C9300 IOS XE 17.18.2 Meraki Mode - VRRP configurations

Ste
Here to help

C9300 IOS XE 17.18.2 Meraki Mode - VRRP configurations

Dear Community,

 

I am currently facing some confusion regarding the configuration of the VRRP mode on two C9300 IOS-XE 17.18.2

switches that are cloud-native and connected by a fiber link.

 

Here is my current setup: I have designated one of the C9300 switches as the master, with a static IP and preferred uplink configured. Following the guide "Cloud-Managed Switching Warm Spare (VRRP) Overview - Cisco Meraki Documentation" from the Cisco Meraki Documentation, I enabled the warm spare on the master C9300 and created the VLANs with the VRRP option flagged. Additionally, I configured the virtual IP and group ID.

 

Despite saving the configuration without encountering any errors or warnings, I noticed that no IPv4 VIP is displayed on the Routing and DHCP Interfaces page. I have repeated this process several times, but the outcome remains the same.

 

What might be missing in my configuration? About the VLAN IPs for the backup VRRP C9300, do I need to configure these as well?

 

Thank you in advance for your help!

 

Best regards,

13 Replies 13
RWelch
Kind of a big deal
Kind of a big deal

VRRP is not supported for cloud-managed Catalyst 9300 switches running IOS XE 17.18.1 or 17.18.2.  

This is why you do not see an IPv4 VIP on the Routing and DHCP Interfaces page, even after following the configuration steps.

 

No further configuration will enable this feature until Meraki adds support in a future release.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Ste
Here to help

on this link Cloud Configuration: Release Versions and Highlights - Cisco Meraki Documentation I see that for 17.18.2 is supported.

 

can you confirmed?

RWelch
Kind of a big deal
Kind of a big deal

You are correct @Ste .

If you are running IOS XE 17.18.2 or newer and do not see the virtual IP (VIP) on the Routing and DHCP Interfaces page, verify both switches are running the correct firmware, are cloud-managed, and are configured as Layer 3 gateways in the same network. Ensure the warm spare configuration is complete, both switches have unique management IPs, and are online in the Meraki Dashboard. If the issue persists, try rebooting the switches or reapplying the configuration.

You do not need to manually configure VLAN IPs for the backup VRRP switch; the warm spare configuration will handle the virtual IP assignment for VLAN interfaces.
If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Ste
Here to help

What do you mean with:

 

configured as Layer 3 gateways in the same network?

 

do I need to configure something on the backup switch about?

RWelch
Kind of a big deal
Kind of a big deal

Both switches in a VRRP (Warm Spare) pair must:

- Be part of the same Meraki Dashboard network (managed together in the same dashboard container).
- Have Layer 3 interfaces (SVIs) configured for the VLANs/subnets you want to protect with VRRP.

You do not need to manually configure Layer 3 interface IP addresses for the backup switch. The Meraki Dashboard automatically synchronizes the configuration from the primary to the backup when you enable Warm Spare (VRRP).

Add both switches to the same network in the dashboard, enable warm spare (VRRP) on the secondary switch and select the backup switch as the spare, ensure both are online and have unique management IPs.
If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Brash
Kind of a big deal
Kind of a big deal

Can you use the Cloud CLI (as shown in the page you linked) to validate whether it has correctly applied?

You should be able to check both the configuration and the VRRP state.

 

That should indicate whether it's not actually working, or whether it's a GUI issue

Ste
Here to help

If i check on CLI the show vrrp I've results only on the Primary core switch, for spare no output:

 

-------------------------

 

SW-CORE-01#show vrrp

Vlan10 - Group 10 - Address-Family IPv4

State is MASTER

State duration 39.635 secs

Virtual IP address is 10.80.10.1

Virtual MAC address is 0000.5E00.010A

Advertisement interval is 1000 msec

Preemption enabled

Priority is 100

State change reason is VRRP_PRIORITY

Master Router is 10.80.10.2 (local), priority is 100

Master Advertisement interval is 1000 msec (expires in 798 msec)

Master Down interval is 3609 msec

FLAGS: 1/1

SW-CORE-01#

 

--------------------------------

 

SW-CORE-02#show vrrp

SW-CORE-02#

Ste
Here to help

after rebooting core-02 when I try to set VRRP on the interfaces without the preferred uplink flag, I receive the message: "Default Gateway can only be set if the interface is designated as the V4 uplink."

 

Could you please provide any insights or suggestions on how to resolve this issue?

RWelch
Kind of a big deal
Kind of a big deal

Unfortunately you might need to ask support for assistance as they can see what's going on with the backend or what the hiccup seems to be getting it to work as it's supposed to.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Brash
Kind of a big deal
Kind of a big deal

I agree with @RWelch at this point.
It's difficult to know exactly how you have it configured and there are multiple possibilities as to what could be the issue. Your best bet is to jump on a call with Meraki support and walk them through your configuration.

Don't forget to circle back here once you do. It's always good to have closure and a resolution for people who come across the post in the future.

Ste
Here to help

Opened: Cisco Meraki Case 13878525. They escaleted with an internal case to have product specialist team review.  

 

I'll keep you posted

Ste
Here to help

 

I share a summary of the latest update I received from support:

 

The Warm Spare feature is not supported for the Catalyst line. For VRRP configuration on Catalyst, each switch needs to have a dedicated SVI. The knowledge base documentation on this topic is somewhat unclear.

 

While the VRRP function is configured and visible only through the switch CLI, it does not show up in the Dashboard. Cisco is currently working on this issue and aims to remove the Warm Spare option from the Dashboard for Catalyst switches. However, there is no estimated time of arrival (ETA) for a resolution at this moment.

 

Could someone in the community confirm this information as well? Your insights would be greatly appreciated.

 

Thank you!

 

cmr
Kind of a big deal
Kind of a big deal

Sounds lovely - GUI only does X, CLI only does Y...

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels