MX84 HA vlan mess

gmartine
Conversationalist

MX84 HA vlan mess

@PhilipDAth

 

After updating my HA topology to what you can see at the end of this thread (see topology with additional red links):

 

https://community.meraki.com/t5/Security-SD-WAN/MX84-HA-setup-tagged-WAN-ports/td-p/24988

 

I am now seeing some really weird messages on my log.  

6B9646A1-A36E-446D-9701-3C9B100FC692.png

 

 

I assume those messages are not harmful, right? 

What I think is happening is that the Internet traffic is landing VLAN1 and it is getting mixed up with my management traffic

4 Replies 4
PhilipDAth
Kind of a big deal
Kind of a big deal

What it means is traffic is being received by that MX on a VLAN with IP addressing belonging to another VLAN.

 

For example, lets say you have configure this on your MX:

VLAN1: 192.168.1.1/24

VLAN2: 10.0.0.1/24

 

The MX should not receive traffic from 10.0.0.0/24 on VLAN1 - that traffic should be on VLAN2.

@PhilipDAth I was trying to put my internet traffic in two separate vlans. The issue I am facing now is that switch usw-b is using port#1 as designated port. Port#1 is my connecting to my ISP and it is untagged. Ideally (and w/o modifying my topology) I would like to have port#4 as the designated port. It seems due to spanning tree tie breakers port#1 is designated because it is the lowest port number. Any idea other than either adjusting the path or switching the link between switches from port#4 to port#1?

PhilipDAth
Kind of a big deal
Kind of a big deal

Do your switches support adjusting the spanning tree port priority?

@PhilipDAth yes. I guess it is an option. Sor far o guess the option is supported via the CLI but it is not visible within the controller

 

https://community.ubnt.com/t5/EdgeSwitch/How-do-I-manually-adjust-port-priority-in-STP/td-p/2389457

 

Is that a better option?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels