Moving DHCP to L3 MS-425

Chapelhill_IT
New here

Moving DHCP to L3 MS-425

We currently have an older MX-100 that is running VLANs / DHCP for the entire site.  We run about a dozen VLANs.  Currently the MS-425 is a L2 switch.  We have a pretty substantial inter-VLAN traffic flow and I'd like to move the DHCP / VLAN configuration from the MX to the MS.  What is the best process to make this change and minimize downtime?

 

Can i setup everything in the MS-425 first and let the MX keep handling the traffic and then make a hard change to the MS device?  From what i've read i only need to configure one access VLAN on the MX when all is said and done?

 

Thanks for the advice here.

7 Replies 7
RWelch
Kind of a big deal
Kind of a big deal

MX and MS Basic Recommended Layer 3 Topology 

I would definitely plan to make the change during a maintenance window or period in which won't impact a lot of users.  Be aware that when you make the change to select the unique client identifier there will be some client/device data will change in the dashboard.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Chapelhill_IT
New here

Do i only keep the Management VLAN in the MX but move all VLAN / DHCP (including DHCP for management VLAN) over to the MS?  Referring to this article:

https://documentation.meraki.com/Architectures_and_Best_Practices/Recommended_Topologies/MX_and_MS_B...

 

Trying to make sure in the move i don't suddenly break access to switches if that makes sense.

RWelch
Kind of a big deal
Kind of a big deal

Screenshot 2025-05-30 at 18.53.55.png

This is what your interface editor options will look like after you make the change to L3.

You will need to select the right switch, give it a name, VLAN, IP/Subnet and gateway.  You will set the DHCP parameters below that (DHCP settings).

 

MS Layer 3 Switching and Routing 

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RWelch
Kind of a big deal
Kind of a big deal

If you are using existing IP subnet on the MX, you will need to delete it from the MX and move it to the MS.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RWelch
Kind of a big deal
Kind of a big deal

You can use the same login that you use for the Meraki Community page to view the L3 setup in the Meraki Learning Hub:

Learn more with this free online training course on the Meraki Learning Hub:

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Chapelhill_IT
New here

Just went thru the Layer 3 routing course and it def helped clarify a few things.  I did come up with a few questions regarding affect on site to site VPN.  Responded to your direct message with that concern.

Boomerang94
Meraki Employee
Meraki Employee

@Chapelhill_IT although it is already mentioned in the article @RWelch has shared above, the overall idea is as follows:

- Carefully move all the vlans and their gateway IPs (except the MS management one) to the MS425 

- As you are moving these VLANs - ensure correct static route on the MX as well pointing towards the MS425 for the correct subnets.

- Once you MS switch is capable of handling most of the VLANs - only have one transit VLAN between the MX and the MS425. You can either do this via access port or trunk port with pruned VLANs. Also, ensure a static default route on the L3 MS towards the MX. 

- Ensure that the management interface and transit VLAN SVI of the MS425 are two different IPs and management interface points to MX as its gateway.

 

 

Although, I have seen some scenarios where the customers are using more than just 1 transit VLAN between MX and Layer 3 MS - and it does work but not considered as best practice. 

If you get into any complications when performing this task, just reach out to Meraki support via https://meraki.cisco.com/support/ 

.ılı.ılı. Cisco Meraki
Network Support Engineer

### If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it ###
Get notified when there are additional replies to this discussion.