Plus 1 review for adding a Layer3 Vlan and DHCP scope prepping for new SSID

Solved
JED2021
Getting noticed

Plus 1 review for adding a Layer3 Vlan and DHCP scope prepping for new SSID

Verified VLAN 32 does not exist.

Verified subnet does not exist.

 

 

Security & SD-WAN > Configure > Addressing & VLANS

 

Routing

Add VLAN

VLAN name.    Corporate

VLAN ID          32

Group policy   None

VPN mode.     Disabled

MX IP.             172.16.32.1

Subnet.          172.16.32.0/22

 

Security & SD-WAN > Configure > DHCP

 

VLAN 32

Run a DHCP server

1 day

Proxy to upstream DNS

Boot options disabled

 

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @JED2021 , the Config looks fine as that would create your later 3 interface on the MX which I assume you’ll Trunk to your down stream switches.

 

Just one question, why not configure the L3 int on your switches instead? Are your switches L2 only or was this done from a security perspective?

 

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

5 Replies 5
cmr
Kind of a big deal
Kind of a big deal

@JED2021 what is your question?

 

All VLANs exist, it is an SVI that you are creating for VLAN32.

JED2021
Getting noticed

Vlan 32 is new  and will support layer 3.

It is added via the MX250 not the switches.

cmr
Kind of a big deal
Kind of a big deal

VLANs are a layer 2 construct, they become layer 3 enabled by creating an interface either on an MS or MX.  Are you asking if your setup is correct?  If so then it looks okay to me.

JED2021
Getting noticed

yes I understand the statement.

Its is added on the MX so it is supporting layer 3.

 

I was just seeking a +1 since more of an IOS person not a Meraki Gui

DarrenOC
Kind of a big deal
Kind of a big deal

Hi @JED2021 , the Config looks fine as that would create your later 3 interface on the MX which I assume you’ll Trunk to your down stream switches.

 

Just one question, why not configure the L3 int on your switches instead? Are your switches L2 only or was this done from a security perspective?

 

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels