Meraki MX High Availability Feature

Dinky
Comes here often

Meraki MX High Availability Feature

Hi Everyone,

 

I am currently investigating an issue in our organization.

It seems that that the secondary MX has taken over as the master MX.

 

One thing I noticed is that the primary MX lost connectivity to one of the uplinks.

In this case, what VRRP priority does it send to the secondary MX? I assume it is lower than 235.

 

The KB article on Meraki website only mentions failure of 2 uplinks.

It doesn't explicitly mentions failure of 1 of 2 uplinks.

 

Thank you.

 

Link to KB article: https://documentation.meraki.com/MX/Networks_and_Routing/Routed_HA_Failover_Behavior

3 Replies 3
Ryan_Miles
Meraki Employee
Meraki Employee

A single uplink failure on an active MX with two working uplinks would/should not cause a failover to the spare MX. Only if all uplinks on the primary MX fail should the spare MX take over based on VRRP mechanics. 

 

The failover process is active MX primary uplink > secondary/remaining uplink > spare MX primary uplink > spare MX secondary/remaining uplink.

 

This assumes WAN links are actually working and VRRP is passing correctly on MX LAN port(s). What is your topology? Are the MXs connected to downstream switches only? Is there also a direct connection between MXs? Are all VLANs allowed on the MX LAN ports or do you have drop untagged traffic enabled on the MX?

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Dinky
Comes here often

Hi Ryan,

 

Thank you for the detailed response.

We have 2 MX that are connected via downstream MS switch.

These 2 MX are also connected to 2 different ISPs:

Primary MX WAN1 - ISP1

Primary MX WAN2 - ISP2

 

Secondary MX WAN1 - ISP1

Secondary MX WAN2 - ISP2


Right now ISP2 is down on Primary MX, and for some reasons the Secondary MX took over as Master FW.

Ryan_Miles
Meraki Employee
Meraki Employee

My recommendation is to open a Support case. They can access your network and troubleshoot it.

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels