Hi Team, I'm testing a dual MX68 warm spare deployment and encountering an issue with VPN failover behavior. Please see the attached network diagram for reference. Setup: Both MX appliances have WAN1 connected to an L2 switch and are configured using a WAN VIP. Each MX LAN port connects to a Cisco 3650 switch (ports configured as trunks). Clients are behind the 3650. Failover Behavior Observed: ✅ When the primary MX’s WAN connection is disconnected: Internet fails over in ~1 second VPN tunnels re-establish within ~30 seconds (expected) ❌ When the primary MX’s LAN connection to the 3650 is disconnected: Internet fails over in ~1 second VPN failover takes 60–90 minutes, or doesn’t complete without intervention I opened a support ticket and was told I needed to submit a feature request to support a LAN side failure. They were unable to provide a recommendation on design or config change to get a fully redundant system. Question: Is this behavior expected when the LAN interface drops? Or is there a potential configuration issue preventing the standby MX from establishing VPN tunnels promptly after LAN-only failover? Thanks in advance for your help!
... View more