Skip to main content

 

Cisco Meraki Documentation

How to Configure Storm Control on MS and Catalyst Switches

Click 日本語 for Japanese

Overview 

Storm control on MS series switches protects LAN connectivity in the event of a packet storm in a network. All MS series switches include control plane policing of STP and CDP/LLDP floods to ensure Meraki Cloud connectivity. 

Enhanced Storm Control suppresses Broadcast, Multicast, and Unknown Unicast packets based on a percentage of traffic on a given interface. Suppression monitors the bandwidth of each individual switch port every 1 second. On classic MS switches, if the specified type of traffic exceeds the defined limit, the switch drops only excess packets. On Catalyst switches, if the specified type of traffic exceeds the defined limit, the switch drops all packets until the monitored traffic falls below the defined limit. 

Platform behavior considerations for IOS XE switches 

Storm control limits broadcast, unknown unicast, and multicast traffic at the port level. How multicast traffic is classified and limited can vary depending on the underlying switch hardware platform. 

Storm control applies to multicast traffic based on traffic thresholds on all platforms. However, platforms differ in how they handle multicast: 

Some platforms treat all multicast traffic equally. 

Others distinguish between control-plane traffic (such as routing protocols) and data-plane multicast. 

On certain switch models, including older models, storm control applies to all multicast traffic and may impact: 

Routing protocols (e.g., OSPF) 

Multicast control traffic (e.g., IGMP, PIM) 

On these models, enabling multicast storm control at low thresholds may disrupt network control protocols. 

On newer hardware platforms, storm control applies more selectively. Control-plane traffic (such as routing protocols) typically remains unaffected, and storm control primarily limits flooded or excessive multicast data traffic. This allows you to use storm control more safely in environments with dynamic routing or multicast applications. 

Storm control behavior depends on hardware, even when configured through the same dashboard. Behavior may also vary with firmware version and feature interactions (QoS, multicast configuration, etc.). 

Best practices: 

  • Avoid setting multicast storm control thresholds too low in networks using dynamic routing (e.g., OSPF) or multicast applications. 
  • Validate behavior in your environment, especially when using mixed hardware platforms or cloud-managed Catalyst switches. 
  • Consider additional protections such as multicast configuration (e.g., IGMP snooping). 

For detailed platform-specific behavior, refer to Cisco Catalyst documentation for your switch version/model.

Platform IOS XE 17.15.x IOS XE 17.18.x IOS XE 26.1.x
Catalyst 9200 Link Link Link
Catalyst 9300 Link Link Link
Catalyst 9350 N/A Link  
Catalyst 9500 Link Link Link
Catalyst 9600 Link Link Link
IE-3500 N/A N/A Link

Prerequisites 

Supported switch models: MS100 series, MS210, MS225, MS250, MS350, MS355, MS400 series, and Catalyst switches. 

The network must contain a supported switch model for the Storm control settings to appear. This also applies to Templates and bound Switch profiles — bind a supported switch to a profile to make the Storm control settings visible. 

Enable Enhanced Storm Control globally before you configure it at the port level. 

Step-by-step instructions 

Enable Enhanced Storm Control globally 

1. Navigate to Switch > Configure > Switch settings

Dashboard navigation to switch settings

2. In the Storm Control section, select Add a storm control rule

3. From the Traffic Types drop-down, select the type of traffic you wish to suppress (BroadcastMulticast, and/or Unknown Unicast). 

switch settings storm control step 2

4. In the % of available port bandwidth field, enter a percentage between 1–99% to complete the configuration of the rule. 

switch settings storm control step 3

5. Select Confirm

switch settings storm control step 4

7. Select Save at the bottom of the settings page to save your configurations. 

switch settings storm control step 5

Configure port-level Enhanced Storm Control 

Port-level control is only available when Enhanced Storm Control is enabled globally. Once you enable Enhanced Storm Control globally, it is enabled on each port by default. 

1. Navigate to Switch > Monitor > Switch ports

Dashboard navigation to switch ports

2. Select the switch port to configure. 

3. In the Storm Control section, select Enable or Disable

Enable storm control on port level

4. Select Update to save the port configuration. 

Update port

  • Was this article helpful?