We have been working on a deployment of 2 MS210-8 as ISP passthrough switches to a pair of MXs . See Picture. The issue we face is that the MXs sometimes (not all the time only when there is a VPN tunnel change on the ASRs) go into Active Active mode. We are load balancing across both ISPs. The fix offered to us is to connect the 2 MXs together. By my understanding this already achieve via ports 3 and 4 of the MXs (see the port descriptions). The ASRs see traffic across the IPsec tunnel from both ISPs but due to the ASR tunnels being in active/passive WAN1 being primary, I believe traffic being load balanced onto WAN2 is being ignored as that tunnel is idle. I have seen this design a lot lately due to the limitations of the carriers to provide more than 1 port.
Anyone see issues with this topology without the physical connection that was suggested?![Logical.jpg Logical.jpg](https://community.meraki.com/t5/image/serverpage/image-id/9414iD9A8FF0F4A5639DC/image-size/large?v=v2&px=999)