I have a strange issue I'm unable to locate and spent a couple hours with Meraki support only to ask we reboot the MX's, which we did with no resolution. Even changed S2S VPN from Hub to Spoke to Off and then back on with no resolve and finding it hard to track down actual root cause.
Have (8) sites all with Meraki MX's and all are Hub to create a mesh network. Has been working this way for months without issue, however yesterday between two of the sites we have a 20-40% packet loss. It is only between these two sites that have been working perfectly since January and one site has MX100 while other has MX84 not that it should matter since same under the hood.
What's interesting is both these sites can ping anything anywhere, WAN, LAN or any other S2S MX's without an issue. However, these two sites in question have issues pinging each other and we're having difficulty operating due to the issues since these two particular sites share many resources. The issue is present in both directions.
Anyone experience similar?
Solved! Go to solution.
I have had a similar issue where the traffic actually was changed on the path between sites. One of the many ISP's had an issue on a US to CDN handoff. I found MTR was really helpful in troubleshooting showing where traffic was dropping. We ended up using another tunnel as the exit point to bypass the poor path until it got fixed.
Good luck
What does a traceroute look like from Site A's public IP to Site B's public IP, and vice versa? Is there a hop in the route that goes slow?
I have had a similar issue where the traffic actually was changed on the path between sites. One of the many ISP's had an issue on a US to CDN handoff. I found MTR was really helpful in troubleshooting showing where traffic was dropping. We ended up using another tunnel as the exit point to bypass the poor path until it got fixed.
Good luck
>between two of the sites we have a 20-40% packet loss
What is reporting this packet loss, or how are you seeing this packet loss?
Solarwinds and various other manual tests via the firewall native tools.
Seems to have been CDN issues as noted. ISP found root cause and have escalated for repair to international vendor edge/border Route.
Thanks!
Awesome!
Glad I could help, this was a super hard problem to troubleshoot (for me), so I am glad the ISP took responsibility (they usually don’t)
😄
What do you see in the Security & SD-WAN > VPN Status page of the two problematic appliances? Everything green regarding VPN registry, NAT and encryption?
Correct, everything is green, s2s vpn connected correctly and can pass traffic between the two sites, just keep freezing up when multiple packets dropped. Firewall VPN rules are Open/Open and Enabled as they have always been. Allowed VPN VLAN's are still the same ones permitted to pass and technically are passing, just dropping major packets.