MX64 and MG21 Failover, Tunnels down.

MPastorU
New here

MX64 and MG21 Failover, Tunnels down.

Hello, I have the following question and scenario:

 

MX64 

  • Active-Active Auto-VPN Disabled
  • Load-Balancing Disabled
  • Flow Preference uplink Off
  • Hub & Spoke Topology

MG21

  • Up Registered and Connected to Meraki Dashboard

 

When we shutdown the WAN1 interface and force failover, VPN tunnels still down but link is connected to WAN2 on VPN Status.

 

This scenario is with some sites, there are sites where the tunnels works well with LTE and another sites where doesn't work with LTE failover with MG21. (Signal poor, good, high and so on in both scenarios).

 

Do you need some signals specification to up tunnels? I Understand that Meraki  LTE best practices is with high signal.

Do you need some fix rules in Firewall to NAT?

Anything?

 

 

 

3 Replies 3
Ryan_Miles
Meraki Employee
Meraki Employee

Do you have the same cellular carrier at all sites or various carriers? Typically AutoVPN not working on cellular is due to CGNAT. In the US I almost never have issues with Verizon or T-Mobile. However, ATT almost never works unless you get a static IP and special APN from ATT.

Ryan / Meraki SE

If you found this post helpful, please give it Kudos. If my answer solved your problem click Accept as Solution so others can benefit from it.
MPastorU
New here

Hy Ryan, is the same cellular carrier in every site. Some branchs works and some branchs doesn't.

 

We have tried with another carriers too and is the same behavior.

 

Our country is Chile, any way to tshoot tunnels and see if we need special APN?

I think your best option at this point is to open a Support ticket with Meraki and they can help troubleshoot the issue with you.

Ryan / Meraki SE

If you found this post helpful, please give it Kudos. If my answer solved your problem click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels