Hello experts,
We have a customer looking to implement the following scenario:
1. Hub site is a datacentre with Internet and L2 ethernet multipoint WAN termination point (The point in the PMP WAN).
2. Multiple branches each with L2 ethernet spoke termination (the multipoints in the PMP WAN). No internet available at branches, only cellular LTE for failover.
3. Requirement for customer to get an alert from MX if WAN service goes down at any site and switches over to LTE.
I thought this will not be an issue as I could simply use one of LAN port in each MX to set up the preferred routed access for the branch to Hub connectivity and LTE modem could be leveraged for Meraki cloud access to have management access and orchestration and that I can set up LTE port as backup with VPN tunnel thru it to datacenter MX and this backup VPN path will have higher cost.
However this approach with WAN circuit connected to the LAN port of MX, does not permit (like MS switches) to report a LAN port going down and it can only alert on the MX WAN ports.
While I can terminate the WAN circuit to Primary Internet port of MX and then Cellular modem (ethernet) to second Internet port (or even cellular USB stick for backup). With NAT thru the Internet port, I will need to set up VPN tunnels over the WAN cloud to mitigate the effects of NAT. Not sure though if this approach will allow using LTE backup service to establish the management access to the cloud needed to establish VPN tunnels. Or maybe, MX at branches can route to the peer at the datacenter (all of them being in the same private /27 subnet) and leverage Internet access from the datacenter MX hub to establish the tunnels.
I will love to hear good advice on this from folks who would have done these kind of non standard setups.
Thanks and everyone be safe and healthy.