Home > Switches > Layer 3 Switching > MS Warm Spare (VRRP) Overview

MS Warm Spare (VRRP) Overview

MS Series switches configured for layer 3 routing can also be configured with a warm spare for gateway redundancy. This allows two identical switches to be configured as redundant gateways for a given subnet, thus increasing network reliability for users.  Warm spare is currently available on the MS42, MS250, MS300 series, and MS400 series family of switches.

Enabling Warm Spare

Warm spare switches cannot be stacked or have OSPF enabled. 

  1. Layer 3 switching must be initialized before configuring warm spare.  To enable L3 switching, follow the instructions in the Layer 3 Switching Overview.
  2. To enable warm spare, navigate to Switch > Switches in the Meraki Dashboard.
  3. Select the switch you would like to hold the primary position in the warm spare configuration
  4. Scroll to the "Warm Spare" section of the page and select "Add a new warm spare".
    warm spare.png
  5. Select to Enable the warm spare functionality
  6. Select the switch you would like to hold the spare position

    warm spare 2.png

    All active L3 interfaces and routing functions on the "Spare" switch will be over-written with the L3 configuration of the selected primary switch.

  1. Once you have selected the desired spare, press "Update".

How Warm Spare Works

Warm Spare is built on VRRP to provide clients with a consistent gateway. The switch pair will share a virtual MAC address and IP address for each layer 3 interface. The MAC address will always begin with 00-00-5E-00-01, and the IP address will always be the configured interface IP address on the primary. Clients will always use this virtual IP and MAC address to communicate with their gateway.



When configured, the primary switch will send out VRRP advertisements on each layer 3 (L3) interface every 0.3 seconds. These advertisements will include the L3 switch's priority, configured addresses, and are used to ensure the spare/backup remains aware that the primary is online. When operating normally, the spare will act only as a layer 2 switch, and not perform any routing. All routing functionality will be performed by the primary.


In the event of a failure, such as the primary losing power, the spare will wait for 3 missed advertisements before it assumes the role of primary. When this occurs, the spare will assume ownership of the virtual IP/MAC addresses and begin performing routing functions. Thus there may about 1 second of downtime before the spare is able to take over for a failed primary. Clients will continue to send traffic to the same IP address, and virtual MAC address, as both of these will be shifted from the primary to the spare.


Once the primary comes back online, it will assume control again, and the spare will return to its previous state.

Important Notes

While the setup and operation of Warm Spare is generally simple and seamless, there are some pieces of information that become important when troubleshooting or planning. 


On Cisco Meraki MS Series switches, the following VRRP timers apply:

  • Advertisement/hello timer - 0.3 seconds
  • Hold timer - 0.9 seconds (3 missed advertisements)
  • Preempt delay - Preempt will occur once the configured primary is fully initialized


The primary will use a priority of 255, and the spare/backup will use a priority of 100.


At this time Cisco Meraki MS Series switches can only be configured in pairs from the same family when using VRRP/Warm Spare. Integration with other vendors or platforms is currently not supported.

Ex. An MS250 can only be paired with another MS250.

Settings When Adding a Spare

When adding a warm spare, any previously configured layer 3 settings for the spare will be lost, and the configuration from the primary will be assumed. If this switch is later removed from the pair, it will not regain its original settings. If a primary switch is removed, the spare will not inherit the settings of the primary. In order to pass these settings, the spare and primary status can be swapped before removal and the spare will be configured with the settings for the primary switch once elected and updated.

Management IP

When configuring VRRP/warm spare, the management IP address on the primary cannot also be assigned to a layer 3 interface. This is due to the interface IP address being shifted to the spare in the event of a failover. Thus both the primary and spare must have unique management IP addresses for communication with Dashboard, that do not conflict with the layer 3 interface IP addresses.


Last modified



This page has no classifications.

Explore the Product

Click to Learn More

Article ID

ID: 1128

Explore Meraki

You can find out more about Cisco Meraki on our main site, including information on products, contacting sales and finding a vendor.

Explore Meraki

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case

Ask the Community

In the Meraki Community, you can keep track of the latest announcements, find answers provided by fellow Meraki users and ask questions of your own.

Visit the Community