{"id":5758,"date":"2025-11-16T19:22:10","date_gmt":"2025-11-16T18:22:10","guid":{"rendered":"https:\/\/cyber-fi.net\/?p=5758"},"modified":"2025-11-16T19:22:27","modified_gmt":"2025-11-16T18:22:27","slug":"connecting-wan-switches","status":"publish","type":"post","link":"https:\/\/cyber-fi.net\/index.php\/2025\/11\/16\/connecting-wan-switches\/","title":{"rendered":"Connecting WAN-Switches"},"content":{"rendered":"\n<p>This is Part 3 of the \u201eConnecting Meraki MX to \u2026\u201c series.<\/p>\n\n\n\n<p><strong><a href=\"https:\/\/cyber-fi.net\/index.php\/2022\/03\/13\/how-to-connect-the-meraki-mx-to-ms-switches\/\" target=\"_blank\" rel=\"noreferrer noopener\">How to connect the Meraki MX to MS switches (Part 1)<\/a><br><\/strong><a href=\"https:\/\/cyber-fi.net\/index.php\/2024\/02\/19\/connecting-your-meraki-mx-to-the-internet\/#comment-53357\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Connecting the Meraki MX to the Internet (Part 2)<\/strong><\/a><\/p>\n\n\n\n<p>In Option 6 and 8 of Part 2, I use a link between the two WAN switches:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"374\" src=\"https:\/\/cyber-fi.net\/wp-content\/uploads\/2024\/02\/5-Dual-MX-2-ISP-2-1024x374.jpg\" alt=\"\" class=\"wp-image-5499\" srcset=\"https:\/\/cyber-fi.net\/wp-content\/uploads\/2024\/02\/5-Dual-MX-2-ISP-2-1024x374.jpg 1024w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2024\/02\/5-Dual-MX-2-ISP-2-300x109.jpg 300w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2024\/02\/5-Dual-MX-2-ISP-2-768x280.jpg 768w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2024\/02\/5-Dual-MX-2-ISP-2.jpg 1537w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p>One question could be if this link is really needed. And as always, the answer is \u201eit depends\u201c.<\/p>\n\n\n\n<p>For me, there are typically two reasons to use the setup with the cross-link:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Limited ports on the Firewall<\/h3>\n\n\n\n<p>To be able to manage both switches, they need to be reachable from the active firewall. With the cross-link, we have the direct link from the active firewall to switch one, and reach switch two via the cross-link between switch one and switch two.<\/p>\n\n\n\n<p>Without the cross-link, we need two links from both firewalls to both switches:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"981\" height=\"466\" src=\"https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches.jpg\" alt=\"\" class=\"wp-image-5760\" srcset=\"https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches.jpg 981w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches-300x143.jpg 300w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches-768x365.jpg 768w\" sizes=\"auto, (max-width: 981px) 100vw, 981px\" \/><\/figure>\n<\/div>\n\n\n<p>And if we have devices with a small number of interfaces like the MX64 or the MX67, we are \u201ewasting\u201c two interfaces instead of using only one per firewall.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Additional devices on the WAN switches<\/h3>\n\n\n\n<p>Because of the limitations of extranet L2L-VPNs on the MX, I often pair a Cisco Secure Firewall with the MX. Depending on the setup, I sometimes prefer to have both (or more) ISPs on a single interface using subinterfaces instead of having one interface per ISP.<\/p>\n\n\n\n<p>With this setup, the firewall connected to WAN-switch one needs to be able to reach the ISP router connected to WAN-switch 2. And this is also done through the cross-link:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"981\" height=\"628\" src=\"https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches2.jpg\" alt=\"\" class=\"wp-image-5761\" srcset=\"https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches2.jpg 981w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches2-300x192.jpg 300w, https:\/\/cyber-fi.net\/wp-content\/uploads\/2025\/11\/WAN-Switches2-768x492.jpg 768w\" sizes=\"auto, (max-width: 981px) 100vw, 981px\" \/><\/figure>\n<\/div>\n\n\n<p>Would I say that the setup with a cross-link is better than a setup without? No, it\u2019s only different and both can be the right solution based on the environment.<\/p>\n\n\n\n<p>Always stay connected!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is Part 3 of the \u201eConnecting Meraki MX to \u2026\u201c series. How to connect the Meraki MX to MS switches (Part 1)Connecting the Meraki MX to the Internet (Part 2) In Option 6 and 8 of Part 2, I use a link between the two WAN switches: One question could be if this link <\/p>\n<div class=\"read-more-text\"><a href=\"https:\/\/cyber-fi.net\/index.php\/2025\/11\/16\/connecting-wan-switches\/\" class=\"read-more\">continue reading<\/a><\/div>\n","protected":false},"author":2,"featured_media":5763,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[5,705,14],"tags":[702],"class_list":["post-5758","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cisco","category-meraki","category-networking","tag-meraki-mx"],"_links":{"self":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/5758","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/comments?post=5758"}],"version-history":[{"count":5,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/5758\/revisions"}],"predecessor-version":[{"id":5766,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/5758\/revisions\/5766"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/media\/5763"}],"wp:attachment":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/media?parent=5758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/categories?post=5758"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/tags?post=5758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}