Hub/spoke redundancy.

Ishai
Here to help

Hub/spoke redundancy.

Hi All

 

I have a question regarding Hub/spoke redundancy.

 

We are in migration Phase from one Dc to another.

 

I have multiple remote sites configured as a spoke (MX68CW) connecting to two Hub in two different DC’s (MX-450),

Is there a restriction (max. 2) in the amount of VPN’s from a spoke point of view toward the Hubs, is it possible to have 3 tunnels to 3 hubs from one spoke?

 

Thank you in advance.

 

  

4 Replies 4
ww
Kind of a big deal
Kind of a big deal

There is no limit.  Just try honor the recommended tunnel count from the sizing guide.   

https://meraki.cisco.com/product-collateral/mx-sizing-guide/

Ishai
Here to help

Thanks for your reply

I’ll do some tests and come back to you (I think the sizing guide refers to full-mash)

MerakiDave
Meraki Employee
Meraki Employee

@Ishai there is no limit, (no maximum of two for example) and the limit will be how many hubs/concentrators you have defined, so if you actually had 5 data center hubs defined, then (if you wanted) each spoke could have 5 tunnels to all 5 hubs defined in any order you like, and of course you could stagger that hub priority order across many different spokes.  I'm not saying I would suggest that necessarily, as this can dramatically increase the tunnel counts, but it's certainly possible, and just keep an eye on the sizing guide.  The three key items for any given MX are throughput, number of clients and tunnel count. 

Hi Dave,

Sorry for the late response.

Thank you for your explanation!

I’m investigating the possibility that the failover to another hub is not taking over when one Hub is down.

(Security & SD-WAN ---- Site-to-Site VPN    Hub position 2 is not taking over after hub in position 1 failed).

 

I can’t be very specific yet but I’m trying to narrow down the possibilities.

Current version: MX 15.42.1

 

Thank you.

Ishai

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels