Cisco support referred me to this link: . https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Connection_Monitoring_for_WAN_Failover#Connectivity_Tests So yes in fact this is the expected behavior and there is no option to change it or specific a choice of IP addresses for the WAN connectivity test. It is interesting to note that with 8.8.8.8 dropped in my upstream firewall there is no failover attempt to use 209.206.55.10 or at least I see no ICMP traffic other than the attempts for 8.8.8.8, so the description of "209.206.55.10 or 8.8.8.8" must mean whichever IP Cisco decides to code in. I have also noticed that with 8.8.8.8 dropped, the Dashboard still shows the switch as Online, so I see no reason to open the firewall to allow ICMP to/from Google. Thanks for all your input
... View more