Secondary WAN-Uplink

MrSmith
Here to help

Secondary WAN-Uplink

Hello all, 

 

i configured a second wan uplink to my MX64 in load sharing mode. Both Uplinks running in Nat Mode.

The internet traffic is split across both links.

 

My Problem is, that i can only access the Web Interface of the first Uplink Router. For the second one i get a time out.

I seems something wrong with the routing?! 

 

In a trace i can see that all request to the 2nd router are forwarded to the 1st one.

 

Can someone help me?

12 Replies 12
Adam
Kind of a big deal

Are you accessing it from the outside?

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
MrSmith
Here to help

yes its works

Adam
Kind of a big deal

I think if you go to Security Appliance>Appliance Status you can use the hostname and it'll be dynamic so you don't have to guess or rely on which WAN is online.  But what are you trying to get to it directly to manage?  As long as one of the uplinks is online can't you manage it from the Meraki Dashboard?

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
MrSmith
Here to help

Yes when i try to connect with the hostname, ich can reach each Uplink Router. 

But from inside the local lan i can only connect to the router which is connected to the Wan1 Uplink

MrSmith
Here to help

Yes when i try to connect with the hostname, ich can reach each Uplink Router. 

But from inside the local lan i can only connect to the router which is connected to the Wan1 Uplink

Adam
Kind of a big deal

From the inside you can connect to the LAN interface. No need to use the WAN interfaces unless you are on the outside. 

 

Note:  Make sure under Security Appliance>Firewall that you have the 'Web (local status & configuration)' set to allow whatever client you are connecting from.

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
MrSmith
Here to help

Hi Adam,

 

My Config. 

 

MX64 NAT Local LAN: 10.49.10.0/24

 

Wan1 Uplink ISP-Router: 

local lan: 192.168.2.0/24 (Transfernet)

 

Wan2 Uplink ISP-Router:

local lan: 192.168.3.0/24 (Transfernet)

 

Mx64 Wan1 192.168.2.2 GW 192.168.2.1 (Uplink Router 1)

MX64 Wan2 192.168.3.3 GW 192.168.3.1 (Uplink Router 2)

 

I can connect from 10.49.10.x/24 to the web interface of Uplink router 1 (192.168.2.1)

I can not connect from 10.49.10.x/24 to the web interface of Uplink router 2 (192.168.3.1)

 

Maybe i would be clear what my problem is. 😉

 

Adam
Kind of a big deal

Sorry if I'm asking a lot of question but I'm just trying to be clear on what you are trying to accomplish.  So you are trying to be able to login to each of the ISP Modem/Routers?

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
hoempf
Getting noticed

Hi 

 

I assume the routers you're mentioning (ISP side) are managed by you or at least you have some sort of web access to them and you want to access this page on each of those routers.

 

Now if you have WAN1 on 192.168.2.0/24 and this is the primary WAN interface, then all traffic will flow over this WAN port, also traffic destined to 192.168.3.0/24.

 

What you need is an Internet traffic flow preference rule (Appliance -> Traffic Shaping). There you set traffic destined to 192.168.3.0/24 to use WAN2 and not WAN1.

 

Screen Shot 2018-04-06 at 21.39.58.png

 

This is roughly the same as configuring a static route to WAN2 for this subnet (192.168.3.0/24) on a Cisco IOS router.

 

Please note that the MX only routes TCP and UDP traffic according to this rule, not ICMP. Don't try to ping or traceroute it from 10.49.10.0/24, just connect to the web interface you want to reach.

 

HTH

 

(I hope I understood what you want to achieve, please let me know if I'm wrong 🙂 )

Adam
Kind of a big deal

I was thinking the same thing as @hoempf

 

At one of our sites we have two WANs and occasionally need to get to the management web interfaces.  So we just created 2 flow preferences.  

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
MrSmith
Here to help

Hey guys, 

 

thank´s for your Feedback. 

 

I already created two flow preferences and falsely i tried to ping. damn.

 

Okay but i can confirm that i can reach the web interface.

 

Thank you!

MrSmith
Here to help

Hey guys, 

 

thank´s for your Feedback. 

 

I already created two flow preferences and falsely i tried to ping. damn.

 

Okay but i can confirm that i can reach the web interface.

 

Thank you!

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels