How to Configure Storm Control on MS and Catalyst Switches
Click 日本語 for Japanese
Overview
Storm control on MS series switches protects LAN connectivity in the event of a packet storm in a network. All MS series switches include control plane policing of STP and CDP/LLDP floods to ensure Meraki Cloud connectivity.
Enhanced Storm Control suppresses Broadcast, Multicast, and Unknown Unicast packets based on a percentage of traffic on a given interface. Suppression monitors the bandwidth of each individual switch port every 1 second. On classic MS switches, if the specified type of traffic exceeds the defined limit, the switch drops only excess packets. On Catalyst switches, if the specified type of traffic exceeds the defined limit, the switch drops all packets until the monitored traffic falls below the defined limit.
Platform behavior considerations for IOS XE switches
Storm control limits broadcast, unknown unicast, and multicast traffic at the port level. How multicast traffic is classified and limited can vary depending on the underlying switch hardware platform.
Storm control applies to multicast traffic based on traffic thresholds on all platforms. However, platforms differ in how they handle multicast:
Some platforms treat all multicast traffic equally.
Others distinguish between control-plane traffic (such as routing protocols) and data-plane multicast.
On certain switch models, including older models, storm control applies to all multicast traffic and may impact:
Routing protocols (e.g., OSPF)
Multicast control traffic (e.g., IGMP, PIM)
On these models, enabling multicast storm control at low thresholds may disrupt network control protocols.
On newer hardware platforms, storm control applies more selectively. Control-plane traffic (such as routing protocols) typically remains unaffected, and storm control primarily limits flooded or excessive multicast data traffic. This allows you to use storm control more safely in environments with dynamic routing or multicast applications.
Storm control behavior depends on hardware, even when configured through the same dashboard. Behavior may also vary with firmware version and feature interactions (QoS, multicast configuration, etc.).
Best practices:
- Avoid setting multicast storm control thresholds too low in networks using dynamic routing (e.g., OSPF) or multicast applications.
- Validate behavior in your environment, especially when using mixed hardware platforms or cloud-managed Catalyst switches.
- Consider additional protections such as multicast configuration (e.g., IGMP snooping).
For detailed platform-specific behavior, refer to Cisco Catalyst documentation for your switch version/model.
| Platform | IOS XE 17.15.x | IOS XE 17.18.x | IOS XE 26.1.x |
| Catalyst 9200 | Link | Link | Link |
| Catalyst 9300 | Link | Link | Link |
| Catalyst 9350 | N/A | Link | |
| Catalyst 9500 | Link | Link | Link |
| Catalyst 9600 | Link | Link | Link |
| IE-3500 | N/A | N/A | Link |
Prerequisites
Supported switch models: MS100 series, MS210, MS225, MS250, MS350, MS355, MS400 series, and Catalyst switches.
The network must contain a supported switch model for the Storm control settings to appear. This also applies to Templates and bound Switch profiles — bind a supported switch to a profile to make the Storm control settings visible.
Enable Enhanced Storm Control globally before you configure it at the port level.
Step-by-step instructions
Enable Enhanced Storm Control globally
1. Navigate to Switch > Configure > Switch settings.

2. In the Storm Control section, select Add a storm control rule.
3. From the Traffic Types drop-down, select the type of traffic you wish to suppress (Broadcast, Multicast, and/or Unknown Unicast).

4. In the % of available port bandwidth field, enter a percentage between 1–99% to complete the configuration of the rule.

5. Select Confirm.

7. Select Save at the bottom of the settings page to save your configurations.

Configure port-level Enhanced Storm Control
Port-level control is only available when Enhanced Storm Control is enabled globally. Once you enable Enhanced Storm Control globally, it is enabled on each port by default.
1. Navigate to Switch > Monitor > Switch ports.

2. Select the switch port to configure.
3. In the Storm Control section, select Enable or Disable.

4. Select Update to save the port configuration.


