- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki MX Failover with VIP - when ISP provided /32 network as default route with /28 routed prefix
My ISP has allocated me a /32 IP address along with a /28 routed prefix.
If I understand correctly, the Meraki MX HA VIP requires the VIP and MX WAN interfaces to reside on the same subnet?
I cannot use the primary /32 IP address from my ISP, as it contains only 1 IP.
If I use the /28, I can allocate enough IP addresses, but not sure how the ISP will route the traffic, as it will be routed to the /32 ?
I am sure I am missing something really simple here, but can someone give me some pointers please? Thank you!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need at least 2 IPs (one for each WAN) and 3 if you are considering using Virtual IP.
Requirements and Best Practices
When configuring routed HA, it is critical that both MXs have a reliable connection to each other on the LAN, so the heartbeats of the primary MX can be seen reliably by the spare. To ensure this connection is reliable:
- The two MXs should be connected to each other through a downstream switch (or ideally, multiple switches) on the LAN to allow for passing VRRP heartbeats.
- There should be no more than one additional hop between them, and they must be able to communicate on all VLANs.
- Make sure STP is enabled on the downstream switching infrastructure, as a properly-configured HA topology will introduce a loop on the network.
- When first configuring routed HA, the spare should be added and configured in the dashboard before the device is physically deployed, so it will immediately fetch its configuration and behave appropriately.
Additionally, the following other considerations should be kept in mind:
- If a virtual IP is being used, each uplink of the two MXs must share the same broadcast domain on the WAN side.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes that is exactly what I understood.
So my original question still remains. With that understanding - how am I best to configure the uplink to my ISP, given that I have been provided with a single IP on /32 and a small range of IP's on /28
Do I create a VLAN on an 8-port switch in front of the MX's - allocate the /32 to the VLAN address and then configure /28 addresses to each MX?
I am looking for best practice in this scenario
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
https://documentation.meraki.com/MX/Deployment_Guides/MX_Warm_Spare_-_High_Availability_Pair
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You meed a router in front of the MX for this to work. A pure L2-switch is not enough, although a Layer3 switch would be fine.
The WAN interface of the router gets the /32, the LAN interface is configured with an IP from the /28.
Be aware that this again introduces a Single point of failure.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tell your ISP you can not use a /32. You need a minimum of a /29.
Ideally, have them present the /28 directly and life will be simple.
Note it is not compulsory to use a VIP.
