<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Too large IP subnets for wireless clients ? in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069872#M172498</link>
    <description>&lt;P&gt;Has anyone experienced broadcast issues with subnets larger than /22?&amp;nbsp;&amp;nbsp; Customer want to increase subnet size to /19, which seems like a problem waiting to happen.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Does Cisco have recommendations on sizing subnets for wireless?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your response&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 14:00:27 GMT</pubDate>
    <dc:creator>Steven Shelton</dc:creator>
    <dc:date>2021-07-05T14:00:27Z</dc:date>
    <item>
      <title>Too large IP subnets for wireless clients ?</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069872#M172498</link>
      <description>&lt;P&gt;Has anyone experienced broadcast issues with subnets larger than /22?&amp;nbsp;&amp;nbsp; Customer want to increase subnet size to /19, which seems like a problem waiting to happen.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Does Cisco have recommendations on sizing subnets for wireless?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your response&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069872#M172498</guid>
      <dc:creator>Steven Shelton</dc:creator>
      <dc:date>2021-07-05T14:00:27Z</dc:date>
    </item>
    <item>
      <title>I recall reading somewhere</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069873#M172499</link>
      <description>&lt;P&gt;I recall reading somewhere that no more than a /23 is recommended but I can't remember where! I have seen networks working fine with /21 and /20 but it depends on what types of traffic you are expecting (e.g. if high in Apple devices there will be lots of Bonjour traffic) and, if there's a local WLC, are you forwarding broadcasts? IPv6 and LLMNR are also common protocols that can use up switch resources and flood the VLANs.&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 01:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069873#M172499</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2017-05-12T01:08:03Z</dc:date>
    </item>
    <item>
      <title>Ric,</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069874#M172500</link>
      <description>&lt;P&gt;Ric,&lt;/P&gt;
&lt;P&gt;The number of Apples device using wireless is about 50% of the total 7000 clients.&lt;/P&gt;
&lt;P&gt;For the most part, the WLC is local to the APs, this is a campus environment with three remote sites. Two remotes are relatively small, less than 20 APs, the other remote site will reach around 100 APs once the new building is finished.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, no IPv6 and probably no LLMNR since we have no older Windows desktops or servers.&lt;/P&gt;
&lt;P&gt;I assume&amp;nbsp;that broadcast traffic is forwarded&amp;nbsp;from the wired vlan via the SSID to its wireless clients. &amp;nbsp;I am not aware of any controls in place that would prevent it. &amp;nbsp; Should we block or limit b'cast traffic? How would you do that?&lt;/P&gt;
&lt;P&gt;Thank you for your reponse&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 11:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069874#M172500</guid>
      <dc:creator>Steven Shelton</dc:creator>
      <dc:date>2017-05-12T11:16:40Z</dc:date>
    </item>
    <item>
      <title>For your remote offices are</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069875#M172501</link>
      <description>&lt;P&gt;For your remote offices are the APs in FlexConnect mode or do you tunnel all that back to your WLC? I'm assuming they do all tunnel back if you're using the same subnet for everything?&lt;/P&gt;
&lt;P&gt;Broadcast traffic is not forwarded across the WLC by default (from wired to wireless and vice versa) so you should be ok there.&lt;/P&gt;
&lt;P&gt;By default layer 2 multicast is also not forwarded unless multicast snooping is enabled. This will prevent apple devices from seeing each other using bonjour but also limit the mDNS traffic smashing your LAN.&lt;/P&gt;
&lt;P&gt;The other issue with running many devices will multicast capabilities is these message are unicast between APs from the WLC and also then to each client. To mitigate this you can use ap multicast mode but there is still a risk the amount of traffic will result in a flood of unicasts on your wireless network.&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 03:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069875#M172501</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2017-05-13T03:41:59Z</dc:date>
    </item>
    <item>
      <title>what WLC model in use ? If it</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069876#M172502</link>
      <description>&lt;P&gt;what WLC model in use ? If it is 5508, then keep 7K is the max client limit. So even you allocate /19 (8192 hosts), WLC cannot handle that many clients in its database (if it is 8540/5520 you should be ok).&lt;/P&gt;
&lt;P&gt;With increase subnet size, you need to look at the ARP table size of L3 switch these wireless client terminate. It will mostly become bottleneck when it handles large MAC address table.&lt;/P&gt;
&lt;P&gt;Regarding wireless side as Ric pointed, as long as you do not enable "broadcast forwarding" feature, you should be fine with /19 network.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2017 20:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069876#M172502</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2017-05-13T20:50:34Z</dc:date>
    </item>
    <item>
      <title>here is partial output from</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069877#M172503</link>
      <description>&lt;P&gt;here is partial output from "show network summary",&amp;nbsp;Ethernet broadcast forwarding is enabled.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Web Mode.................................... Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Web Mode............................. Enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Web Mode Cipher-Option High.......... Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Web Mode Cipher-Option SSLv2......... Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Web Mode RC4 Cipher Preference....... Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Web Mode SSL Protocol................ Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;OCSP........................................ Disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;OCSP responder URL.......................... &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Shell (ssh).......................... Enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Secure Shell (ssh) Cipher-Option High....... Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Telnet...................................... Disable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;Ethernet Multicast Forwarding............... Enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 8pt;"&gt;Ethernet Broadcast Forwarding............... Enable&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;IPv4 AP Multicast/Broadcast Mode............ Multicast Address : 239.240.240.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;IPv6 AP Multicast/Broadcast Mode............ Multicast Address : ::&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;IGMP snooping............................... Enabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;IGMP timeout................................ 60 seconds&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;IGMP Query Interval......................... 20 seconds&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;MLD snooping................................ Disabled&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 14 May 2017 01:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069877#M172503</guid>
      <dc:creator>Steven Shelton</dc:creator>
      <dc:date>2017-05-14T01:10:15Z</dc:date>
    </item>
    <item>
      <title>This is not looking good. </title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069878#M172504</link>
      <description>&lt;P&gt;This is not looking good.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you see high channel utilization in this network ? If you forward all broadcast over the air, that should consume most of valuable air time, resulting degraded performance for clients.&lt;/P&gt;
&lt;P&gt;In a large network, this is not an recommended setting. By default this is in "disabled" state.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Rasika&lt;/P&gt;
&lt;P&gt;*** Pls rate all useful responses ***&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2017 23:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069878#M172504</guid>
      <dc:creator>Rasika Nayanajith</dc:creator>
      <dc:date>2017-05-14T23:21:00Z</dc:date>
    </item>
    <item>
      <title>As simple as this seems, I'm</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069879#M172505</link>
      <description>&lt;P&gt;As simple as this seems, I'm not sure I fully understand exactly what this function does.&amp;nbsp; Are these statements correct?&lt;/P&gt;
&lt;P&gt;If Ethernet Broadcast Forwarding is disabled then broadcast packets are only forwarded to a specific AP?&lt;/P&gt;
&lt;P&gt;If Ethernet Broadcast Forwarding is enabled then all broadcast packets are forwarded to all APs?&lt;/P&gt;
&lt;P&gt;The Ethernet broadcast traffic would be from the vlan which is mapped to the SSID in the AP group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And since Ethernet Broadcast Forwarding is a global setting, the broadcast traffic would include all vlans/SSIDs in the all AP groups.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 13:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069879#M172505</guid>
      <dc:creator>Steven Shelton</dc:creator>
      <dc:date>2017-05-18T13:06:35Z</dc:date>
    </item>
    <item>
      <title>If Ethernet Broadcast</title>
      <link>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069880#M172506</link>
      <description>&lt;P&gt;If Ethernet Broadcast Forwarding is enabled then the WLC will pass any broadcasts like network discoveries&amp;nbsp;through which can result in significant performance impact. For example, if you have 7000(!) clients in one subnet and half of those are wireless half are wired. For every device that sends out some form of broadcast, e.g. a network discovery broadcast, that packet will be unicast to each of your Cisco APs to start with (unless you have AP Multicast enabled) and then after that it will be unicast to every single one of your wireless clients so that's 3500 wireless unicasts + the number of APs you have as overhead. Now what happens when two clients start broadcasting etc etc... you get my point.&lt;/P&gt;
&lt;P&gt;If Ethernet Broadcast is disabled (common) then basically the WLC blocks those sorts of things traversing it which seems to have very little affect on most networks and is recommended.&lt;/P&gt;
&lt;P&gt;Correct on the global front, it would affect everything if the APs are in local mode or central switching with FlexConnect.&lt;/P&gt;
&lt;P&gt;Ric&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 13:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/too-large-ip-subnets-for-wireless-clients/m-p/3069880#M172506</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2017-05-18T13:16:07Z</dc:date>
    </item>
  </channel>
</rss>

