cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this solution

L1 Bithead

FYI.

 

I got this resolved, finally! With the help from a PA tech guy who actually knew his way around VPNs 🙂

So here are some gotachas:

1. The Meraki MX was behind an ISP router that was handing out it's own private IPs.

1.2. This means that you have to enable NAT-T on the PA side. IKE Gateway > Advanced Options > check Enable NAT Traversal

 

2. Meraki MX does not allow you to specify a Local ID, by default it is using an WAN IP address found in the "Uplink" menu of the firewall.

2.1 IKEv2 allows you to enter the "Local ID", but it did not take affect for some reason. The Meraki was still sending it's "WAN IP" as the local ID.

 

Everything is working now! 

View solution in original post

Who Me Too'd this solution