%20service%2Fapp)%20and%20our%20on%20premise%20mx64.%20Although%20the%20tunnel%20is%20up%2C%20running%20and%20passing%20traffic%2C%20I%20can't%20rdp%20to%20my%20resources%20in%20Azure.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20spoke%20to%20Cisco%20and%20they%20confirmed%20my%20vmx100%20is%20configured%20correctly%20and%20traffic%20is%20reaching%20the%20Azure%20resources%20however%20traffic%20from%20Azure%20VM%20is%20not%20being%20passed%20back.%20I%20need%2C%20specifically%2C%20to%20be%20able%20to%20rdp%20to%20the%20VMs%20in%20Azure.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20set%20up%20routes%20but%20obviously%20they%20are%20not%20correct%20or%20else%20this%20would%20be%20working!%3C%2FP%3E%3CP%3EI%20have%20also%20set%20up%20network%20security%20groups%20allowing%20inbound%20and%20outbound%20traffic%20to%20port%203389%20(rdp).%20When%20I%20run%20the%20connection%20test%20it%20tells%20me%20that%20access%20has%20been%20granted.%20However%2C%20when%20I%20try%20to%20rdp%20using%20the%20MS%20rdp%20client%2C%20I%20get%20the%20generic%20unable%20to%20connect%20message.%20When%20I%20try%20to%20rdp%20using%20the%20Azure%20rdp%20client%2C%20it%20tells%20me%20another%20computer%20has%20disconnected%20my%20session%20which%20is%20not%20possible%20since%20I'm%20the%20only%20one%20setting%20this%20up.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20out%20there%20that%20has%20successfully%20set%20up%20a%20Cisco%20Meraki%20VMX100%20in%20Azure%20and%20is%20able%20to%20access%20the%20resources%20in%20Azure%20behind%20the%20vmx100%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3ESharyn_S%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1804570%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20connect%20to%20resources%20via%20site%20to%20site%20vpn%20using%20Meraki%20VMX100%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1804570%22%20slang%3D%22en-US%22%3EHi%20Sharyn_S%2C%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20you%E2%80%99re%20well.%3CBR%20%2F%3E%3CBR%20%2F%3ECan%20you%20confirm%20your%20route%20tables%20and%20that%20they%E2%80%99re%20connected%20to%20the%20correct%20subnets%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%E2%80%99m%20not%20familiar%20with%20the%20Meraki%20vmx%20specifically%20but%20will%20try%20to%20assist.%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1804698%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20connect%20to%20resources%20via%20site%20to%20site%20vpn%20using%20Meraki%20VMX100%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1804698%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F840957%22%20target%3D%22_blank%22%3E%40IrishTechie%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20route%20tables%20look%20correct.%20I've%20attached%20a%20network%20diagram.%20If%20you%20look%20at%20the%20diagram%2C%20it's%20the%20part%20at%20the%20top%2C%20in%20azure%2C%20where%20the%20two%20way%20connection%20is%20not%20happening.%20The%20Azure%20resources%20are%20not%20passing%20traffic%20back%20to%20the%20vmx.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAccording%20to%20cisco%2C%20there%20is%202%20way%20communication%20between%20the%20azure%20vmx%20and%20the%20on%20premise%20Meraki%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1804789%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20connect%20to%20resources%20via%20site%20to%20site%20vpn%20using%20Meraki%20VMX100%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1804789%22%20slang%3D%22en-US%22%3EThanks%20for%20sharing%20the%20diagram.%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20if%20I%20read%20it%20right%20Your%20EliteU%20subnet%20should%20have%20a%20route%20table%20attached%20that%20looks%20a%20bit%20like%3A%3CBR%20%2F%3E%3CBR%20%2F%3E-%200.0.0.0%2F0%20%26gt%3B%20Next%20Hop%20Appliance%3A%2010.0.9.4%3CBR%20%2F%3E%3CBR%20%2F%3ECan%20you%20ping%20the%20internal%20interface%20of%20the%20VMX%20from%20the%20EliteU%20subnet%3F%20Can%20you%20do%20a%20tracert%20to%20the%20internet%2C%20Google%20or%20something%20and%20post%20the%20results%3F%20That%E2%80%99s%20assuming%20internet%20traffic%20is%20running%20via%20the%20VMX.%3CBR%20%2F%3E%3CBR%20%2F%3EAlso%2C%20sorry%2C%20could%20you%20confirm%20your%20address%20space%20in%20your%20azure%20VNET%20is%3F%20As%20the%20default%2010.0.0.0%2F16%20would%20overlap%20with%20your%20on-premise.%3CBR%20%2F%3E%3CBR%20%2F%3EEdit%3A%20corrected%20as%20I%20misread%20diagram.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1806020%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20connect%20to%20resources%20via%20site%20to%20site%20vpn%20using%20Meraki%20VMX100%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1806020%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F840957%22%20target%3D%22_blank%22%3E%40IrishTechie%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20meraki%20vmx100%20is%20not%20supposed%20to%20route%20to%20the%20internet.%20It%20is%20being%20used%20as%20a%20vpn%20concentrator%20and%20routes%20outgoing%20traffic%20to%20my%20on%20premises%20(HQ)%20Meraki.%20I%20am%20able%20to%20ping%20thru%20the%20vpn%20tunnel%20to%20the%26nbsp%3B%20Hq%20Meraki%20via%20IP%20address.%20I%20am%20also%20able%20to%20ping%20from%20HQ%20up%20the%20tunnel%20to%20the%20IP%20address%20of%20the%20vmx100.%20The%20tunnel%20is%20passing%20traffic%2C%20the%20issue%20seems%20to%20be%20with%20the%20Azure%20resource%20routing%20to%20the%20vmx100%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can't%20ping%20the%20vmx100%20from%20the%20VM%20that%20I%20have%20set%20up.%20Here%20is%20the%20route%20table%20I%20have%20set%20up%20for%20the%20vnet%2Fsubnet%20that%20the%20VM%20I'm%20trying%20to%20reach%20is%20on.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20dont%20get%20confused%20by%20the%20name%20of%20the%20vnet.%20There%20is%20NO%20bastion%20attached%20to%20that%20network%20anymore.%20The%20VM%20that%20I'm%20trying%20to%20RDP%20to%20is%20part%20of%20the%20subnet%20that%20this%20table%20is%20associated%20to.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1807091%22%20slang%3D%22en-US%22%3ERe%3A%20Unable%20to%20connect%20to%20resources%20via%20site%20to%20site%20vpn%20using%20Meraki%20VMX100%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1807091%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F840759%22%20target%3D%22_blank%22%3E%40Sharyn_S%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20you%20are%20well.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20responding.%20Also%2C%20thanks%20for%20sharing%20the%20screenshot%20of%20your%20Route%20Table.%20That%20is%20pretty%20much%20what%20I%20would%20expect%20for%20this%20configuration.%20It%20will%20send%20all%20traffic%20to%20the%20VMX%20(Except%20VNET%20bound%20traffic)%2C%20your%20VMX%20then%20needs%20to%20decide%20what%20to%20do%20with%20it.%20So%2C%20in%20short%2C%20that%20looks%20fine%20to%20me.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20need%202%20more%20things%20to%20help%20diagnose%20the%20issue%20here.%20Would%20you%20mind%20providing%20me%20with%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EWhat%20address%20space%20are%20you%20using%20for%20your%20VNET%3F%20(I%20can%20see%20the%20subnets%20in%20a%20previous%20diagram%20but%20would%20like%20to%20know%20the%20overall%20VNET%20address%20space)%3C%2FLI%3E%3CLI%3ECan%20you%20run%20some%20tracerts%20from%20the%20Azure%20VM%20and%20send%20screenshots.%3CUL%3E%3CLI%3EOne%20tracert%20to%20an%20on-premise%20resource%20that%20you%20should%20be%20able%20to%20hit.%3C%2FLI%3E%3CLI%3EOne%20tracert%20to%20an%20internet%20based%20entity%2C%20whether%20the%20VM%20should%20be%20allowed%20to%20hit%20it%20or%20not.%3C%2FLI%3E%3C%2FUL%3E%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThe%20tracerts%20will%20demonstrate%20that%20traffic%20is%20(or%20isn't)%20hitting%20the%20VMX%20appliance%20as%20it's%20next%20hop.%20This%20will%20help%20us%20narrow%20down%20where%20the%20issue%20lies%20as%20your%20route%20table%20is%20exactly%20what%20I%20would%20do%20for%20this%20setup.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELook%20forward%20to%20your%20response.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKarl%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi.

We have established a site to site vpn between our Azure Meraki vmx100 (managed Azure service/app) and our on premise mx64. Although the tunnel is up, running and passing traffic, I can't rdp to my resources in Azure. 

 

I spoke to Cisco and they confirmed my vmx100 is configured correctly and traffic is reaching the Azure resources however traffic from Azure VM is not being passed back. I need, specifically, to be able to rdp to the VMs in Azure.

 

I have set up routes but obviously they are not correct or else this would be working!

I have also set up network security groups allowing inbound and outbound traffic to port 3389 (rdp). When I run the connection test it tells me that access has been granted. However, when I try to rdp using the MS rdp client, I get the generic unable to connect message. When I try to rdp using the Azure rdp client, it tells me another computer has disconnected my session which is not possible since I'm the only one setting this up.

 

Anyone out there that has successfully set up a Cisco Meraki VMX100 in Azure and is able to access the resources in Azure behind the vmx100?

 

Thanks,

Sharyn_S

7 Replies
Hi Sharyn_S,

Hope you’re well.

Can you confirm your route tables and that they’re connected to the correct subnets?

I’m not familiar with the Meraki vmx specifically but will try to assist.

Thanks

@IrishTechie 

My route tables look correct. I've attached a network diagram. If you look at the diagram, it's the part at the top, in azure, where the two way connection is not happening. The Azure resources are not passing traffic back to the vmx.

 

According to cisco, there is 2 way communication between the azure vmx and the on premise Meraki

Thanks for sharing the diagram.

So if I read it right Your EliteU subnet should have a route table attached that looks a bit like:

- 0.0.0.0/0 > Next Hop Appliance: 10.0.9.4

Can you ping the internal interface of the VMX from the EliteU subnet? Can you do a tracert to the internet, Google or something and post the results? That’s assuming internet traffic is running via the VMX.

Also, sorry, could you confirm your address space in your azure VNET is? As the default 10.0.0.0/16 would overlap with your on-premise.

Edit: corrected as I misread diagram.

@IrishTechie

 

The meraki vmx100 is not supposed to route to the internet. It is being used as a vpn concentrator and routes outgoing traffic to my on premises (HQ) Meraki. I am able to ping thru the vpn tunnel to the  Hq Meraki via IP address. I am also able to ping from HQ up the tunnel to the IP address of the vmx100. The tunnel is passing traffic, the issue seems to be with the Azure resource routing to the vmx100

 

I can't ping the vmx100 from the VM that I have set up. Here is the route table I have set up for the vnet/subnet that the VM I'm trying to reach is on.

 

Please dont get confused by the name of the vnet. There is NO bastion attached to that network anymore. The VM that I'm trying to RDP to is part of the subnet that this table is associated to.

@Sharyn_S 

 

Hope you are well.

 

Thanks for responding. Also, thanks for sharing the screenshot of your Route Table. That is pretty much what I would expect for this configuration. It will send all traffic to the VMX (Except VNET bound traffic), your VMX then needs to decide what to do with it. So, in short, that looks fine to me.

 

We need 2 more things to help diagnose the issue here. Would you mind providing me with the following:

 

  • What address space are you using for your VNET? (I can see the subnets in a previous diagram but would like to know the overall VNET address space)
  • Can you run some tracerts from the Azure VM and send screenshots.
    • One tracert to an on-premise resource that you should be able to hit.
    • One tracert to an internet based entity, whether the VM should be allowed to hit it or not.

The tracerts will demonstrate that traffic is (or isn't) hitting the VMX appliance as it's next hop. This will help us narrow down where the issue lies as your route table is exactly what I would do for this setup.

 

Look forward to your response.

 

Thanks

 

Karl

@IrishTechie 

 

Hi Karl,

Thanks for your response and verifying my routes are seemingly correct.

 

I decided to stand up another VM, exactly like the EliteU VM, but on the same vnet as the vmx, different subnet. So now I have a comparison between the traffic coming and going from 10.0.9.36 (subnet of 10.9.0.0/24. I've named the VM, VM-Mer-EliteU, residing on the 10.0.9.32/28 subnet.

 

My vnets are:

10.0.9.0/24 subnetted into 2, 10.0.9.0/28 on which the vmx (10.0.9.4) resides and 10.0.9.32/28 on which my new VM-Mer-EliteU (10.0.9.36) resides.

 

10.0.8.0/24 also subnetted into 2, 10.0.8.0/28 on which the Bastion, which has been deleted resided and 10.0.8.32/28, on which my original VM-EliteU (10.0.8.37) resides.

 

As of yesterday, I was unable to ping or trace to and from anything vmx100 to any of the vnets/subnets or from either of the resources (the 2 VMs) to the Meraki. Last night, for sh*ts and giggles, I played around with vnet peering. I was actually able to ping the 10.0.9.36 VM but today I can't. Not sure what has changed. I still can't rdp to it though even though it is using the same NSG as the original EliteU VM, 10.0.8.37 with RDP port 3389 open. I can't rdp to either vm which was the problem that started all of this.

 

I have to run for a bit, I'll post the traces soon.

@Sharyn_S 

 

Hi,

 

Thanks for this.

 

Can I confirm that there is VNET Peering between the 10.0.9.0/24 and 10.0.8.0/24 subnet?

Also, you don't have any route tables or NSGs attached to the VMX subnet?

 

Can I also just check that your on-premises subnets are 10.0.0.0/24 and that there isn't anything that might be overlapping with the 10.0.9.0/24 or 10.0.8.0/24 subnets?

 

Look forward to the traces as they might shed some light on where the traffic is going.

 

:)difficult when I can't get my hands on it!