Unable to add device to Network: Warm Spare Error

auhyden
Here to help

Unable to add device to Network: Warm Spare Error

I am looking for some help in troubleshooting a device not being able to be added to a network in the Dashboard. I am trying to add a MX64 to the network with the end state goal of establishing it as a spoke for Auto VPN. 

 

Network's current MX84 shows Warm Spare as Disabled on the Appliance Status page. 

 

When I try to add the MX64 to the network, I receive the following error:

"Primary and Spare MXes must be the same model when using Warm Spare"

 

I understand that MX'es must be the same model when utilizing the HA feature. However, is this a default behavior of the MX to assume the HA role and try to pair with the active MX even if Warm Spare is disabled?

14 Replies 14
cmr
Kind of a big deal
Kind of a big deal

You can only have one MX in a network (or an HA pair).  If you want to use another MX you need to create a second network.

In the inventory, there are multiple MX (MX84 is the Active, and MR34) in the network. Warm spare is not configured, and shows disabled in the Appliance Status settings. 

I was curious as to why HA would attempt to establish if it's not enabled.

cmr
Kind of a big deal
Kind of a big deal

Sounds like a GUI bug, HA is disabled if IPv6 is enabled, but even if you disable IPv6 you cannot pair an MX84 and MX64.

So there would be no way to add multiple MX's of differing models to a single network? Does it try to establish HA pairing by default? 

IPv6 is not enabled on the MX84 that we have in the network. 

cmr
Kind of a big deal
Kind of a big deal

@auhyden that is correct, one network has one logical MX, either a single physical box, and HA pair or a virtual appliance.

 

Why would you want to have the MX84 and MX64 in the same network?

My Customer is trying to establish AutoVPN in lieu of a recent critical outage. 

They do not have another MX84 that can be added to the network unfortunately, so they are trying to get the M64 in there.

Following your AutoVPN train of thought, how does that work having the MX64 in another network? Does it a assume a site-to-site VPN between Network 1 (MX84) and Network 2 (MX64)?

cmr
Kind of a big deal
Kind of a big deal

Yes AutoVPN only works between networks.  It is used to connect two networks together over a connection such as the Internet.  Usually this would be two separate locations.  Is that what they want?

Ok good to know. I believe that is what they are doing, and would need to confirm.

cmr
Kind of a big deal
Kind of a big deal

When you say disabled, do you see this?

 

Screenshot_20230822_232205_Chrome.jpg

yes i do. On the Appliance Status page for the MX84. "Configure Warm Spare" shows disabled. 

cmr
Kind of a big deal
Kind of a big deal

If you tap on the triangle a message should pop up saying why it is disabled, on my example you get this:

Screenshot_20230822_233204_Chrome.jpg

This is what I see when I am on the MX for that network's Appliance Status page.
197_74_1.png

What I discovered was the new MX64 that I need to add is going to be at another site, so creating the new network is what I need to do, and set it up as a Spoke to the MX85's Hub site. 

I was running into that Warm spare conflict because by default, the MX will assume trying to create an HA pair hence the reason I got the models are different error. Happy learning under trial by fire! haha.

Thank you for your help!! I will post results once I verify the network is up and running.

cmr
Kind of a big deal
Kind of a big deal

And if you want to use AutoVPN then you want it in a second network.

BlakeRichardson
Kind of a big deal
Kind of a big deal

If you are trying to configure site to site VPN then you need the MX in two seperate networks. If you are not familiar with Meraki you can have multiple networks within a single organisation. Once you have configured the networks the VPN should be easy to setup.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels