Home > Switches > Layer 3 Switching > MS Layer 3 Switching Overview

MS Layer 3 Switching Overview

Layer 3 routing capabilities are available on most Cisco Meraki switches. This allows the switches to route traffic between VLANs in a campus network without the need for an additional layer 3 device.

Supported models 

In order to enable and configure layer 3 routing on MS switches, a layer 3 capable switch is required.


Model Routes Routed Clients Features
MS210 16 interfaces/16 static routes     4096

Static Routing

DHCP Relay

MS225 16 interfaces/16 static routes 4096
MS250 1024 4096

Static Routing


DHCP Server + Relay

Warm Spare (VRRP)

Multicast Routing (PIM-SM)



16384 (MS350-24X)


512k (MS350-24X)

MS410 8192 96k
MS425 16384 112k

Initializing layer 3 routing

In order to route traffic between VLANs, routed interfaces must be configured. Only VLANs with a routed interface configured will be able to route traffic locally on the switch, and only if clients/devices on the VLAN are configured to use the switch's routed interface IP address as their gateway or next hop.


To start using layer 3 routing, navigate to the switch details page by going to Switch > Monitor > Switches and clicking on the switch to be configured. Under Status > L3 routing status, click Configure layer 3 settings .

The window that appears will allow the configuring of the first routed interface and a default route. It is recommended that the uplink VLAN be configured first.

  • Interface name: A friendly name/description for the interface/VLAN
  • Subnet: The network that this routed interface is on, in CIDR notation (ex.
  • Interface IP: The IP address this switch will use for layer 3 routing on this VLAN/subnet. This cannot be the same as the switch's management IP.
  • VLAN: The VLAN this routed interface is on
  • Multicast support:  Enable multicast support if, multicast routing between VLANs is required.
  • Default gateway: The next hop for any traffic that isn't going to a directly connected subnet or over a static route. This IP address must exist in a subnet with a routed interface.
  • DHCP settings: If DHCP on this VLAN should be handled by the switch, or forwarded to a server, make the appropriate selections. See the article on Configuring DHCP Services for more details.
  • OSPF settings: This VLAN can be distributed via OSPF.  See the article MS OSPF Overview for more details.


When complete, click Save, or Save and add another to configure additional routed interfaces immediately.


Configuring Additional Layer 3 Interfaces

To configure additional layer 3 interface for additional VLANs:

  1. Navigate to Switch > Configure > Routing and DHCP.
  2. Click Add an interface.
  3. Select the Switch the interface should exist on.
  4. Provide the required configuration details, as described in the 'Initializing layer 3 routing' section above.
  5. Click Save, or Save and add another to add additional interfaces.

In this example below, the 'Data' VLAN has been configured to use remote DHCP server for client requests.


Once created, any layer 3 interfaces or static routes will appear under Switch > Configure > Layer 3 routing.


Note: Each switch can only have a single L3 interface per VLAN. 

Configuring Static Routes

In order to route traffic elsewhere in the network, static routes must be configured for subnets that are not being routed by the switch or would not be using the default route already configured. Such as if another portion of the network was located behind a router or another layer 3 switch downstream from the Cisco Meraki layer 3 switch being configured.


To create a new static route:

  1. Navigate to Switch > Configure > Routing and DHCP.
  2. Click Add a static route.
  3. Select the Switch it should be applied to.
  4. Provide the following information:
    • Name: A friendly name/description for the static route.
    • Subnet: The network that this static route is for, in CIDR notation (ex.
    • Next hop IP: The IP address of the next layer 3 device along the path to this network. This address must exist in a subnet with a routed interface.
  5. Click Save, or Save and add another it additional static routes are needed.


Editing an existing layer 3 interface or static route

To modify an existing layer 3 interface or static route on a specific switch:

  1. Navigate to Switch > Configure > Routing and DHCP
  2. Click on the desired Interface or Route
  3. Make any desired changes.
  4. Click Save

Moving a layer 3 interface to another switch

To mode a layer 3 interface from one switch to another:

  1. Navigate to Switch > Configure > Routing and DHCP.
  2. Select the layer 3 interfaces that will be moved.
  3. Click Edit > Move...
  4. Select destination switch or switch stack, then click Submit.

Deleting a layer 3 interface or static route

In order to delete  a layer 3 interface or static route:

  1. Navigate to Switch > Configure > Routing and DHCP.
  2. Click on the desired Interface or Route.
  3. Click Delete Interface/Route, then click Confirm delete.

Note: A switch must retain at least one routed interface and the default route. The default route cannot be manually deleted.

Disabling layer 3 routing

In order to disable layer 3 routing, any configured static routes and layer 3 interfaces must be deleted in a specific order.

  1. Navigate to Switch > Configure > Routing and DHCP.
  2. Delete any static routes other than the Default route for the desired switch.
  3. Delete any layer 3 interfaces other than the one which contains the next hop IP for the default route on the desired switch.
  4. Delete the last layer 3 interface to disable layer 3 routing.

Performing these steps out of order will result in an error and not allow the route/interface to be deleted.

Notes regarding switch management address when using L3 routing

The management IP is treated entirely different from the layer 3 routed interfaces and must be a different IP address. It can be placed on a routed or non-routed VLAN (such as in the case of a management VLAN independent from client traffic). Traffic using the management IP address to communicate with the Cisco Meraki Cloud Controller will not use the layer 3 routing settings, instead using its configured default gateway. Therefore, it is important that the IP address, VLAN, and default gateway entered for the management/LAN IP still provide connectivity to the Internet.  The management interface cannot have a gateway of it's own L3 interfaces.

Last modified



This page has no classifications.

Explore the Product

Click to Learn More

Article ID

ID: 1162

Explore Meraki

You can find out more about Cisco Meraki on our main site, including information on products, contacting sales and finding a vendor.

Explore Meraki

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case

Ask the Community

In the Meraki Community, you can keep track of the latest announcements, find answers provided by fellow Meraki users and ask questions of your own.

Visit the Community