VPN and Warm Spare

ylutigneaux
New here

VPN and Warm Spare

Hello !

 

I have configured a VPN site to site between à MX105 and a MX68. It's working great. 

 

I have tried to hade a second MX68 to do a warm spare. The warms spare is working great for Internet connection. I have only one internet connection, the both MX68 are connected by a switch to the conenction internet

 

But When i do a swap between my primary to my slave, the VPN connection is lost and don't restart even a long time. 

 

I tried with Virtual IP adresse in warm configuration and without but it's the same problem. 

 

Have you any idea of the problem ? 

 

Have a nice day,

Yoann

4 Replies 4
KarstenI
Kind of a big deal
Kind of a big deal

Do both of your MX68 have a public IP? I've seen ISPs where the first device got the public IP from a /30 but the second only a private IP from a DHCP pool. This could break VPN connectivity.

And are you talking about AutoVPN or a manual IPsec config?

Hi Karstenl,

 

In fact i could identfy that the main problem come from Cellular connection. When i get out the SIM Card from my first Meraki it's working great. 

 

I have made an AutoVPN configuration. 

 

I am searching for some info on cellular conenction. I break my Warm spare to test with only one MX. I am able to get a VPN connection without SIM Card but not when i have SIM Card and Wan connected... 

ylutigneaux
New here

I Think i got it... I activate this "Do not create VPN tunnels over the secondary uplink unless the primary uplink fails." in SD-Wan configuration.

 

To my minf, MX is unable to connect VPN between the Cellular and Wan connection at the same time. So with this option, i activate Tunnel on cellular only when WAN1 come down. 

 

Now it's working as i want. 

 

Thanks for help 

👍

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels