Meraki MX in one armed VPN concentrator mode dual uplink to switch stack

Solved
DylanEbner
Conversationalist

Meraki MX in one armed VPN concentrator mode dual uplink to switch stack

Is there a recommended way to dual uplink a meraki MX in one armed mode that doesn't involve a warm spare or L3 between the MX and the stack?

 

Topology:

MX68 -> Cisco 5500 Stack -> Cisco FTD2130 pair - ISPs

 

I'd like to be able to connect each of the mx68 wan ports to a different 5500 switch so I have some redundancy if a switch goes down. The only think I found from meraki was to use two mx68s and put one in a warm spare mode. Others suggested using L3 between the MX and the stack, which I am trying to avoid.

 

 

1 Accepted Solution
DylanEbner
Conversationalist

I found my answer. 

 

In short, not possible without the warm spare.

 

https://community.meraki.com/t5/Security-SD-WAN/Nexus-VPC-with-Meraki-MX100-One-Armed-Concentrators/...

 

Meraki: please add some kind of link aggregation to your devices.

View solution in original post

2 Replies 2
DylanEbner
Conversationalist

I found my answer. 

 

In short, not possible without the warm spare.

 

https://community.meraki.com/t5/Security-SD-WAN/Nexus-VPC-with-Meraki-MX100-One-Armed-Concentrators/...

 

Meraki: please add some kind of link aggregation to your devices.

RaphaelL
Kind of a big deal
Kind of a big deal

Hi ,

 

One-Armed Concentrator

This configuration utilizes an MX device configured to act in VPN concentrator mode, with a single Ethernet connection to the upstream network. All traffic will be sent and received on this interface. This is the recommended configuration for MX appliances serving as VPN termination points into the datacenter.

https://documentation.meraki.com/MX/Deployment_Guides/VPN_Concentrator_Deployment_Guide

 

I don't think that is supported. You will have to run a warm spare if you want redundancy 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels