Failover query

Vishal07
Getting noticed

Failover query

Hi all,

 

I'm having one pair of Meraki Mx place as perimeter firewall and below one pair of FTD fw directly connected to Mx. Need to know how will be my failover works here as Meraki works as warmspare i.e failover would only happen if there's a connectivity loss with dashboard, while FTD support link, device, path failover.

 

MX1 single link to FTD1

 

MX2 single link to FTD2

 

Just a thought if I do criss cross connectivity between Mx and FTD, would my Active FTD connected to both Mx's forward traffic to Spare Mx also and that traffic would be drop ?

 

Pls help

4 Replies 4
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

A diagram would help better understand exactly how you plan to deploy. But in general MX HA monitors reachability both on the WAN and LAN side in different ways. This doc (and linked docs within) cover the process in detail.

 

https://documentation.meraki.com/MX/Deployment_Guides/MX_Warm_Spare_-_High_Availability_Pair#Underly...

Vishal07
Getting noticed

Vishal07_0-1754636834963.png

Will it be disruption in network if i do criss cross connectivity with FTD and MX ? Link from active FTD to spare MX will process traffic or all traffic will go via active Ftd to active Mx ?

cmr
Kind of a big deal
Kind of a big deal

Add these two links and you'll be fine, otherwise if the FTD connected to the spare MX becomes active you will lose internet access

cmr_0-1754689628143.png

 

If my answer solves your problem please click Accept as Solution so others can benefit from it.
GIdenJoe
Kind of a big deal
Kind of a big deal

Both MX devices need L2 connectivity to each other to pass their VRRP keepalives.  So the FTD uplinks must either be a bridge group or interfaces connected to intermediate switches to split between both MX units.

Get notified when there are additional replies to this discussion.