<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meraki Implementation in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/290840#M77191</link>
    <description>&lt;P&gt;This worked for us as well. We are not seeing the performance issues others have said they seen.&lt;/P&gt;&lt;P&gt;Created the Static NAt for our HA pairs VIP which is the source IP for the Meraki AutoVPN.&lt;/P&gt;&lt;P&gt;We were able to get all green across the Meraki dashboard and our tunnels came up.&lt;BR /&gt;&lt;BR /&gt;Thank you for all the digging you did. I have been talking with Palo and Meraki and didn't get anywhere.&lt;/P&gt;&lt;P&gt;Reworded my google search and thanks to this article ours are working.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2019 22:51:19 GMT</pubDate>
    <dc:creator>Golioth68</dc:creator>
    <dc:date>2019-10-01T22:51:19Z</dc:date>
    <item>
      <title>Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/195645#M58406</link>
      <description>&lt;P&gt;Curious if anyone has Meraki and a PAN setup.&amp;nbsp; We are trying to to link our remote sites to the data center.&amp;nbsp; At the remotes the meraki is the router then in the data center we have the meraki behind the the PA.&amp;nbsp; We can establish a VPN tunnel and ping internal devices, but it is really slow.&amp;nbsp; For example logons to workstations take forever, and I mean it they never logon wheel keeps spinning, but if I get by that, web pages dont load even from internal servers that should not have to go bck to the palo alto.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did the one arm concentrator mode, so it doesnt have a public IP, it sits in the trust zone with the other internal servers.&amp;nbsp; We started in the DMZ, put the policy righting got complex so more time consuming so we tabled that to just test performance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We haev a call in into Meraki as well, but curious of others experiences.&amp;nbsp; Palo Alto has best practices for others, just not meraki.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 05:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/195645#M58406</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-01-18T05:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/195815#M58427</link>
      <description>&lt;P&gt;@Retired Member,&lt;/P&gt;&lt;P&gt;I'm honestly suprised you actually got this to work at all to be honest. Have you verified through enabling interzone-default logging that the Palo Alto is actually&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; blocking any traffic. Meraki is generally pretty picky about being behind another firewall and if possible I would really recommend taking a look at redesigning your solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to do some troubleshooting; have you tried moving the Meraki out from behind your Palo Alto, or another connection all-together, and verified that the issue isn't present even with your Palo Alto out of the picture? I would call that step-one of the process just to rule that out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 21:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/195815#M58427</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-01-18T21:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/195816#M58428</link>
      <description>&lt;P&gt;I will turn on the logging.&amp;nbsp; Meraki has documentation on being behind a firewall and this morning it seems to be working better.&amp;nbsp; Almost like it takes time to improve service.&amp;nbsp; We discussed placing it outside the PA, but we still want to be able to use the PA to manage all user internet traffic.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 21:29:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/195816#M58428</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-01-18T21:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228091#M65604</link>
      <description>&lt;P&gt;I'm trying tom implement this now too andnot having much luck.&amp;nbsp; Do you have a link to the documentatuon you mentioned?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 20:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228091#M65604</guid>
      <dc:creator>rscott259</dc:creator>
      <dc:date>2018-08-23T20:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228124#M65609</link>
      <description>&lt;P&gt;So the docs have changed some, but here is the link:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Site-to-site_VPN_Settings" target="_self"&gt;https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Site-to-site_VPN_Settings&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see if I can find the old docs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Overall I was not that impressed with Meraki, to get it to work we placed the device inside the network and did a static nat translation and just opened the ports.&amp;nbsp; Not ideal, but it was just a POC, we had a lot of small bugs in the Meraki software, that always seemed to be a software update away.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The biggest show stopper for us was the cellular failover and how you could not restrict traffic over it.&amp;nbsp; So we had a IP camera that streams constantly over the cell connection in HD.&amp;nbsp; Wasteful as a backup.&amp;nbsp; Other little bugs that I dont recall anymore.&amp;nbsp; We decided to look into ECMP and use PA devices at each site.&amp;nbsp; Seems like a better cost alternative.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A little birdie told me that Palo Alto may have some SD-WAN stuff in the works, third party or maybe, fingers cross internal.&amp;nbsp; I dont see why they could not build a basic implementation into their firewalls.&amp;nbsp; We didnt need any of the traffic shaping during normal business, we run thin clients and IP phones at the site so the protocols are minimal.&amp;nbsp; Meraki was fine for that and a reasonable price point over the competition.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 03:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228124#M65609</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-24T03:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228315#M65656</link>
      <description>&lt;P&gt;I have setup the One Arm VPN concentrator. I connected into the internal LAN, created a static bi-drectional NAT for it. On the meraki side, set it up as "Manual - Port Forwarding" and chose a port to use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No issues like you're describing.&amp;nbsp; It has its use cases, but I'm not the biggest fan&lt;/P&gt;</description>
      <pubDate>Sun, 26 Aug 2018 19:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228315#M65656</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-08-26T19:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228317#M65657</link>
      <description>Had the same setup, problem wasn’t at the headend although I did not find it to be the most reliable. The problem we had was at the remote sites that used cellular. Their built in firewall/router was just really basic. We consider Viptela as well but the price was VMUG her than we could justify.</description>
      <pubDate>Sun, 26 Aug 2018 23:16:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228317#M65657</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-26T23:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228318#M65658</link>
      <description>&lt;P&gt;were the remote sites using the MX64? That's how I deployed at a client, they full tunneled everything to their DC.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 00:25:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228318#M65658</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2018-08-27T00:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228319#M65659</link>
      <description>64s and z3, just was feature lacking</description>
      <pubDate>Mon, 27 Aug 2018 01:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228319#M65659</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-08-27T01:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228363#M65669</link>
      <description>&lt;P&gt;After a marathon session with both Palo andMeraki we have this working now.&amp;nbsp; here are teh final notes fromteh Palo Support session&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please go through this document to understand this problem we were facing during NAT:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Session-setup-fails-due-to-session-hash-collision-error/ta-p/70539" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Session-setup-fails-due-to-session-hash-collision-error/ta-p/70539&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Finally we created source static NAT (Not bi-directional) and after that all the tunnel was up and running as expected&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Aug 2018 13:09:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/228363#M65669</guid>
      <dc:creator>rscott259</dc:creator>
      <dc:date>2018-08-27T13:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki Implementation</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/290840#M77191</link>
      <description>&lt;P&gt;This worked for us as well. We are not seeing the performance issues others have said they seen.&lt;/P&gt;&lt;P&gt;Created the Static NAt for our HA pairs VIP which is the source IP for the Meraki AutoVPN.&lt;/P&gt;&lt;P&gt;We were able to get all green across the Meraki dashboard and our tunnels came up.&lt;BR /&gt;&lt;BR /&gt;Thank you for all the digging you did. I have been talking with Palo and Meraki and didn't get anywhere.&lt;/P&gt;&lt;P&gt;Reworded my google search and thanks to this article ours are working.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 22:51:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meraki-implementation/m-p/290840#M77191</guid>
      <dc:creator>Golioth68</dc:creator>
      <dc:date>2019-10-01T22:51:19Z</dc:date>
    </item>
  </channel>
</rss>

