Skip to content
CONFIGLANE

Cisco Meraki / SD-WAN & branch connectivity

Meraki SD-WAN.Connect sites. Plan for failures.

Meraki MX can simplify branch connectivity. We design the architecture around it: which paths applications use, what happens when a circuit fails and how headquarters, cloud services and existing networks connect.

Scope of service

What you receive.

A good fit when branches are expanding, VPN links have grown independently or the backup circuit still needs to prove its value. Before selecting a device, we establish the connections your business actually requires.

A clear WAN design

Site roles, hub connectivity, address spaces, local internet breakout and cloud destinations are planned together. MX selection and licensing assumptions reflect enabled features, connections and required performance.

VPN and routing with explicit limits

We configure suitable Auto VPN topologies and check integration with existing networks. Third-party VPN, overlapping addresses and specialised routing requirements are reviewed for compatibility before implementation.

Segmentation across branches

Users, guests and specialist systems receive defined traffic permissions. Firewall rules, VLANs and VPN access are derived from application requirements and agreed with the responsible teams.

Tested failure scenarios

We test agreed events such as circuit loss and recovery using relevant applications. Results, failover behaviour and remaining dependencies are documented instead of treating a redundancy diagram as proof.

The delivery path

Three controlled steps.

  1. 01

    Map traffic and dependencies

    Capture sites, circuits, providers, applications and existing VPNs. Define availability requirements and maintenance windows.

  2. 02

    Validate the pilot and boundaries

    Prove the target topology at a suitable site. Test routing, security rules and failure behaviour under controlled conditions.

  3. 03

    Migrate and operate

    Migrate sites in agreed waves, accept the results and hand over alerting and operations.

What we agree before starting

Two circuits do not guarantee independent paths. Provider routing, power, MX redundancy and application behaviour require separate assessment. Uninterrupted failover and compatibility with every third-party VPN are not blanket promises.

Planning example · SD-WAN acceptance

Two WAN circuits become a design when failover is tested.

For a branch with two providers, document target paths and acceptance criteria before rollout. Thresholds depend on applications and the agreed scope.

  1. Document the design

    For each application, record its destination, local breakout or hub path, source network and permitted segments. Shared ducts or power remain explicit provider-dependency risks.

  2. Test failures separately

    After approval, test WAN 1 loss, WAN 2 loss and return to normal separately. Observe new connections, existing sessions, DNS and critical applications independently.

  3. Hand over acceptance evidence

    Record expected versus observed path, packet loss, interruption and recovery with timestamps. A green VPN indicator alone is not application evidence.

Good to know

Your questions. Clear answers.

Does Auto VPN replace WAN design?

No. Auto VPN simplifies connections between suitable Meraki MX networks. Topology, routing, segmentation, capacity and failure scenarios still need to be designed and tested.

Will a backup circuit take over without interruption?

There is no universal guarantee. Failover behaviour, existing sessions and applications differ. We agree test cases and document the behaviour observed.

Can we retain our existing headquarters network?

Phased integration is often possible. Before confirming suitability, we assess the VPN peer, routing requirements, address spaces and required features. Meraki is not suitable for every specialised topology.

Let’s discuss your requirements

A few details are enough to begin.

You do not need a finished design. We establish the need, boundaries and a dependable next step.

Plan branch connectivity

Helpful for the first conversation

  • Sites, circuit types and bandwidth
  • Headquarters, cloud services and important applications
  • Existing VPNs, address spaces and firewall boundaries
  • Requirements during circuit or device failure

Please do not submit passwords, API keys or confidential network plans through the form.

Explore the technical detail

Choosing Meraki or Catalyst by requirements

Technical background: Cisco: Meraki Auto VPN configuration and troubleshooting

More Cisco Meraki services