Sorry for my English not good ! Model as shown - I do not use direct connection. The hypothesis is that when deliberately break between MX Master and Core SW => The result is the appearance of "Dual Master" on two MX devices. In the test, when the Master lost the WAN connection (Two ISPs are different between MX Primary and Spare), or fail-over (power-off), MX Spare became the "current master". In fact, sometimes 2 MX devices are still working normally, but the link from MX Master to Core SW is interrupted, Local Lan is still on the normal internet, at this time the traffic goes through MX Spare , but the VPN connection was unsuccessful, because the Site-2-Site VPN connection between MX Branch and HQ was still in Primary MX. VRRP in the configuration of other network devices, support "tracking" feature on the interface, but I found meraki does not support this feature.
... View more