- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No internet access from lan device through warm spare cluster
Newbie question probably 😉
Have two mx105 configured with separate public IPs I get from ISP. They're connected to dashboard, warm spare shows which one is current primary, spare is "passive ready" so all should be fine. I have also third public IP from ISP and I set is as Virtual IP.
Somehow when I try to reach internet from a core switch directly connected to one of primary mx lan ports it doesn't work. Traceroute to 8.8.8.8 from it stops at meraki (meraki is it's default gateway). Core switch and meraki are connected by trunk port and communicating over vlan400 - 10.255.255.0/29. Both meraki and core have ip addresses in this vlan .1 & .2 respectively and they can ping each other.
Do I need to enable masquerading somewhere? Meraki has default route pointing to WAN Uplink.
When im pinging google from primary or secondary uplinks ip's - it works, but when I try to choose as a source virtual ip then it fails.
Solved! Go to solution.
- Labels:
-
Other
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, looks like the problem was with this specific ip address I picked for VIP.
When I setup different one - it started to work 😅
I've created ticket with ISP support to verify why
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pings to 8.8.8.8 should also work from the virtual IP source. Might have something upstream from the MX interfering?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Taking a capture on the MX itself while performing ping tests to Google DNS, I can see it does attempt to communicate out on the VIP, and sees no response, while the uplink IP does see a response. Any idea what that could be? Ip I use for VIP wasn't in use since about couple of months. ISPs are caching mac addresses or what?
Here is how it looks. Red is active internet connection.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could be something on the WAN switch blocking the VIP like an access list. You could do a capture on the ISP side of the WAN switch to see if the ping goes out to the ISP. On the ISP side, if your VIP is part of the /29 attributed to you, I don't see any reason for them to be blocking the VIP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, looks like the problem was with this specific ip address I picked for VIP.
When I setup different one - it started to work 😅
I've created ticket with ISP support to verify why
