Maximum vlan ( limit ? ) on a MX

RaphaelL
Kind of a big deal
Kind of a big deal

Maximum vlan ( limit ? ) on a MX

Hi there ,

 

We have a setup that requires 500+ vlans. Currently we are using MX84/MX85. However when we bind the MX to the template , they can take up to a week to come online. We tried with a MX250 and it took 25 minutes. 

 

It can't even "fetch" the config which is weird. I could probably create 1000 vlans on pfsense running on a RPI1 , I don't see why a MX85 couldn't do that.

 

 

Has anyone ever tried a large amount of vlans on a small/medium size MX ? 

 

Yes we did open a case.

10 Replies 10
alemabrahao
Kind of a big deal
Kind of a big deal

Wow, why so many VLANs?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
RaphaelL
Kind of a big deal
Kind of a big deal

The design is questionable ( I 10000% agree ). Something like 85 floors / 6 vlans per floor. 

 

It's a stupid design but I have to get it working. 😤

Ryan_Miles
Meraki Employee
Meraki Employee

With that amount of floors & VLANs what is the expected client count? I'd have to imagine something way higher than a MX84 or MX85 can even handle from a flows perspective. 

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RaphaelL
Kind of a big deal
Kind of a big deal

Currently 200 clients.  We have to provision the vlans even tho there might never be any clients in that vlan.

 

So the MX85 is checking all the boxes performance wise.

Ryan_Miles
Meraki Employee
Meraki Employee

krule-john-c-reilly.gif

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RaphaelL
Kind of a big deal
Kind of a big deal

Our large campus are all defined the same way. We made "molds" or templates so that one size fits all.

 

Why so few clients ? Well this MX only routes "external" vlans ( non corporate assets ).

6 vlans ? 1 for HVAC , cameras , IOT , and so on. And these devices are not present on every floor but in the case that a new installation would require a device to be placed in the IOT vlan , that vlan would already be present. That's why. Not my design. Frankly it's trash , but I have to live with it a couple more months.

 

 

Anyway we are getting side tracked.

A brand new MX85 out of the box can't even load the dummy config.  We tried 100 vlans, takes 10 mins. 200 vlans takes 30-60mins. 300 even more and to a point that the MX doesn't even come online.

Even a "beefy" MX250 can take 10-20-30 minutes to load a simple config with many vlans. Engineering is going to repro this in their lab next week. So I will get some answers.

alemabrahao
Kind of a big deal
Kind of a big deal

The only thing that I know is that you can only have a maximum of 255 VLANs configured on MXs in HA. - Dashboard will not stop you from going beyond 255 but will break things if you do. This is a known bug and dev team is looking into a long term fix on this one.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Ryan_Miles
Meraki Employee
Meraki Employee

SImilar to what @alemabrahao mentions above regarding the HA scenario there are cases in which large numbers of VLANs create performance issues on MX models. The general guidance appears to be no more than 100 VLANs as mentioned here.

Ryan

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
PhilipDAth
Kind of a big deal
Kind of a big deal

Interesting!  I've never tried.

 

I bet this is something solvable by the dev team - if they are motivated.  Unless it is some dumb silicon restriction (maybe they have to register the VLANs they are interested in with the silicon, and the more VLANs the slower the silicon gets at adding them).

 

Have you tried experimenting with different firmware versions?

RaphaelL
Kind of a big deal
Kind of a big deal

Good point. I'm testing with 18.1 and a lot of increase in performance with 18.2. Might be worth to try

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels