SD-WAN SETUP WITH DUAL ISP

Prince
Just browsing

SD-WAN SETUP WITH DUAL ISP

Good day!

 

Newbie here and I was not around during the configuration of our Meraki devices as the contractor had it preconfigured for us.

 

We had a total of 3 offices on which we use SD-WAN to connect from each other.  Office 1 is MX84 and Office 2 & 3 are MX64. Recently, we added secondary ISPs on all our offices. However, if the primary ISP of office 1 was down, it cannot connect to office 2 and 3, same goes with other offices.  All our primary ISPs had public IPs, however, our 2nd ISPs (Starlink) don't have since it is a residential plan and these changes from time to time.

 

Is there a way to connect our offices when a primary ISP went down even without those public IPs of our secondary ISP?  And what would be the configuration/setup for this.

 

Thanks in advance.

4 Replies 4
alemabrahao
Kind of a big deal
Kind of a big deal

This is automatic, so there is a high chance that it is a problem with Starlink.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

It's very simple even without a public IP.

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Load_Balancing_and_Flow_Preferen...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

What was the specific test you performed?  Unlugging the primary ISP from the head office?

 

That should failover and work.  Especially if all of the sites have a public IP directly on the primary WAN interface of the MX.

Amin_Costa
Conversationalist

There's something that might be happening. Probably the VPN between the meraki is configured as "Non-meraki VPN peers". I'm not sure but this might be the case as by default meraki use both links.

 

Check how the VPN is configured:

 

Security & SD-WAN -> Site-to-Site VPN -> Non-meraki VPN peers

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels