Greetings, Prior to adding the Spare MX appliance was this the same configuration from ISP switch > your switch > MX appliance? Were the 1:Many NAT rules in place and working prior to the addition of the secondary MX? If you power off the secondary MX do the rules start working as configured? What sort of swith are you utilizing between the ISP and the Meraki MX pairing? What are the port configurations for this switch? If the same behavior is still in place where the MX is not receiving on the WAN captures even with the spare powered off it would be great to have the captures from your switch both on the port connected to the ISP switch along with the port connected to the MX to ensure that the swtich is properly receiving/sending the traffic over the required ports. Is it possible to plug the MX directly into the ISP switch (either just the primary or the HA Pair) to bypass the additional switch in between? This may be beneficial if your capture from your switch shows the same behavior where you are not seeing the inbound traffic for the 204, 205, and 206 IP addresses and would then be easier to ask the ISP where that traffic is going since its not making it to the MX appliance.
... View more