Load Balancing on MX84 with different ISPs

Solved
mcoomber
Getting noticed

Load Balancing on MX84 with different ISPs

Hi,

I've got two WAN Links connected. 

WAN1 - Static Public IP Address (Primary Uplink)

WAN2 - Private Static IP Address. The gateway for this link is the router's gateway. 192.168.1.1.

 

Desired Result 

I want to have all mobile phones connect to the internet via WAN2. Desktops and laptops via WAN1, which is the corporate network. 

 

Work Done So Far

  • Created an SSID 
  • Created Group Policy only allowing Android, iPod, iPad, iPhone, Blackberry and ChromeOS. 
  • Created a VLAN ID 30
  • Created a subnet 192.168.48.0/24
  • Created a Flow Preference directing the subnet to use WAN2
  • Activated DHCP for the subnet on the MX84 

 

Problem

When I try to connect the phones to the SSID, I get the error message: Couldn't get an IP

 

addressWAN2 configurationWAN2 configurationSubnetSubnetDHCP for the Mobile PhonesDHCP for the Mobile PhonesFlow PreferenceFlow PreferenceSSID ConfigSSID Config

 

 

 

 

1 Accepted Solution
PhilipDAth
Kind of a big deal
Kind of a big deal

The individual ports that the APs connect to need to be trunk ports, to allow VLAN30.  You can make the native VLAN10 if you like.

View solution in original post

15 Replies 15
RaphaelL
Kind of a big deal
Kind of a big deal

What is the port config of the switchport where the APs are connected ?

mcoomber
Getting noticed

The uplink port from the switch to the backbone switch is the Trunk but the individual ports that the APs are connected to switch are user access ports on the Data VLAN 10

 

 
PhilipDAth
Kind of a big deal
Kind of a big deal

The individual ports that the APs connect to need to be trunk ports, to allow VLAN30.  You can make the native VLAN10 if you like.

alemabrahao
Kind of a big deal

It was a pleasure to help you.

Guys, just to let you know that I was helping @mcoomber  closely, one of the things that was missing was to create VLAN 30 on a 3850 switch that was between the MX and the MS. In addition, not all APs had the switch port configured for trunk, which was also causing the problem (this was confirmed by Meraki).

So in short, it wasn't just about allowing VLAN 30 in the SSID and configuring trunk on the ports, it was still necessary to configure the VLAN on the Catalyst switch.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Mloraditch
Kind of a big deal

Is VLAN 30 allowed on the trunk from the MX to the switch involved? and same on the switch port to the AP? and is the AP's native vlan something other than 30?

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
mcoomber
Getting noticed

The uplink port from the switch to the backbone switch is the Trunk but the individual ports that the APs are connected to switch are user access ports on the Data VLAN 10

 

 
Mloraditch
Kind of a big deal

The AP ports need to be trunked. You can set them with 10 as the native vlan and at least vlans 10,30 allowed then your setup should work without other changes

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
mcoomber
Getting noticed

Thanks, I have configured the ports but will confirm tomorrow if all is well when I'm back in the office. 

 

mcoomber
Getting noticed

Screenshot 2025-05-08 104442.pngScreenshot 2025-05-08 104632.pngScreenshot 2025-05-08 105345.png

I'm still getting the error message. Couldn't get an IP address.

alemabrahao
Kind of a big deal

Is the MX port also in trunk mode?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
mcoomber
Getting noticed

Yes. 

Screenshot 2025-05-08 112116.png

mcoomber
Getting noticed

VLAN Configured on switchVLAN Configured on switch

 

PhilipDAth
Kind of a big deal
Kind of a big deal

You need to change this from an Access port to a Trunk port.

 

PhilipDAth_0-1746648236915.png

 

alemabrahao
Kind of a big deal

As informed, the port must be configured in Trunk mode.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
mcoomber
Getting noticed

Thanks @alemabrahao @PhilipDAth @Mloraditch @RaphaelL for the answers you provided. 

 

 

 
Get notified when there are additional replies to this discussion.