High Availability using MS435-32

RCooper
Here to help

High Availability using MS435-32

We have two MS425-32 switches that are stacked, We also have two SD-WAN devices (not Meraki) that are configured for HA.  It has never worked, I am hoping someone has got this configured and working and can share the correct config with me.

Firstly I should mention the SD-WAN devices do not like LACP they have bridged ports.  2 ports per device are configured.

I have set the ports on the MS devices on the same VLAN (2) on trunk ports with RSTP disabled and STP loop guard enabled.

Ports number 1 on the two switches are set to be connected to the primary SD-WAN device and ports number 2 to the secondary SD-WAN device.

Currently, only one port is connected to the SD-WAN device, when I connect the other port on the other switch the internet goes down.  How can I achieve two active uplink ports and two standby uplink ports?

Is there anyone out there with a similar setup that can help me?

13 Replies 13
alemabrahao
Kind of a big deal
Kind of a big deal

You need to have spanning tree enabled, because as you cannot use LACP, STP will block one of the ports to prevent network looping.

The MX also does not support LACP and I configured STP on the switch and it worked as expected.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

RCooper_0-1720015975446.png

So to confirm i should enable RSTP?

alemabrahao
Kind of a big deal
Kind of a big deal

Yes it should.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

I will test it, the supplier of the SD-WAN device suggested that RSTP be disabled

I changed the port config and enabled RSTP but when i connected the two ports the connection was not stable, the constant ping kept timing out and the ping time was not good either

ww
Kind of a big deal
Kind of a big deal

Your should not use loop guard on switch ports from the same switch that connect to eachother on layer2. You blocking port will not go to forwarding when something happens, but it will go into inconsistency state

GIdenJoe
Kind of a big deal
Kind of a big deal

This!

RCooper
Here to help

They connect on Layer 3 they are layer three switches.

cmr
Kind of a big deal
Kind of a big deal

@RCooper they might have L3 features, but they are also L2 switches.

PhilipDAth
Kind of a big deal
Kind of a big deal

>2 ports per device are configured.

 

I would change the devices so they have a single connection.  Connect SDWAN1 to SW1 and SDWAN2 to SW2.  It will be loop-free, and if the HA works - fault tolerant.

I have tried this and when i turn off an SD WAN i lose internet connection

cmr
Kind of a big deal
Kind of a big deal

@RCooper that should definitely not happen.  How are the 425s stacked?

They are stacked as you would normally stack them?  Using the stacking ports.  

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels