Deploying Meraki MX HA using VRRP

adten
Here to help

Deploying Meraki MX HA using VRRP

Hi,

 

Please does anyone have experience with deployment of HA for two MX 67 using VRRP.

 

We are planning to deploy HA for two MX 67 using VRRP and need some helpful hints for the implementation in such a way that Dual Active issue will be avoided.

 

Thank you

4 Replies 4
KarstenI
Kind of a big deal
Kind of a big deal

Here is a guide to follow:

https://documentation.meraki.com/MX/Deployment_Guides/MX_Warm_Spare_-_High_Availability_Pair

Why are you mentioning Dual Active issues? Did you have trouble before?

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
cmr
Kind of a big deal
Kind of a big deal

@adten the approved setup is to have two LAN ports on each device connected to two separate LAN switches.  We follow this with switch stacks where each MX has one LAN cable to the first stack member and a second LAN cable to a second stack member.  This has not caused us any issues (unless you reboot the whole stack) in over a year.  If you have separate non-stacked switches it is often safer to only connect one LAN cable from each MX to a LAN switch to avoid a layer 2 loop being formed and not being dealt with properly by the spanning tree protocol.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
adten
Here to help

Hi cmr,

 

Thanks for the response. But I need clarification on 4 points -

 

1. In the approved setup you referenced, is it only one LAN port on each Meraki MX device that should be connected to stacked switches

 

2. Is a virtual IP required for these two Meraki devices or only physical IPs will suffice

 

3. If physical IP addresses are required, how will the routing be done to ensure failover occurs in the event one of the devices fail

 

4. In a situation where you have only two WAN links, can they be connected one per Meraki device ?

 

Thank you 

 

 

cmr
Kind of a big deal
Kind of a big deal

@adten in answer to your questions:

 

  1. Two LAN ports per MX for approved setup, however 1 works better if switches not stacked
  2. Virtual IP is for WAN side and for each ISP you need a minimum of two public IPs (one for each MX) and ideally 3 (the third for the virtual IP)
  3. Virtual IP above is used if configured, if you don't use virtual IP then it is not seamless but the physical ones are used.
  4. No, use a dumb L2 switch to split the WAN port from the ISP into multiple ones, one switch per ISP
If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels