Hi all,
My company decided to go for Meraki some months ago, and I am still struggling with some issues that I'd like to share to see if anyone else is facing them.
we have a couple of MX600 working as active - warm spare, both units are connecting with 1 x 10ge link to 2 MS425 switches working in stacked mode. Both firewalls are also directly connected between them for VRRP purposes.
1 - My first surprise comes when I see that one of the ports in the switch, the one connected to the active MX unit, is in STP discarding mode. I raise the issue and Support says this is how Meraki Stack switches work (??), and the firewall works with VRRP, passing also the STP BPDUs through the link between them, therefore creating a loop that the switches need to block. OK... How is possible that there is root bridge election within stack members?
2 - The firewall doesn't seem to monitor the LAN ports, as it only relies on VRRP packets, if we remove the cable connected between them, and any of the switches fail, we face a brain split issue impacting all the internet. therefore, we need that cable in place, and if you don't have crossed connections between firewall and switches, you will have a problem because the active unit REMAINS active even if there's no LAN connection anymore.
3 - I have powered off the switch connected to the active firewall, and I was shocked that it took 1.35 minutes for ALL my traffic to recover, it should rely only in STP, isn't it? and even with the RSTP timers, any impact is just not acceptable in a corporate environment. Just to mention that when powering it back it caused another 35 of service disruption. For this point, I am waiting for the reply.
The HA setup is just giving us many issues. I don't know if you guys are also experiencing these problems?
Thank you.