@Bruce wrote: I’d do one link from SWX1 to primary MX, and a second link to the primary MX from SWX2. Likewise with the standby MX, one link to SWX1 and another to SWX2. Have all links configured the same, and let STP take care of blocking one of the links to each MX. Why would you run redundant link from the Primary MX, as well as the Secondary when running Warm Spare? Is it really that important to keep using the Primary MX? If MX-Pri is connected to SW1 in a stack, and MX-Sec is connected to SW2 in a stack. If Sw1 fails, failover to MX -Sec will occur, and failover time is less than 30 seconds, from failure detection to be processing VPN packets again. Redundant links between MX and switch would imho, only make sense you were aggregating links, but since the MX does not support LACP, that's out of the picture. Depending on your Spanning-Tree domain, when the network converges, you'll might already have exceeded the time it takes for Warm Spare failover.
... View more