MX250 HA LAN Failover issue via switch interconnect

Solved
kishen32
New here

MX250 HA LAN Failover issue via switch interconnect

Team, we have a migration tomorrow for MX250 HA setup and testing HA failover. WAN failover works and when primary fails (power down), secondary takes over seamlessly. However, when we unplug downlink of active unit to downstream switch, both MX becomes active/active. Both MX are not directly connected and LAN failover I assume to work via VRRP towards downstream switch using its virtual IP. Please advice what i am doing wrong here. I followed few guides as below but i need someone to correct me if i am doing something wrong here.

 

https://documentation.meraki.com/MX/Deployment_Guides/MX_Warm_Spare_-_High_Availability_Pair

https://community.meraki.com/t5/Security-SD-WAN/MX-Warm-Spare-Issue/td-p/12979

https://www.willette.works/mx-warm-spare/

https://community.meraki.com/t5/Security-SD-WAN/How-to-cable-MX-amp-MS-for-HA/td-p/22765

 

kishen32_0-1604637413753.png

 

 

 

 

1 Accepted Solution
ww
Kind of a big deal
Kind of a big deal

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

That is expected behaviour

Use recommended setup with more downlinks https://documentation.meraki.com/MX/Deployment_Guides/MX_Warm_Spare_-_High_Availability_Pair#Recomme...

kishen32
New here

thanks @ww and @Bruce 

Bruce
Kind of a big deal

@kishen32 As you only have one downlink from each MX250 to the core switch if you unplug a downlink then the VRRP messages between the MX devices will cease to flow. Since each MX is no longer receiving VRRP messages from the other each will assume the other has failed as will try to become master (or remain as master). Remember that the WAN interfaces aren't used for VRRP messages.

 

Looks like the only document you haven't listed is this one, https://documentation.meraki.com/MX/Networks_and_Routing/Routed_HA_Failover_Behavior.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels