I use a dedicated heartbeat/VRRP connection between MX nodes when the LAN network is not managed by us but by a 3rd party (i.e. the customer). The LAN is then an untrusted network with no visibility or management capabilities. The dedicated connection is using a separate vlan (access port). Whatever happens on the unmanaged LAN is not taken into consideration to trigger a failover but the WAN interfaces will ALWAYS trigger a failover. If the MAIN MX looses a WAN interface, there will be a failover to the SPARE MX. Tested and working
... View more