This is something I've battled with for years, and I'm not sure the correct way to do this. The internet connection that comes into my office is a single line. But I have two Meraki MX85 firewalls, one is the failover, one is the primary. If I want the secondary firewall to be able to seamlessly operate when the primary goes offline, how can I do this? I've asked my ISP if they can provide me a second physical connection to the same network connection, and they said this would basically be a new circuit and would charge me double. But if I plug in the connection to the primary firewall as I should, if that primary loses power, then there's no internet connection for my secondary.
I've called Meraki about this multiple times, created multiple tickets and tried many different things to fix this. So far, the only solution anyone has given is for me to put a hub or some other switch in front of the firewall to essentially "split" the uplink to go to the two firewalls. But if I do that, I'm adding more moving parts, and a single point of failire.
Okay, so I fudged the first paragraph to simplify my setup. Here's more detail and my ACTUAL setup: I'm using two ISP uplinks, but both have this same issue where I need to "split" them. I have two MX85 firewalls but one license, so they're primary/secondary and not HA. I've tried even sending the uplinks to Meraki switch ports, assigning a random VLAN to three ports, then "splitting" the uplinks back to the firewalls that way. But that gives me all sorts of STP errors, gives the switches incorrect public IPs, and I had all sorts of ARP flooding on some of the non-dedicated circuits. It was just a nightmare and I had alerts coming dozens per day about the tunnels going down and coming back up.
So - without buying two standalone switches/hubs to split these uplinks, and without paying my internet provider thousands of dollars more a month to get a separate physical connection that I can feed to both firewalls to keep me operational during an outage... what is the correct way to make sure BOTH of my firewalls have BOTH internet connections without one firewall feeding off another?
Thanks - maybe there's a simple answer here, but it seems like the more than a dozen folks I've asked haven't been able to come up with anything. And I say this almost every day to my team at work "there's no way we are the first people who had this issue, look it up or call support". But I've tried so much, on something that seems like it would be an extremely widespread issue that almost everyone here would have had to deal with. Why am I not able to find a simple solution for this?
Thanks, guys.