Swapping ISP provided MX250

MerUser874
Here to help

Swapping ISP provided MX250

We have a Meraki MX250 provided by our ISP. Our contract is almost up, so I purchased another MX250 and plan to swap the old one for this new one.
A quick background to our setup, we have two offices, each with an MX250, and we have two MX licenses in our Dashboard. Our Meraki licenses are co-termed.
I've looked online for the specifics on swapping this out, and between that and an AI search, I have the basics on how to swap out this firewall.
It starts with claiming the new MX in the Dashboard. The next step is to remove the MX we are replacing from its current Network (Temporary Step), and add the new MX to this same Network. It says that this will allow the new MX to inherit the current MX250 config, but it says this would also keep all the users online through the old MX, even though it is out of its Network.
Does this sound correct?

 

Since we only have two MX licenses, but at one point will have 3 MX250s running during the switchover, will this affect anything in any way?


I talked to Meraki, and they said we do not need to purchase a separate MX license since we're just swapping out the hardware.

After this, it gets into the physical setup/hookup of the new MX hardware, recommending to hook up the LAN port on the new MX so it can apply the inherited config, and then move all of the other cables over and verify everything.
Having never done this, I guess my big question is, once the old MX is removed from its Network container and the new MX is added, will the old MX still provide internet to the clients?


I couldn't find this in any documentation, and I just want to make sure that AI is not hallucinating this step.

6 Replies 6
RWelch
Kind of a big deal
Kind of a big deal

How To Replace An Existing Meraki MX - Meraki Dashboard Tutorial 

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Mloraditch
Kind of a big deal
Kind of a big deal

I suggest reading the official KB for this here: https://documentation.meraki.com/SASE_and_SD-WAN/MX/Operate_and_Maintain/How-Tos/MX_Cold_Swap_-_Repl...

Users will not stay online while you do this swap. There will be a minimum of some bump while you move cables with Method 2 in the docs. Method 1 would be more of a bump because config will have to download and apply, but Method 1 preserves client data, etc, which may be important for you.

I do also suggest getting the new MX online in a cloned or dummy network with firmware settings matching the live so that firmware is updated before you do the swap.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
MerUser874
Here to help

It's looking like Method 1 is going to be the way to go. As for the dummy network to get the new MX updated, will us only having two MX licenses make a difference when we add the new MX to this dummy network?

I'll do this early one weekend morning, so a little downtime is not a huge issue, but I also don't want to send up any licensing red flags with Meraki.

Mloraditch
Kind of a big deal
Kind of a big deal

No, you have 30 days grace period once you go out of license compliance so you will be fine, it will be back in compliance as soon as you are complete.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
PhilipDAth
Kind of a big deal
Kind of a big deal

>but it says this would also keep all the users online through the old MX, even though it is out of its Network.
>Does this sound correct?

 

That is not correct.  The network will go down during the swap over.

 

It has mistakenly referred to the process of adding a warm spare, but you are not adding an MX, you are replacing an MX.

MerUser874
Here to help

Thanks so much, I'm glad I checked.

It's looking like Method 1 above, that Mloraditch mentioned, is going to be the way to go.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels