Bit late on a response here but this has come up again, interested to see if anyone else has come up with this or can replicate.
Scenario:
Active-Active Auto VPN enabled
WAN 1: - MPLS | 4/4Mb/s
WAN 2: - NBN | 100/40Mb/s
We push SIP and Citrix over MPLS and everything else over NBN (including windows file share) with regular internet traffic breaking out at the branch directly.
Issues:
- When active-active is enabled and spoke branch attempts to download a file from one of our shared drives in the DC they are experiencing incredibly poor download performance, basically if a PDF is 40MB you can be sure it will take either 5 minutes or will timeout.
Troubleshooting Steps:
- Initial thoughts were AMP as this has bitten us plenty of times so disabled that and still no good.
- Maybe it's SMB? Poked around here and nothing obvious found as LAN speeds to the file share are excellent.
- Maybe QOS? Checked that and everything is within spec.
- To be sure it wasn't SMB or our server related in general we shared a file path on a PC to the remote site user with a 40MB pdf and when testing we experienced acceptable speeds/download time.
- That confused us so we kept digging and didn't get anywhere. 😃
- Ready to pass the ball to the systems team we disabled active-active auto VPN as this has bitten us previously for the same issue and conducted our tests again...suddenly download speeds are beautiful.
Conclusion
Assuming our config is fine which i'm confident it is, something is seriously not right with the active-active feature.
Raised a ticket with Meraki support and confirmed traffic is traversing WAN1 and WAN2 regardless of the policy in place. Meraki are going to dig a bit deeper and report back what is going on here.
I thought the DC should respect what SDWAN policies are set and send file share traffic back via the NBN tunnel.
High number of TCP retrans and packets out of order when the feature is enabled with almost none when disabled.
Versions:
MX67: 14.40 (branch)
MX250: 14.39 (dc)