Replacing MX68W with MX85

DanielBHSNIT
Getting noticed

Replacing MX68W with MX85

We're upgrading our MX68W with the MX85.  The 68W is a hub for our site-to-site VPN's.  I can't find any clear guidance on how I can replace this with a minimum amount of fuss.  I have a three hour maintenance window and was hoping I could add this to the network so I could pre-populate some network configuration but it appears that I can't.

 

Wondering if anyone has some wisdom on how you might have accomplished similar task?

3 Replies 3
ww
Kind of a big deal
Kind of a big deal

I would just use option 1 if i had 3 hours.

But option2 should also work

https://documentation.meraki.com/MX/Other_Topics/MX_Cold_Swap_Replacing_an_Existing_MX_with_a_Differ...

alemabrahao
Kind of a big deal
Kind of a big deal

Have you checked this link?

 

https://documentation.meraki.com/MX/Other_Topics/MX_Cold_Swap_Replacing_an_Existing_MX_with_a_Differ...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
OVERKILL
Building a reputation

I've done this a few times and just replaced an MX84 with an MX85 last night. The Cold Swap link (which currently appears to be unavailable) does a good job of describing the process. 

 

The port assignments will be different, due to the different port layout of the devices, but since you've got 3 hours, that's plenty of time to fix any issues on that front if they arise. 

 

Here's how I would proceed:

 

Before your 3 hour window:

1. Add the new MX to your inventory, don't assign it to a network

2. Fire up the new MX, connect a PC to it and navigate to setup.meraki.com and configure your WAN interface(s) with the static info if your ISP configs are static

3. If you have a fail-over WAN link, you can test to make sure that the new MX can reach the internet by connecting this to the 2nd WAN port on the new device. The status LED should rotate through the colours and then go white. 

4. Make screenshots of your existing configs "just in case". DHCP setup, VLAN's, VPN setup...etc. 

 

When your window arrives:

1. Make sure you have a computer that is connected to a different network that won't be affected by the outage and logged into your dashboard. I tethered to my cell phone for this task. 

2. Navigate to the organization and network you are performing the swap on.

3. After confirming you are on the right network, remove the old MX from the network by clicking the "Remove appliance from network..." button under "Appliance Status" in "Security & SD-WAN". The white status LED will starting blinking. "Security & SD-WAN" will disappear from the available menus on the left side. 

4. Navigate to your Inventory (Organization -> Inventory) and check the box next to the MX85 and click "Add to..." and then add it to the network you just removed the MX68W from.  

5. Refresh the page, "Security & SD-WAN" will reappear. 

6. Navigate to the configuration area for the new MX, under "Addressing & VLANs" adjust the interfaces to reflect how you are going to connect it. 

7. Physically connect the WAN link(s) to the MX85. Apply power. The status LED will cycle and eventually go white. Wait. It will typically perform a firmware update and reboot. 

8. Once the device has finished updating and rebooting and the status LED is solid white, you should see it as online in the dashboard. 

9. Give a quick glance at the configuration for VLANs, DHCP...etc and make sure everything looks correct. 

10. Connect your LAN cable(s) to the new MX. Confirm things are working as expected. 

11. Navigate to your site-to-site VPN config page and re-enable the site-to-site VPN (this is disabled when you replace the MX). Confirm all your tunnels come up and everything is working as expected. 

 

That should be it! 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels