02-05-2025 06:22 AM
Hi guys,
So I have been reviewing this Meraki document: https://documentation.meraki.com/MX/Site-to-site_VPN/BGP_routing_over_IPsec_VPN where the feature is explained.
As I understand it we finally have a semi route based solution where only one TS will be used for 0.0.0.0/0 and then use an eBGP session with the remote VPN peer over a tunnel subnet allowing for routing of local and autoVPN subnets to external networks.
The only disturbing thing I found with this is that the local MX will advertise ALL local VPN enabled networks in addition to the AutoVPN received iBGP routes which basically means your entire enterprise... and also inbound you will receive all the routes the peer sends you. Since BGP is a trust based system...
Question 1: Are there plans to make in and outbound filtering of routes available per BGP session?
Question 2: Does this work seamless with VPN subnet translation?
Question 3: Is there a way to filter outbound or inbound packets over the IPsec VPN?
Question 4: When will we finally have the ability to just use static route based VPN's and control which local subnets we announce to which peer? Both route based and policy based.
In essence: we need more control!
02-05-2025 08:26 AM
I admire you for still having hope for extranet VPNs.
02-05-2025 09:42 AM
I know that route filtering for BGP is generally under consideration, but can't provide any specific details. In the meantime, definitely apply VPN firewall rules - controls traffic leaving the MX: https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings#VPN_Firewall_Rules
02-06-2025 01:12 PM
You got me there at least half. You can apply outbound VPN firewall rules towards non-Meraki VPN peers but you cannot block incoming, so you are trusting the external network to not send unwanted traffic.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide