Hi.
Thanks for your reply. Great questions! I'll do my best to answer...
"Prior to adding the Spare MX appliance was this the same configuration from ISP switch > your switch > MX appliance?"
No. The ISP switch went was plugged directly into the WAN1 port on the single MX.
"Were the 1:Many NAT rules in place and working prior to the addition of the secondary MX?"
Yes, they have been in place and working on the single MX for many weeks prior to this change.
"If you power off the secondary MX do the rules start working as configured?"
I can test tomorrow. I'm not on site today.
"What sort of switch are you utilizing between the ISP and the Meraki MX pairing?"
A small ubiquiti/unifi switch.
"What are the port configurations for this switch?"
Port 1 - Vlan99 (access) - connected to ISP's switch
Port 2 - Vlan99 (access) - connected to Primary MX, WAN1
Port 3 - Vlan99 (access) - connected to Spare MX, WAN1
Port 4 - [empty]
Port 5 - vlan80 (access) - connected to Primary MX, Port 12 (PoE)
vlan99 is not routed on any device, including on the MX. It is intended just to isolate the traffic from the ISP to the two MX's.
vlan80 is our management vlan. Port 12 on the MX is PoE (so powers the small switch) and allows management access to the switch.
"Is it possible to plug the MX directly into the ISP switch (either just the primary or the HA Pair) to bypass the additional switch in between?"
Yes... but I only have a single "hand off" (is that the correct term?) from the ISP switch. Only 1 port is live, so I can only plug into either the Primary MX or Secondary MX. I can try this tomorrow also.
My troubleshooting tomorrow will be in the following order...
1. Run packet capture on my switch, mirroring port 1. Check for traffic to .204-.206
2. Run packet capture on my switch, mirroring port 2. Check for traffic to .204-206
(this should give me enough evidence to know if the my switch is an issue, but I will also try #3 below).
3. Plug Primary MX directly into ISP switch, see if IPs .204-.206 are receiving traffic.
Am I right in saying the following...
If test #1 above shows packets are sent to port 1, then the ISP stuff is working fine and to run the next test. Otherwise contact ISP.
If test #2 above shows packets are NOT being sent to port 2, then my switch setup is wrong/not working, replace switch (if have a old, dumb hub I could try instead) and try again. Otherwise if packets are being sent to port 2 then MX must be receiving the packets and the MX (or HA) is broke somehow. Contact Meraki for troubleshooting.