- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 MXs with multple VLANs
Hello
We have TWO MXs configured with multiple VLANs. I need to a device to access device across the MXs. Is this possible without adding the VLAN to each MX? Sorry if this is confusing or I am not explaining properly, but I am attaching a diagram to help. Thank you for your help.
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, the subnet must be the one you want to access from the peer side.
Like the image I sent, if on the MX1 you want to reach the 100.x.x.x network that is on the Mx2 then your route has to be as follows.
Subnet 100.x.x.x/24 (just an example) next hop 172.16.1.2 (MX2 interface IP).
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to add routes on each MX, but for that each MX needs to be on a link VLAN to be able to point the next hop.
So you can create vlan 999 (for example) with a /30 address on each MX and then just add the static routes.
Or just configure SD-WAN.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you consider using SD-WAN (in my opinion it's the best way) don't forget that one of the MXes must be the HUB.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would choose static routes.
It saves you the impact/load of tunnel encryption on the mx, less latency on you sessions, and no mtu reduction
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I agree, but he also asked for a way without having to create another SVI, in which case SD-WAN "would be" the best way.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To confirm the static route would live on the MX configured without the VLAN I need to reach, correct?
Ill give this a shot, thanks again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, but you need to have a common VLAN on each MX with a configured IP, to point the next hop.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some thing like this.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I configured the common VLAN with a uniquire Gateway IP will save no issues.
The issue is now when I add the static Route, I use the subnet of the VLAN and next Hop IP, I get the following message:
- Static lan route subnets cannot be contained by (or be equal to) a VLAN subnet.
Which subnet should I use when adding the static route to MX 2? MX 2 is where I am adding the common VLAN. In your example I am using the VLAN 999 subnet 172.16.1.0/30 next hop 172.16.1.1
On MX1 I just added static route 172.16.1.0/30 next hop 172.16.1.2, this saved without error.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, the subnet must be the one you want to access from the peer side.
Like the image I sent, if on the MX1 you want to reach the 100.x.x.x network that is on the Mx2 then your route has to be as follows.
Subnet 100.x.x.x/24 (just an example) next hop 172.16.1.2 (MX2 interface IP).
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah I now see my mistake. Static route is working, thank you for the help kind sir! Virtual pint on me!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The two MXs would need VLANs with unique subnets to make this work.
