Meraki HA(High Availability) MX and redundant topology

Solved
VanDerTuch
Here to help

Meraki HA(High Availability) MX and redundant topology

Hi Guys, i would like to ask for your help.

I am trying with my colleague configure HA for two MXs 105 with virtual IPs(3 public ip). Everything was working until our customer built second server room and we added second core switch to topology. Before was one Meraki 9300X switch, now we have two 9300X in two separeted server rooms.(without possibility of stack)(Previous design was only one core box). And now we have problem.

9300X supports only physiscal stacking so we are running RSTP in the topology. Primary CORE A switch has priority of 4096 and secondary has 8192. And every access switches will have one link to CORE A and one link to CORE B(Core B link will be in blocking state because of RSTP). But.....problem is MXs firewalls. It works only in topology, where primary MX has one link to CORE A and secondary switch has one link to CORE B (two server rooms). If we want to add cross links, like in RECOMENDED design, LAN switches stop forwarding.....MXs are looking fine where is one active and second is passive ready, but no Internet conectivity. Switches are two cores(meraki 9300X) and access switches are also Meraki(different models)....Do you have some idea what is the problem? In picture, topology works without links(2), if we add links(2), it will stop forward.

Thanks a lot.HA Topology.png

1 Accepted Solution
KarstenI
Kind of a big deal
Kind of a big deal

No native VLAN on the MX?

https://cyber-fi.net/index.php/2022/03/13/how-to-connect-the-meraki-mx-to-ms-switches/

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

4 Replies 4
KarstenI
Kind of a big deal
Kind of a big deal

No native VLAN on the MX?

https://cyber-fi.net/index.php/2022/03/13/how-to-connect-the-meraki-mx-to-ms-switches/

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
VanDerTuch
Here to help

thanks for reply. Yes, without Native(we are using drop untagged traffic) and also no vlan 1. We are using vlan 2 and higher.

KarstenI
Kind of a big deal
Kind of a big deal

Expected behavior then. Your BPDUs get lost and STP can't work.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
VanDerTuch
Here to help

Thanks a lot. Yes, that is true. So we have to create native vlan and propagete it via trunk links. Have a nice day and thanks.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels