Re: non-Meraki VPN peer is not establishing with zScaler (2024)

Re: non-Meraki VPN peer is not establishing with zScaler (1)

MOmarRiaz

Here to help

‎Jan 26 20232:25 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20232:25 AM

non-Meraki VPN peer is not establishing with zScaler

Hello ,

I'm trying to setup non-Meraki ipsec peer with zscaler.

My MX68 device is directly connected to public network. I can successfully ping zscaler public IP from MX68. MX68 is not generating any kind of traffic to zscaler (checked via packet capture on MX68). The only thing which I found in Event Log is

Event Type: Non-Meraki / Client VPN negotiation

Event Details: msg: FIPS mode disabled

Re: non-Meraki VPN peer is not establishing with zScaler (2)

Here is the custom setting in non-meraki vpn provided to us by zscaler team.

Re: non-Meraki VPN peer is not establishing with zScaler (3)

Here is the result of capture.

Re: non-Meraki VPN peer is not establishing with zScaler (4)

Here is the ping response from MX68 to zScaler public IP.

Re: non-Meraki VPN peer is not establishing with zScaler (5)

I tried to find solution but no success, could you advice me what I can do?

Best regards,

Omar

Solved!Go to solution.

Labels:

  • Labels:
  • 3rd Party VPN

0Kudos

Subscribe

1 Accepted Solution

Re: non-Meraki VPN peer is not establishing with zScaler (6)

MOmarRiaz

Here to help

‎Jan 29 20231:15 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 29 20231:15 AM

Dear All,

thanks for your valuable feedback and suggestions. Issue got resolved after contacting call support from Meraki team.

Here is the final settings of non-meraki vpn peer after that issue resolved in our case.

Re: non-Meraki VPN peer is not establishing with zScaler (7)

Re: non-Meraki VPN peer is not establishing with zScaler (8)

I thing i must like to add that the peer does not go up until we forward from traffic. That is one thing we have observed.

e.g.

Here is the case that I can see that the route is active in routing table for non-Merkai VPN peer.

Re: non-Meraki VPN peer is not establishing with zScaler (9)

But when we see VPN status we found out that peer is down.

Re: non-Meraki VPN peer is not establishing with zScaler (10)

We thought in actual the peer is down. But when we send some icmp packet to zscaler then VPN status shows peer is up.

Re: non-Meraki VPN peer is not establishing with zScaler (11)

VPN status after icmp packet

Re: non-Meraki VPN peer is not establishing with zScaler (12)

We have observed that they are few drop for icmp packer at very start but after that ping observed normal with out any drops and peer shows up.

Another thing we have observed that if there is no traffic on the non-meraki vpn peer then VPN status again show red or peer down after few hours but if we send some traffic or icmp ping then again it comes to green (VPN peer up).

This is all we have observed so far.

View solution in original post

0Kudos

Subscribe

  • All forum topics
  • Previous Topic
  • Next Topic

21 Replies 21

Re: non-Meraki VPN peer is not establishing with zScaler (13)

Re: non-Meraki VPN peer is not establishing with zScaler (14)alemabrahao

Kind of a big deal

‎Jan 26 20233:04 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:04 AM

Follow these recommendations:

  • Security & SD-WAN -> Configure: Site-to-site VPN ->Non Meraki VPN settings:

    • Preshared secret must be greater than 14 characters
    • Authentication cannot be MD5
    • Diffie-Hellman Group must be 14
    • Phase 2 encryption cannot be NULL
    • PFS can be configured to be eitheroff or 14

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to alemabrahao

Re: non-Meraki VPN peer is not establishing with zScaler (15)

MOmarRiaz

Here to help

‎Jan 26 20233:16 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:16 AM

1. Preshared secret must be greater than 14 characters

Yes in our case preshared key is 16 characters.

2. Authentication cannot be MD5

Yes we are not using MD5

3. Diffie-Hellman Group must be 14

I have also check with "Diffie-Hellman Group must be 14". Same issue.

4. Phase 2 encryption cannot be NULL

Yes, In our case Phase2 encryption is AES256, AES192,AES128.

5. PFS can be configured to be either off or 14

In our case it is off. I have also check this with 14.

I have found this above setting from Meraki documentation and i have implemented this but or creation of non-meraki vpn peer, event log message is same. msg: FIPS mode disabled

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (16)

Re: non-Meraki VPN peer is not establishing with zScaler (17)alemabrahao

Kind of a big deal

‎Jan 26 20233:25 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:25 AM

Is your MXbehind a CG-NAT?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to alemabrahao

Re: non-Meraki VPN peer is not establishing with zScaler (18)

MOmarRiaz

Here to help

‎Jan 26 20233:53 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:53 AM

No. Public IP is directly assigned to MX68.

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (19)

Re: non-Meraki VPN peer is not establishing with zScaler (20)alemabrahao

Kind of a big deal

‎Jan 26 20233:37 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:37 AM

And alsonot even the first and last character of the password can be a special character.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to alemabrahao

Re: non-Meraki VPN peer is not establishing with zScaler (21)

MOmarRiaz

Here to help

‎Jan 26 20233:54 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:54 AM

In our case credential does not contain any special character.

first and last character are lowercase alphabet

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (22)

Re: non-Meraki VPN peer is not establishing with zScaler (23)alemabrahao

Kind of a big deal

‎Jan 26 20233:53 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:53 AM

Have you tried it?https://community.meraki.com/t5/Security-SD-WAN/IPSEC-Tunnel-withZScaler/m-p/53769

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to alemabrahao

Re: non-Meraki VPN peer is not establishing with zScaler (24)

MOmarRiaz

Here to help

‎Jan 29 20231:02 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 29 20231:02 AM

Yes I have tries this but same situation. However issue got resolved after getting call support from Meraki team.

0Kudos

Subscribe

Re: non-Meraki VPN peer is not establishing with zScaler (25)

Re: non-Meraki VPN peer is not establishing with zScaler (26)ww

Kind of a big deal

‎Jan 26 20233:34 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:34 AM

1Kudo

Subscribe

In response to ww

Re: non-Meraki VPN peer is not establishing with zScaler (27)

MOmarRiaz

Here to help

‎Jan 26 20233:55 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20233:55 AM

Yes we have enable 2 local subnet for vpn at MX68.

0Kudos

Subscribe

Re: non-Meraki VPN peer is not establishing with zScaler (28)

MOmarRiaz

Here to help

‎Jan 26 20234:09 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20234:09 AM

Another thing i would like to add that below is the configuration of ours non-meraki vpn with zScaler. (peer not established)

Re: non-Meraki VPN peer is not establishing with zScaler (29)

While here is the configuration of another meraki dashboard of same customer a another country which is working fine.

Both non-meraki settings have its own credentials.

Re: non-Meraki VPN peer is not establishing with zScaler (30)

Also note that both MX have same version.

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (31)

Re: non-Meraki VPN peer is not establishing with zScaler (32)alemabrahao

Kind of a big deal

‎Jan 26 20234:17 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20234:17 AM

Open a support case.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to alemabrahao

Re: non-Meraki VPN peer is not establishing with zScaler (33)

MOmarRiaz

Here to help

‎Jan 26 20234:43 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20234:43 AM

I have already opened case and check many options with support team. And till yet we did not find out the cause. That's why I have adopted this community so that may be i found some help from experts in meraki field. Mean while i am also in coordinate with support team for resolution.

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (34)

Re: non-Meraki VPN peer is not establishing with zScaler (35)alemabrahao

Kind of a big deal

‎Jan 26 20235:10 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20235:10 AM

You've tried all possible options, maybe you can try with a different version.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (36)

Re: non-Meraki VPN peer is not establishing with zScaler (37)alemabrahao

Kind of a big deal

‎Jan 26 20236:26 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20236:26 AM

You can try changing the phase 2 lifetime to 3600s.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

0Kudos

Subscribe

In response to alemabrahao

Re: non-Meraki VPN peer is not establishing with zScaler (38)

MOmarRiaz

Here to help

‎Jan 26 20237:09 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20237:09 AM

Just tried with 3600s. Same issue.

0Kudos

Subscribe

Re: non-Meraki VPN peer is not establishing with zScaler (39)

rhbirkelund

Kind of a big deal

‎Jan 26 20235:48 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20235:48 AM

Do you see anything in the MX event log on Site-to-Site VPN negotiation?

LinkedIn ::: https://blog.rhbirkelund.dk/

Like what you see? - Give a Kudo ## Did it answer your question? - Mark it as a Solution 🙂

All code examples are provided as is. Responsibility for Code execution lies solely your own.

0Kudos

Subscribe

In response to rhbirkelund

Re: non-Meraki VPN peer is not establishing with zScaler (40)

MOmarRiaz

Here to help

‎Jan 26 20237:06 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20237:06 AM

In Event logs I only found this message. And this event only occurs if i delete peer and create new one. Changing a already created peer does not generate any log.

Re: non-Meraki VPN peer is not establishing with zScaler (41)

0Kudos

Subscribe

In response to MOmarRiaz

Re: non-Meraki VPN peer is not establishing with zScaler (42)

rhbirkelund

Kind of a big deal

‎Jan 26 202312:12 PM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 202312:12 PM

If you do a pcap on the MX internet interface, you should be seeing packets on udp/500 and udp/4500, as far as I recall.

LinkedIn ::: https://blog.rhbirkelund.dk/

Like what you see? - Give a Kudo ## Did it answer your question? - Mark it as a Solution 🙂

All code examples are provided as is. Responsibility for Code execution lies solely your own.

0Kudos

Subscribe

In response to rhbirkelund

Re: non-Meraki VPN peer is not establishing with zScaler (43)

MOmarRiaz

Here to help

‎Jan 26 20239:11 PM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 26 20239:11 PM

But in pcap there is not a single packet for UDP500 or to destination zscaler peer ip.

I beleive MX68 is not able to generate any ipsec messages and event log is FIPS mode disable.

0Kudos

Subscribe

Re: non-Meraki VPN peer is not establishing with zScaler (44)

MOmarRiaz

Here to help

‎Jan 29 20231:15 AM

  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎Jan 29 20231:15 AM

Dear All,

thanks for your valuable feedback and suggestions. Issue got resolved after contacting call support from Meraki team.

Here is the final settings of non-meraki vpn peer after that issue resolved in our case.

Re: non-Meraki VPN peer is not establishing with zScaler (45)

Re: non-Meraki VPN peer is not establishing with zScaler (46)

I thing i must like to add that the peer does not go up until we forward from traffic. That is one thing we have observed.

e.g.

Here is the case that I can see that the route is active in routing table for non-Merkai VPN peer.

Re: non-Meraki VPN peer is not establishing with zScaler (47)

But when we see VPN status we found out that peer is down.

Re: non-Meraki VPN peer is not establishing with zScaler (48)

We thought in actual the peer is down. But when we send some icmp packet to zscaler then VPN status shows peer is up.

Re: non-Meraki VPN peer is not establishing with zScaler (49)

VPN status after icmp packet

Re: non-Meraki VPN peer is not establishing with zScaler (50)

We have observed that they are few drop for icmp packer at very start but after that ping observed normal with out any drops and peer shows up.

Another thing we have observed that if there is no traffic on the non-meraki vpn peer then VPN status again show red or peer down after few hours but if we send some traffic or icmp ping then again it comes to green (VPN peer up).

This is all we have observed so far.

0Kudos

Subscribe

Re: non-Meraki VPN peer is not establishing with zScaler (51)

Get notified when there are additional replies to this discussion.

Subscribe

Re: non-Meraki VPN peer is not establishing with zScaler (2024)

References

Top Articles
Latest Posts
Article information

Author: Prof. Nancy Dach

Last Updated:

Views: 6459

Rating: 4.7 / 5 (57 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Prof. Nancy Dach

Birthday: 1993-08-23

Address: 569 Waelchi Ports, South Blainebury, LA 11589

Phone: +9958996486049

Job: Sales Manager

Hobby: Web surfing, Scuba diving, Mountaineering, Writing, Sailing, Dance, Blacksmithing

Introduction: My name is Prof. Nancy Dach, I am a lively, joyous, courageous, lovely, tender, charming, open person who loves writing and wants to share my knowledge and understanding with you.