Connecting Meraki Network to Aviatrix Transit Network

This document assumes that you have deployed a Meraki vMX100 in AWS that has full meshed to all your branch offices using Meraki MX products. In this technical note, we will outline the steps to have end to end connectivity from your Meraki network to your AWS Global Transit Network using Aviatrix solution. At the end of configuration, your on-prem client will be able to access an EC2 instance in a Spoke VPC.

meraki_avxtransit01

In this configuration guide, we will summarize the Meraki on-prem subnets (10.28.144.0/24 and 10.28.145.0/24) into a single 10.28.0.0/16. We will also summarize Aviatrix Spokes subnets (10.32.0.0/16, 10.50.0.0/16, 10.63.0.0/16) into 10.32.0.0/11. With a good planning on on-prem subnets and VPC subnets, we can use summarized subnets in the Site2Cloud connection and avoid configuring AWS route table and security groups when we add new Meraki on-prem subnet or new Aviatrix Spoke.

The objectives here are:

  • Build an Aviatrix Transit Network with multiple spokes.
  • Launch an Aviatrix gateway in the same VPC as vMX100.
  • Create a Site2Cloud connection from Aviatrix gateway to the same VGW used in Aviatrix Transit Network.
  • Adjust security groups on both vMX100 and Aviatrix gateway and update AWS route tables accordingly.

Note

This document assumes you have already launched an Aviatrix Controller. Aviatrix GW uses EIP, make sure you have sufficient quota for EIP. You can contact AWS support to request for more EIPs. Aviatrix supports multiple Transit GW groups from one Controller. In this example, we will only use one Transit GW group with HA enabled.

Build an Aviatrix Transit Network with multiple spokes

  1. Launch Aviatrix Transit GW Follow Step 1 and Step 2 to launch an Aviatrix Transit GW and enable HA in the Transit hub VPC. You can consider using a new Transit hub VPC in case the existing Transit hub VPC does not have enough IP addresses to launch new instances (The Aviatrix Transit GW pair).
  2. Connect Aviatrix Transit GW to VGW Follow Step 3. At this point, VGW starts to advertise to Aviatrix Transit GW. Make sure you specifiy a different “AS” number for the BGP session of Aviatrix Transit GW connection to VGW.
  3. Attach Spoke VPC to Aviatrix Transit GW Follow Step 4, Step 5 and Step 6 to launch an Aviatrix GW in this Spoke VPC (with HA as an option) and attach to the Aviatrix Transit GW.
  4. Repeat the above step 3 and 4 Repeat the above 2 steps for the remaining Spoke VPCs.

Note

In Aviatrix solution, Spoke VPCs have no connectivity to each other by default. If a Spoke VPC needs connectivity to another Spoke VPC, for example, the shared service VPC, configure AWS Peering or Aviatrix Encrypted Peering from the Controller console.

In this example, Meraki vMX100 is already deployed in us-west-2 (Oregon) region in VPC with 10.10.0.0/16. The following is the configuration for vMX100 in AWS VPC.

meraki_avxtransit02

Here is the configuration for the MX64 at on-prem.

meraki_avxtransit03

Launch an Aviatrix gateway in the same VPC as vMX100

  1. Login to Aviatrix Controller UI and click Gateway at the navigation panel.
  2. Click New to launch a gateway with the following settings:
  • Gateway Name = vMX-AvxGW
  • Access Account Name = Select the same AWS account where the vMX100 is deployed
  • Region = us-west-2 (Oregon)
  • VPC ID = Select the same VPC where vMX100 is deployed
  • Public Subnet = Select the same subnet where vMX100 is deployed
  1. Click OK to create the gateway.

Create a Site2Cloud connection between Aviatrix GW and VGW

  1. Go to AWS console in us-west-2 (Oregon) region. Click on Services and go to VPC Dashboard.
  2. Click on VPN Connections at the left panel.
  3. Click “Create VPN Connection” to create an IPsec tunnel to Aviatrix GW.
meraki_avxtransit04
  1. Select the VPN connection that you just created and click “Download Configuration” to download the “Generic” configuration.
  2. At Aviatrix Controller UI, click Site2Cloud at the navigation panel.
  3. Click “Add New” to configure the Site2Cloud connection to the same VGW that is already connected to Aviatrix Transit Networks.
meraki_avxtransit05
  1. Click on Site2Cloud > Diagnostics page and verify that the IPsec tunnel is established between Aviatrix GW and the VGW.
meraki_avxtransit06

Adjust security groups and update AWS route tables

  1. Go to AWS console and select us-west-2 (Oregon) region.
  2. Go to EC2 Dashboard and click on the vMX100 instance.
  3. Click on the Security Group for the vMX100 and add Allow Inbound traffic from 10.10.0.0/16, 10.28.0.0/16 and 10.32.0.0/11. Let the default Outbound Allow All.
meraki_avxtransit07
  1. Select EC2 Aviatrix GW instance and click on its Security Group.
  2. Add Allow Inbound traffic from 10.10.0.0/16, 10.28.0.0/16 and 10.32.0.0/11. Let the default Outbound Allow All.
meraki_avxtransit08
  1. Go to AWS VPC Dashboard, edit the route table of the VPC where vMX100 and Aviatrix GW are deployed. Configure both the public and private route table such that 10.28.0.0/16 is pointed to vMX100 eni. The 10.32.0.0/11 and 10.254.0.0/26 are automatically added when we create the Site2Cloud connection to the VGW in the previous section.
meraki_avxtransit09

Validate connectivity

  1. At Aviatrix Controller UI, click Site2Cloud at navigation panel.
  2. Select Site2Cloud connection for the Aviatrix Transit Network. You should observe that both IPsec tunnels to VGW are UP. There will be 2 learned routes from VGW (10.10.0.0/16, 10.28.0.0/16) and 3 advertised networks from spokes (10.32.0.0/16, 10.50.0.0/16, 10.63.0.0/16).
meraki_avxtransit10 meraki_avxtransit11
  1. In this example here, I have 3 EC2 instances in each Spoke VPC (10.32.102.81 in private subnet, 10.50.0.5 in public subnet, 10.63.100.97 in private subnet). My on-prem client is 10.28.144.19. The following screenshot shows the end to end connectivity from on-prem to each spoke.
meraki_avxtransit12
  1. Here is a logical view of the networks from Aviatrix Controller UI.
meraki_avxtransit13
  1. If you have high number of spokes in your deployment, we recommend that you enable Manual Summarization to reduce the number of advertised networks. This is needed due to an AWS BGP route limitation. Please see How do I troubleshoot BGP connection issues over VPN? for more details.
  2. In order to summarize Spoke CDIRs, you will select the Site2Cloud connection for the Aviatrix Transit Network. Enter the summarized route in the “Manual BGP Advertised Network Lis” and click “Change BGP Manual Spoke Advertisement”.
meraki_avxtransit14

In summary, we can connect an existing Meraki network to Aviatrix Transit Network to leverage the agility, automation and other benefits of using Aviatrix solution.