I mentioned in the previous post that we have all Meraki gear here. When I interviewed for the job, I thought this was really cool because I am not a networking guy, and anything that could help my life be easier, I am all for it. At least I thought it was cool until the day I started looking at establishing the first VPN to Azure and the only documentation on the Internet said it could not be done, something about IPSEC policies not being compatible or something. Apparently the were posts I was reading were old, because once I figured out the settings (and there is a setting on the Meraki side for Azure), the setup was really pretty simple. However there was no straightforward documentation on exactly what to do. Now I like things simple and straightforward, I do not like to read between the lines to get something done because reading between the lines always leaves things open to interpretation, which leads to wasting time.
So here is the Step-By-Step Cookbook on how to implement a VPN from your Meraki setup to Azure.
1. Login to your Azure portal and Select New
2. Type Virtual Network, Hit Enter
3. Select Resource Manager, and click Create
4. Setup the Virtual Network specific to your environment. Remember the Address Space setting. You will need this later.
5. After the Virtual Network is created, Select Subnets.
6. Select Gateway Subnet.
7. Add the IP Address Range as it pertains to your environment.
8. Click on New.
9. Type In Virtual Network Gateway.
10. Select Create.
11. Customize the settings as it would apply to your environment. The VPN type MUST be Policy Based. GO through the process of creating a Public IP Address, Note the IP Address assigned, you will need it later. Hit Create and take a break. This will take a while.
12. Note this IP Address, you will need it later.
13. Go back to the Home Screen, Click on New
14. Enter Local Network Gateway, Hit Enter.
15. Select Local Network Gateway.
16. Select Create
17. Make the appropriate entries as it pertains to your environment. The IP Address, is the external IP address of your On Prem environment. Enter all of the appropriate On Prem networks in the Address Space. If you do not enter all of the correct networks here, the VPN will fail Phase 2 Authentication. Click Create.
18. Select Connections.
19. Select Add.
20. Make the appropriate entries as it pertains to your environment. Select OK.
21. On your Meraki dashboard, Go to Security Appliance\Site-to-site VPN
22. Select Add a peer and enter in the appropriate information for your environment. The Public IP is the IP address that was created in Azure in Step <>. The Private Subnet is the entire subnet that was originally created, not just the Gateway Subnet. If you enter the wrong Subnet information, it will fail Phase 2 VPN authentication. Select Save Changes.
23. To check the status of the connection, in Azure, open the connection properties.