specific subnetwork not exiting MX 2nd ISP when internet flow preference is configured

Shyam1
Here to help

specific subnetwork not exiting MX 2nd ISP when internet flow preference is configured

We have Two MX 105 in HA , 2 ISPs with 1st ISP - with /29 and 2nd ISP - with /30.

When i configure specific subnetwork to exit 2nd ISP in internet flow preference , it does not work.

Kindly help me with this issue. I have a switch in between ISP router and Firewall too.After Firewall - switches are in standalone.

10 Replies 10
alemabrahao
Kind of a big deal
Kind of a big deal

To use the second ISP, you need at least one /29 because each MX requires an IP address.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Shyam1
Here to help

I am trying to exit the traffic from a subnetwork when there is no HA failure , when there is no ISP failure.

 

Could you please explain me why I require that /29 on 2nd ISP

alemabrahao
Kind of a big deal
Kind of a big deal

First question, is the second ISP only connected to the active MX ?

If so, okay. But consider that in case one of the MXes fails, wouldn't it be better to have a link on each MX ?

The /29 is necessary because the /30 only provides two usable IPs, in this case the gateway and its MX. Since each MX needs an IP (ideally), you need at least one /29.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Shyam1
Here to help

Hi ,

2nd ISP is connected to 1st MX. We tried reaching 2nd ISP for increase in subnet size but no luck. So deployed HA with /29 ISP1.

 

Any ways we can achieve this 

alemabrahao
Kind of a big deal
Kind of a big deal

Is it possible to test this link directly on your device or another one? Just to make sure it's working as expected.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Shyam1
Here to help

2nd ISP Link was removed from MX primary and checked the working , internet is reachable. 

 

alemabrahao
Kind of a big deal
Kind of a big deal

Could you please show me how you are creating your traffic forwarding rule?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Shyam1
Here to help

Hi,

Gave protocol as any at start . After that changed to TCP .

 

34805.jpg

alemabrahao
Kind of a big deal
Kind of a big deal

And how do you test this to make sure it's not working?

 

I'm asking because of this small observation.

 

Note: ICMP traffic is not subject to traffic shaping rules. As a result, Flow Preference will have no impact on ICMP traffic.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Shyam1
Here to help

Whatsmyip webpage is used after connecting and end host in this specific vlan

Get notified when there are additional replies to this discussion.