One-Armed Conentrator HA

Maiquel
Comes here often

One-Armed Conentrator HA

Hello Folks,

This is my first post on community.

I have 2 x MX450 in HA mode one-arm vpn Concentrator over Palo Alto Firewall. In MX1 Internet interface 10.9.2.120 MX2 Internet interface 10.9.2.121 and WAN 1 shared IP 10.9.2.122.
In my branch i have 1 link MPLS and 1 Link internet all connected in the meraki cloud. When i put the concentrator in HA mode the VPN with Branch over Internet does not work, just over MPLS. I remove the cable in the branch wan2 (MPLS), but route show-me "bad". When i remove the HA all its ok.

2 Replies 2
MilesMeraki
Head in the Cloud

Hello @Maiquel, welcome to the community.

 

Just so that I follow you when you remove the HA arrangement (i.e you have two separate MX450 in concentrator mode), the Auto-VPN over MPLS and internet for the Branch is up. When you put the MX450's into HA, the Auto-VPN works only over the MPLS connection?

 

Is this a correct assumption of your problem?

Eliot F | Simplifying IT with Cloud Solutions
Found this helpful? Give me some Kudos! (click on the little up-arrow below)
Maiquel
Comes here often

Hi @MilesMeraki, tks for your help.

 

I had some problem with ACL and NAT over Palo Alto for VRRP VIP. I did change and it worked. 

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels