ICMP not working

Solved
Sanman
Here to help

ICMP not working

Hi all, 

I have Meraki SDWAN set up with MPLS (WAN1) and Internet (WAN2). At primary and secondary HUB I have MX250 with Primary Uplink as MPLS (WAN1). For traffic to the internet I have configured 'Flow preference --> Internet' on Security & SDWAN tab. Internet is working fine. I also have a  rule that specifically allows traffic from a LAN subnet to Internet service provider /30 via the Internet link (WAN2). 

From the Cisco LAN switch I am creating IPSLA with the responder IP as the service provider /30 (I am tracking routes for fail over reason). I am not able to ping the internet provider /30 IP address (Carrier PE). I can see that the ping traffic is going out through the correct interface (Internet port) but traffic does not seem to come back. I have ruled out any filters on the service provider PE as I can get a response back when the MPLS link is plugged out from the MX. This could also mean that the FW rules are working. 

 

Internet is working fine and I can reach 8.8.8.8 but for few reasons I do not want to use google DNS as the IPSLA responder. 

 

Any pointers to resolve this please? 

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

Sounds like you're seeing this in action:

https://community.meraki.com/t5/Security-SD-WAN/Flow-Preferences-ICMP/m-p/11354

 

Flow preferences do not honour ICMP (or rules that are "Any" instead of TCP or UDP.)

View solution in original post

3 Replies 3
Brash
Kind of a big deal
Kind of a big deal

Sounds like you're seeing this in action:

https://community.meraki.com/t5/Security-SD-WAN/Flow-Preferences-ICMP/m-p/11354

 

Flow preferences do not honour ICMP (or rules that are "Any" instead of TCP or UDP.)

Thank you so much. I will try this out. 

One questions though. I am getting response from ping 8.8.8.8. and it is going via WAN 2. 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels