Sonicwall port shield group with Meraki switch

I have an Sonicwall nsa 3600 with port 12-15 in a port shield group with a couple vlans.  The 1gb fiber ports are going to a Meraki ms420 fiber aggregation switch.  According to Meraki dashboard, 3 if the 4 ports are discarding stp.

Should the fiber ports on the Meraki be in a link aggregation ?  Why is this happening. Have I miss-configured something on the nsa ?
LVL 1
Leigh KalbliAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Aaron TomoskySD-WAN SimplifiedCommented:
Yes, you have to enable LACP, otherwise stp will block the other ports to avoid a loop
0
Leigh KalbliAuthor Commented:
Hello.  I am unsure how you enable LACP.  I believe its just by "aggregating" from the web ui but the ports say they are running LACP but its been disabled.
0
Aaron TomoskySD-WAN SimplifiedCommented:
Both devices have to be setup for this to work. You may need to be onsite as sometimes the LACP configure step fails when it has active links. If so, unplug all the links you are trying to aggregate during the below setup steps.

first, set it up on the meraki switch
https://documentation.meraki.com/zGeneral_Administration/Tools_and_Troubleshooting/Link_Aggregation_and_Load_Balancing
"In order to configure 2 or more ports (up to 8) to be a port aggregate, simply navigate to Configure > Switch ports and select the target ports, then choose "Aggregate Ports". It is recommended that you do not have the target ports physically connected to anything during this step. "

then setup the sonicwall
https://www.sonicwall.com/en-us/support/knowledge-base/170505988976495
After setting up the port shield: "From the Switching | LinkAggregation page, click on the Add button to select the ports for a Link Aggregation (LAG) bundle, multiple ports maybe added to a LAG bundle one at a time. A SonicWall LAG bundle may have from 2 to 4 ports."
0
Introducing the "443 Security Simplified" Podcast

This new podcast puts you inside the minds of leading white-hat hackers and security researchers. Hosts Marc Laliberte and Corey Nachreiner turn complex security concepts into easily understood and actionable insights on the latest cyber security headlines and trends.

Leigh KalbliAuthor Commented:
When i go to create my Link Aggregation on the NSA, it does not show my ports as available.  I am using an NSA 3600, and ports 12,13,14,15

Capture.PNG
Capture1.PNG
Capture3.PNG
0
Leigh KalbliAuthor Commented:
I spoke to SW Support about this and they said not to use port shield but to use the link aggregation option.  I did so but i still receive a the same thing.
0
Aaron TomoskySD-WAN SimplifiedCommented:
Perhaps it's a bug with your version? This works with lacp, I've done it with exactly these directions.
0
Leigh KalbliAuthor Commented:
What version of Sonicwall OS are you on and what model?
0
Aaron TomoskySD-WAN SimplifiedCommented:
It was a few years ago, nsa3600 6.something. I don't have access to it anymore sorry.
0
Leigh KalbliAuthor Commented:
NP. im using a 3600 as well but current FW from Jan.  I have a follow up call scheduled with SW.
0
Aaron TomoskySD-WAN SimplifiedCommented:
My only tip is to remove everything from the ports you are going to lacp. Any special configs and unplug all wires. Lacp won't setup sometimes if those ports are in use, this isn't SW specific, it's an issue with all vendors
0
Leigh KalbliAuthor Commented:
I had a follow up call with SW on this.  It seems that when trying to aggregate all 4 1GB fiber ports, the issue coems up. but doing two LAG's with 2 ports each works.  The support rep is looking into if there is an issue with the 4 port LAG.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Leigh KalbliAuthor Commented:
Settled on 2 port aggregates. SW didnt have an ansewer.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.