Want to shift few wired & wireless users on WAN 2 ISP

NishikaKamat
Conversationalist

Want to shift few wired & wireless users on WAN 2 ISP

Hello,

I have a network of 2 MX84 Firewalls, 2 MS355 Switches & 6 MR53 APs.
I have 2 WAN connections. One is primary of 100Mbps & another is secondary of 50Mbps.
Both are connected to Port 1 & Port 2 respectively of both the Firewalls for redundancy issues.

Now we have a few AWS workspaces which are located in N.Virginia region. But our ISP of 100Mbps is facing high latency some days a week. So I am planning to shift all the users who work on those workspaces to 50Mbps link.
These include wired & wireless both systems.
Can someone guide me how to make sure just a few users in office can access the 50Mbps ISP and remaining work on 100Mbps.

Any help & suggestion would be really helpful. 

3 Replies 3
KarstenI
Kind of a big deal
Kind of a big deal

You need to make sure that these "special" users all have IP-addresses from a unique range (or always get the same IPs with a reservation). Then you can configure flow-preferences under "Security & SD-WAN" -> "SD-WAN & Traffic-Shaping" and assign the right WAN-Link to them.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
PhilipDAth
Kind of a big deal
Kind of a big deal

Building on @KarstenI solution - I think I would be tempted to create a new VLAN.  They use group policy applied to the user to force them into the new VLAN.  Then force everything in that VLAN out WAN2.

 

Otherwise you can give the users static IP addresses.

cmr
Kind of a big deal
Kind of a big deal

If it's the destination that has the latency then you should be able to create a rule to send traffic to that destination

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels