cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1451
Views
1
Helpful
10
Replies

Disable Layer 3 on 3750X

jphipps85
Level 1
Level 1

Hello, I am hoping someone can give me guidance.

We have a site that we just took over that has a 3750X Multi layer switch that is used for layer 3 routing, VLANs, DHCP etc.

I am wanting to install a Meraki MX105 controller to the edge of the network and use IT for the layer 3 routing instead.

What would be the best way to disable layer 3 on the 3750X and allow the MX105 to takeover the layer 3 responsibilities?

Note, this site is live and active and I want to do this with minimal impact to connectivity.

Thank you greatly!

10 Replies 10

Richard Burts
Hall of Fame
Hall of Fame

We do not know much about your environment and that makes it difficult to give good advice. But the specific question you ask has a fairly simple answer. To disable layer 3 you would use the command "no ip routing".

Dealing with the implications of using that command could become complex. First you need to address how to stage in the necessary functions on the Meraki, without impacting the functioning network. Then you would need to address removal of the layer 3 functions from the 3750.

HTH

Rick

Thank you for the input Richard. One other question, if i were to issue the "no ip routing" command on the MLS, would reverting that command BACK keep in place the existing VLANs and layer 3 stuff?

You ask an interesting question and I am not certain about the answer. For the most part if you remove ip routing from running config I would expect the other parts of running config to remain in place and putting ip routing back in should restore functionality. But there is some possibility that something could be missing. So I suggest this approach: copy running config to startup config to be sure that startup is in sync with running, remove ip routing from running config, perhaps check how things work with Meraki, if you want to revert instead of inserting ip routing just copy startup config to running config (or reboot the switch which restores the config to its original state).

HTH

Rick

no ip routing will only disable the layer 3 forwarding/routing on the switch. The rest of the config should be left intact as it is.

It is however a good idea to make a backup of the config before doing any major changes.

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev

Have you tested this and know for sure that nothing else would change? I have not but I wonder, for example, if the switch config had some routing feature configured such as Policy Based Routing, if you remote ip routing would the ip policy <routemap> statement still be in the interface config?

HTH

Rick

I have removed "ip routing" from an IOS switch before and had to do a config cleanup afterwards. So I assumed that it wouldn't touch the layer 3 related configuration at all. A quick test in the lab tells me that routing protocol configuration is actually removed while other things like static routes, ACLs and PBR configuration is left intact.

Thank you for questioning my assumptions!

Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev

You are welcome. Interesting that things like PBR are left in the config. And glad to know that some things like routing protocol  configuration are removed. So removing ip routing does have some impacts beyond that single command.

HTH

Rick

jphipps85
Level 1
Level 1

So I issued the "no ip routing" command from my MLS and not sure whether it applied or not. There is not a "no ip routing" in the running config output after issuing it and I'm getting some conflicting IP errors (expected as I have my Meraki configured with the same VLANs this MLS currently services). Any pointers to get that darn layer 3 on the MLS to be successfully removed?

jphipps85
Level 1
Level 1

Here is the running config of the MLS, maybe I'm just not understanding properly:

US-SFC-MPOE-CS1#show run
Building configuration...

Current configuration : 38959 bytes
!
! Last configuration change at 20:54:19 PST Tue Mar 21 2006 by netops
!
version 15.2
service nagle
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime localtime
service timestamps log datetime localtime
no service password-encryption
!
hostname US-SFC-MPOE-CS1
!
boot-start-marker
boot-end-marker
!
!
vrf definition GUEST
rd 255:5
!
address-family ipv4
exit-address-family
!
vrf definition PUBLIC
!
address-family ipv4
exit-address-family
!
logging buffered 50000
logging rate-limit console 3 except critical
enable secret X.X.X
!
username netops privilege 15 secret X.X.X
no aaa new-model
clock timezone PST -8 0
clock summer-time PST recurring
switch 1 provision ws-c3750x-24s
switch 2 provision ws-c3750x-24s
switch 3 provision ws-c3750x-24s
system mtu routing 1500
!
!
!
!
no ip source-route
ip routing
ip gratuitous-arps
no ip cef optimize neighbor resolution
!
no ip dhcp conflict logging
ip dhcp excluded-address 10.17.90.1 10.17.90.10
ip dhcp excluded-address 10.17.127.1 10.17.127.10
ip dhcp excluded-address 10.130.130.193 10.130.130.195
ip dhcp excluded-address 10.130.131.1 10.130.131.10
ip dhcp excluded-address 10.130.151.1 10.130.151.10
ip dhcp excluded-address 10.130.152.1 10.130.152.10
ip dhcp excluded-address vrf GUEST 10.130.156.1 10.130.156.10
!
ip dhcp pool ACCESS-POINTS
vrf GUEST
network 10.130.156.0 255.255.252.0
default-router 10.130.156.1
dns-server 1.1.1.1 8.8.8.8
!
ip dhcp pool LEGACY_VLAN15
network 10.17.90.0 255.255.255.0
default-router 10.17.90.1
dns-server 1.1.1.1 8.8.8.8
!
ip dhcp pool LEGACY_VLAN13
network 10.17.127.0 255.255.255.0
default-router 10.17.127.1
dns-server 1.1.1.1 8.8.8.8
!
ip dhcp pool VLAN19
network 10.130.130.192 255.255.255.192
default-router 10.130.130.193
dns-server 1.1.1.1 8.8.8.8
!
ip dhcp pool VLAN20
network 10.130.131.0 255.255.255.0
default-router 10.130.131.1
dns-server 1.1.1.1 8.8.8.8
!
ip dhcp pool VLAN30
network 10.130.151.0 255.255.255.0
default-router 10.130.151.1
dns-server 1.1.1.1 8.8.8.8
!
ip dhcp pool VLAN123
network 10.130.152.0 255.255.252.0
default-router 10.130.152.1
dns-server 1.1.1.1 8.8.8.8
!
!
ip igmp snooping querier
vtp domain sfc.us.ad.westfield.com
vtp mode transparent
!
!
!
!
!
udld aggressive

mls qos map cos-dscp 0 8 16 24 32 46 48 56
mls qos srr-queue input bandwidth 70 30
mls qos srr-queue input threshold 1 80 90
mls qos srr-queue input priority-queue 2 bandwidth 30
mls qos srr-queue input cos-map queue 1 threshold 2 3
mls qos srr-queue input cos-map queue 1 threshold 3 6 7
mls qos srr-queue input cos-map queue 2 threshold 1 4
mls qos srr-queue input dscp-map queue 1 threshold 2 24
mls qos srr-queue input dscp-map queue 1 threshold 3 48 49 50 51 52 53 54 55
mls qos srr-queue input dscp-map queue 1 threshold 3 56 57 58 59 60 61 62 63
mls qos srr-queue input dscp-map queue 2 threshold 3 32 33 40 41 42 43 44 45
mls qos srr-queue input dscp-map queue 2 threshold 3 46 47
mls qos srr-queue output cos-map queue 1 threshold 3 4 5
mls qos srr-queue output cos-map queue 2 threshold 1 2
mls qos srr-queue output cos-map queue 2 threshold 2 3
mls qos srr-queue output cos-map queue 2 threshold 3 6 7
mls qos srr-queue output cos-map queue 3 threshold 3 0
mls qos srr-queue output cos-map queue 4 threshold 3 1
mls qos srr-queue output dscp-map queue 1 threshold 3 32 33 40 41 42 43 44 45
mls qos srr-queue output dscp-map queue 1 threshold 3 46 47
mls qos srr-queue output dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23
mls qos srr-queue output dscp-map queue 2 threshold 1 26 27 28 29 30 31 34 35
mls qos srr-queue output dscp-map queue 2 threshold 1 36 37 38 39
mls qos srr-queue output dscp-map queue 2 threshold 2 24
mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55
mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63
mls qos srr-queue output dscp-map queue 3 threshold 3 0 1 2 3 4 5 6 7
mls qos srr-queue output dscp-map queue 4 threshold 1 8 9 11 13 15
mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14
mls qos queue-set output 1 threshold 1 100 100 50 200
mls qos queue-set output 1 threshold 2 125 125 100 400
mls qos queue-set output 1 threshold 3 100 100 100 400
mls qos queue-set output 1 threshold 4 60 150 50 200
mls qos queue-set output 1 buffers 15 25 40 20
mls qos
!
energywise domain sfc.us.ad.westfield.com security shared-secret 0 westfield
!
crypto pki trustpoint DNAC-CA
enrollment mode ra
enrollment terminal
usage ssl-client
revocation-check crl none
!
!
crypto pki certificate chain DNAC-CA
certificate ca 619142D3CE64688765FD7B620CE1B1B002F101F5
308203A5 3082028D A0030201 02021461 9142D3CE 64688765 FD7B620C E1B1B002
F101F530 0D06092A 864886F7 0D01010B 05003062 312D302B 06035504 030C2432
64306531 6631662D 30353666 2D393566 372D3566 32302D33 33303336 38316165
38623131 16301406 0355040A 0C0D4369 73636F20 53797374 656D7331 19301706
0355040B 0C104369 73636F20 444E4120 43656E74 6572301E 170D3232 30363031
32323035 35355A17 0D323530 32323532 32303535 355A3062 312D302B 06035504
030C2432 64306531 6631662D 30353666 2D393566 372D3566 32302D33 33303336
38316165 38623131 16301406 0355040A 0C0D4369 73636F20 53797374 656D7331
19301706 0355040B 0C104369 73636F20 444E4120 43656E74 65723082 0122300D
06092A86 4886F70D 01010105 00038201 0F003082 010A0282 010100A0 AD14050D
121203C3 79B1F8F2 6BE03F19 B911C6D2 B2D85F4E F55B6FDD F006F8D7 42B3EBC4
A0EE7B3E 76F75195 CECE8881 115EB221 28BF9AFF 2A2BDF9C 7914AA08 658D7A37
F65EC617 1FAC12BD 963CF4E2 1C910F4F EFFBC6CD C620C08C F58D65EF 2F54B06F
58E9E679 6BC17C74 E4EB9465 1EC5D88C 1A91E838 2FAF0D4E CD9D6A91 A47E686F
F2CB1EA1 9315C22C 1E6257A0 B3F1222B B047D4BF 1860A2E8 A6F3A751 F4991151
BE6EF2AE 865B8F9D 4DA6CF3F A3FB9111 6C18FC3E 037C5AA1 1F63B0F4 A8D893C3
B3A426AD 40B9A260 17467544 75110CF2 3410890C C59B56B4 24B922D0 AD23CD43
70AE3FFF A8905F71 22BCE020 1FC4A63A A75D3EA1 13AEC205 C2432F02 03010001
A3533051 301D0603 551D0E04 16041493 B04B580A FE4E84E5 8BD8C638 A2A9B2CF
4001C030 1F060355 1D230418 30168014 93B04B58 0AFE4E84 E58BD8C6 38A2A9B2
CF4001C0 300F0603 551D1301 01FF0405 30030101 FF300D06 092A8648 86F70D01
010B0500 03820101 00788580 809A5ED1 E4DF48CB 62FE650D 68D1C2A3 9C041F88
909F45A0 C2301B6C 40019327 E1953D68 48E227BC 9259AE2A 05DC7DCB 94E9D329
EC170BF9 2F95A6C6 FD703B77 982D7918 77249516 90D1F2CE 19704032 16D73785
EEF929BF A6B6EECF 0B95ED36 6EF9B6F8 132CB873 5D0240E8 AE0CDE48 B0D5EC31
C52667BA 700F5554 6DE47851 42D483F8 098F34DA 3B9ABD4E 097CA009 56EB1DA6
FB76044A 0F152BA2 FBF0EA4A 42E0C269 AD4629BA C79F74A8 A0606FCB CEB0649A
9F4FE160 0474ADE4 4B7A4D7C E2E419CE 3FBF157A BBDC3C2D F33DF3A3 95C6B57A
B8B74483 6C3CD1CD F92675FC E5ACFE83 4C3E8A66 0E57D2F6 7AFA73F7 F0BFC437
0030FF28 5B2C6CE1 1E
quit
!
!
!
!
spanning-tree mode rapid-pvst
spanning-tree loopguard default
spanning-tree portfast edge bpduguard default
spanning-tree extend system-id
spanning-tree vlan 1-1000 priority 4096
spanning-tree vlan 1001-1024 priority 24576
auto qos srnd4
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause sfp-config-mismatch
errdisable recovery cause gbic-invalid
errdisable recovery cause l2ptguard
errdisable recovery cause psecure-violation
errdisable recovery cause port-mode-failure
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause pppoe-ia-rate-limit
errdisable recovery cause mac-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause inline-power
errdisable recovery cause arp-inspection
errdisable recovery cause loopback
errdisable recovery cause small-frame
errdisable recovery cause psp
errdisable recovery interval 600
port-channel load-balance src-dst-ip
!
!
!
!
vlan internal allocation policy ascending
!
vlan 1
tb-vlan1 1002
tb-vlan2 1003
!
vlan 9
name MGMT-NWR/LABS
!
vlan 10
name vlan:wfmgmt:transport:sfc.us
!
vlan 11
name SERVERS
!
vlan 12
name SERVERS-MGMT
!
vlan 13
name LABS-USERS
!
vlan 15
name NWR-USERS
!
vlan 19
name PRINTER
!
vlan 20
name vlan:wfmgmt:data:sfc.us
!
vlan 29
!
vlan 30
name VOIP
!
vlan 31
name ACCESS-POINTS
!
vlan 50
name ip:hosted:mallpod-mgmt:sfc.us
!
vlan 51
name ip:hosted:mallpod-vmotion:sfc.us
!
vlan 52
name MALLPOD-ISCSI
!
vlan 53
name MALLPOD-NFS
!
vlan 54
name MALLPOD-CIFS
!
vlan 60
name LABS-VOIP
!
vlan 61
name NWR-VOIP
!
vlan 100
name vlan:case:TimeLapse:sfc.us
!
vlan 102
name SHOPPERTRAK
!
vlan 103
name MALLPOD-CCTV
!
vlan 104
name MEDIA-WALLS
!
vlan 115
name PROJECT_NEXT
!
vlan 123
name CCTV-CAMERA/SERVERS
!
vlan 180
name vlan:ecowise:delta:sfc.us
!
vlan 181
name vlan:ecowise:andover-data:sfc.us
!
vlan 201
name vlan:obscura:data:sfc.us
!
vlan 801
name FW-TRANSIT
!
vlan 802
name MPLS-TRANSIT
!
vlan 804
name GUEST-TRANSIT
!
vlan 805
name MPLS2-TRANSIT
!
vlan 820
name WWW-ASA01
!
vlan 821
name WAN-iRTR01
!
vlan 822
name WAN-iRTR02
!
vlan 900
name PUBLIC-LAN
!
vlan 901
name L2-XO-INTERNET
!
vlan 902
name L2-DMZ
!
vlan 999
name vlan:wfmgmt:blackhole:sfc.us
!
vlan 1002
tb-vlan1 1
tb-vlan2 1003
!
vlan 1003
tb-vlan1 1
tb-vlan2 1002
!
ip telnet source-interface Vlan10
!
!
!
!
!
!
!
!
!
!
!
!
interface Port-channel9
description Uplink to Mallpod 1
switchport trunk encapsulation dot1q
switchport mode trunk
ip dhcp snooping trust
!
interface Port-channel23
description US-SFC-MPOE-FW
switchport trunk allowed vlan 801,804,900,902
switchport trunk encapsulation dot1q
switchport mode trunk
load-interval 30
shutdown
!
interface FastEthernet0
no ip address
no ip route-cache
shutdown
!
interface GigabitEthernet1/0/1
description US-SFC-MPOE-iRTR01
switchport trunk allowed vlan 10,802,821
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
shutdown
!
interface GigabitEthernet1/0/2
description US-SFC-IDF6-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch | cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/3
description US-SFC-IDF6-AS2
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch | cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/4
description US-SFC-IDF7-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch | cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/5
description US-SFC-IDF11-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch | cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/6
description US-SFC-IDF12-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/7
description US-SFC-IDF13-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/8
description US-SFC-IDF14-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/9
description US-SFC-IDF16-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/10
description US-SFC-IDF17-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/11
description US-SFC-IDF18-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/12
description US-SFC-IDF19-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/13
description US-SFC-IDF22-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/14
description US-SFC-IDF23-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/15
description US-SFC-IDF24-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/16
description US-SFC-IDF25-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/17
description US-SFC-IDF26-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/18
description US-SFC-MPOE-MPOD-AS1
switchport trunk encapsulation dot1q
switchport mode trunk
channel-group 9 mode active
ip dhcp snooping trust
!
interface GigabitEthernet1/0/19
description US-SFC-IDF28-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/20
description US-SFC-IDF3-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/21
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/22
description US-SFC-MPOE-MPOD-AS1
switchport trunk encapsulation dot1q
switchport mode trunk
channel-group 9 mode active
ip dhcp snooping trust
!
interface GigabitEthernet1/0/23
description US-SFC-IDF33-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/0/24
description US-SFC-IDF8-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface GigabitEthernet2/0/1
description US-SFC-IDF35-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/2
description US-SFC-IDF36-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/3
description US-SFC-IDF37-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/4
description Uplink to sw34.sfc
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/5
description US-SFC-IDF39-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/6
description US-SFC-MGMT-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/7
description US-SFC-IDF41-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/8
description US-SFC-IDF42-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/9
description US-SFC-IDF2-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/10
description US-SFC-IDF4-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/11
description US-SFC-IDF5-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/12
description US-SFC-IDF1-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/13
description US-SFC-IDF27-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/14
description US-SFC-IDF32-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/15
description US-SFC-COWORKING-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/16
description US-SFC-IDF34-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/17
description US-SFC-IDF29-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet2/0/18
description US-SFC-MPOE-MPOD-AS1
switchport trunk encapsulation dot1q
switchport mode trunk
channel-group 9 mode active
ip dhcp snooping trust
!
interface GigabitEthernet2/0/19
description CIRCUIT Century Link - CA/KXFN/226964/LVLC 551303371-334823639
no switchport
vrf forwarding PUBLIC
ip address 4.53.137.86 255.255.255.252
ip access-group INET-IN in
no ip redirects
no ip unreachables
no ip proxy-arp
speed nonegotiate
!
interface GigabitEthernet2/0/20
description ION3k-1 controller
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet2/0/21
description ION3k-1 data
switchport trunk allowed vlan 801,804
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet2/0/22
description US-SFC-MPOE-MPOD-AS1
switchport trunk encapsulation dot1q
switchport mode trunk
channel-group 9 mode active
ip dhcp snooping trust
!
interface GigabitEthernet2/0/23
description Internet to ION3k-1
switchport access vlan 900
switchport mode access
!
interface GigabitEthernet2/0/24
description US-SFC-BESPOKE-AS1
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
srr-queue bandwidth share 1 30 35 5
priority-queue out
mls qos trust cos
macro description cisco-switch
auto qos trust
spanning-tree link-type point-to-point
!
interface GigabitEthernet2/1/1
!
interface GigabitEthernet2/1/2
!
interface GigabitEthernet2/1/3
!
interface GigabitEthernet2/1/4
!
interface TenGigabitEthernet2/1/1
!
interface TenGigabitEthernet2/1/2
!
interface GigabitEthernet3/0/1
description US-SFC-MPOE-iRTR2
switchport trunk allowed vlan 10,805,822
switchport trunk encapsulation dot1q
switchport trunk native vlan 999
switchport mode trunk
!
interface GigabitEthernet3/0/2
description TO SFC-LABS-AS1
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet3/0/3
description TO US-SFC-NWR-AS01
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
spanning-tree link-type point-to-point
ip dhcp snooping trust
!
interface GigabitEthernet3/0/4
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/5
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/6
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/7
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/8
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/9
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/10
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/11
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/12
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/13
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/14
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/15
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/16
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/17
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/18
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/19
switchport trunk encapsulation dot1q
switchport mode trunk
switchport nonegotiate
shutdown
spanning-tree link-type point-to-point
!
interface GigabitEthernet3/0/20
description ION3k-2 controller
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet3/0/21
description ION3k-2 data
switchport trunk allowed vlan 801,804
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet3/0/22
description US-SFC-MPOE-FW [m0/0]
switchport access vlan 10
switchport mode access
shutdown
spanning-tree portfast edge
!
interface GigabitEthernet3/0/23
description US-SFC-MPOE-FW [g0/1]
switchport trunk allowed vlan 801,804,900,902
switchport trunk encapsulation dot1q
switchport mode trunk
load-interval 30
shutdown
channel-group 23 mode active
!
interface GigabitEthernet3/0/24
shutdown
!
interface GigabitEthernet3/1/1
!
interface GigabitEthernet3/1/2
!
interface GigabitEthernet3/1/3
!
interface GigabitEthernet3/1/4
!
interface TenGigabitEthernet3/1/1
!
interface TenGigabitEthernet3/1/2
!
interface Vlan1
description ip:case:cctv-merge:sfc.us
ip address 172.18.26.253 255.255.255.0
no ip redirects
!
interface Vlan2
no ip address
!
interface Vlan9
ip address 10.19.9.1 255.255.255.192
no ip redirects
!
interface Vlan10
description NETWORK-MGMT
ip address 10.19.2.65 255.255.255.192 secondary
ip address 10.130.128.1 255.255.255.128
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan11
description SERVERS
ip address 10.130.129.1 255.255.255.0
!
interface Vlan12
description SERVER-MGMT
ip address 10.130.130.1 255.255.255.224
!
interface Vlan13
ip address 10.17.127.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan15
ip address 10.17.90.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan19
description PRINTERS
ip address 10.130.130.193 255.255.255.192
!
interface Vlan20
description WF-USERS
ip address 10.16.42.1 255.255.255.0 secondary
ip address 10.130.131.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan30
description VOIP
ip address 10.130.151.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan31
description ACCESS-POINTS
vrf forwarding GUEST
ip address 10.130.156.1 255.255.252.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan50
description IP:MALLPOD-MGMT:SFC:US
ip address 10.14.7.1 255.255.255.224
no ip redirects
!
interface Vlan51
description IP:MALLPOD-VMOTION:SFC:US
ip address 10.14.7.33 255.255.255.224
no ip redirects
!
interface Vlan53
description IP:MALLPOD-NFS:SFC:US
ip address 10.14.7.97 255.255.255.224
no ip redirects
!
interface Vlan54
description IP:MALLPOD-CIFS:SFC:US
ip address 10.14.7.129 255.255.255.224
no ip redirects
!
interface Vlan60
ip address 10.27.127.1 255.255.255.0
no ip redirects
!
interface Vlan61
ip address 10.24.90.1 255.255.255.0
no ip redirects
shutdown
!
interface Vlan102
description SHOPPERTRAK
vrf forwarding GUEST
ip address 192.168.2.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan103
description IP:MALLPOD-CCTV:SFC:US
ip address 10.18.197.1 255.255.255.0
no ip redirects
!
interface Vlan104
description MEDIA-WALLS
ip address 10.130.142.1 255.255.255.0
!
interface Vlan115
description PROJECT NEXT
ip address 10.130.150.1 255.255.255.0
no ip redirects
no ip proxy-arp
!
interface Vlan123
description CCTV-CAMERAS/SERVERS
ip address 10.130.152.1 255.255.252.0
no ip redirects
!
interface Vlan180
ip address 10.18.42.1 255.255.255.0
no ip redirects
!
interface Vlan181
ip address 10.10.20.1 255.255.255.0
no ip redirects
!
interface Vlan801
description FW-TRANSIT
ip address 10.130.128.193 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan802
description MPLS-TRANSIT
ip address 10.130.128.201 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan804
description GUEST-TRANSIT
vrf forwarding GUEST
ip address 10.130.128.217 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan805
description MPLS2-TRANSIT
ip address 10.130.128.225 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Vlan820
ip address 10.19.9.65 255.255.255.252
no ip redirects
!
interface Vlan821
ip address 10.19.9.69 255.255.255.252
no ip redirects
!
interface Vlan822
ip address 10.19.9.73 255.255.255.252
no ip redirects
!
interface Vlan900
description Century Link Public LAN Block
vrf forwarding PUBLIC
ip address 4.7.95.137 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
!
ip forward-protocol nd
!
!
ip ftp source-interface Vlan10
no ip http server
no ip http secure-server
ip http client source-interface Vlan10
ip tftp source-interface Vlan10
ip route 0.0.0.0 0.0.0.0 10.130.128.196 name SD-WAN
ip route vrf GUEST 0.0.0.0 0.0.0.0 10.130.128.220 name GUEST-TRANSIT
ip route vrf GUEST 10.146.16.187 255.255.255.255 10.130.128.196 global name DHCP
ip route vrf GUEST 10.146.18.15 255.255.255.255 10.130.128.196 global name ISE-west2
ip route vrf GUEST 10.147.18.15 255.255.255.255 10.130.128.196 global name ISE-east1
ip route vrf PUBLIC 0.0.0.0 0.0.0.0 4.53.137.85
ip ssh source-interface Vlan10
ip ssh version 2
!
ip access-list extended INET-IN
remark TRAFFIC TO ION
permit ip any host 4.7.95.138
remark MOBILE USERS EGRESS - SOUTHWEST
permit icmp host 134.238.197.232 host 4.53.137.86
remark MOBILE USERS EGRESS - SOUTHWEST
permit icmp host 165.1.147.228 host 4.53.137.86
remark MOBILE USERS EGRESS - NORTH EAST
permit icmp host 208.127.71.222 host 4.53.137.86
remark MOBILE USERS EGRESS - CENTRAL EUROPE
permit icmp host 165.1.150.83 host 4.53.137.86
remark REMOTE NETWORKS EGRESS - WEST
permit icmp host 208.127.234.224 host 4.53.137.86
remark REMOTE NETWORKS EGRESS - EAST
permit icmp host 208.127.90.40 host 4.53.137.86
remark DENY & LOG
deny ip any any
ip access-list extended guest-print
permit ip 192.168.202.0 0.0.1.255 any
ip access-list extended internet-only
deny ip 192.168.202.0 0.0.1.255 host 10.17.90.12
deny ip 192.168.202.0 0.0.1.255 host 10.17.127.85
permit ip 192.168.28.0 0.0.0.255 any
permit ip 192.168.2.0 0.0.0.255 any
permit ip 192.168.80.0 0.0.3.255 any
permit ip 192.168.199.0 0.0.0.255 any
permit ip 192.168.202.0 0.0.1.255 any
ip access-list extended vlan199-in
permit udp any eq bootpc any eq bootps
permit icmp 192.168.199.0 0.0.0.255 host 192.168.199.1
deny ip any 10.0.0.0 0.255.255.255
deny ip any 172.16.0.0 0.15.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip 192.168.199.0 0.0.0.255 any
ip access-list extended vlan28-in
permit udp any eq bootpc any eq bootps
permit icmp 192.168.28.0 0.0.0.255 host 192.168.28.1
permit icmp 192.168.28.0 0.0.0.255 host 10.19.9.66
deny ip any 10.0.0.0 0.255.255.255
deny ip any 172.16.0.0 0.15.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip 192.168.28.0 0.0.0.255 any
ip access-list extended vlan30-in
permit udp any eq bootpc any eq bootps
permit icmp 192.168.2.0 0.0.0.255 host 192.168.2.1
deny ip any 10.0.0.0 0.255.255.255
deny ip any 172.16.0.0 0.15.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip 192.168.2.0 0.0.0.255 any
ip access-list extended vlan501-in
permit udp any eq bootpc any eq bootps
permit icmp 192.168.202.0 0.0.1.255 host 192.168.202.1
permit icmp 192.168.202.0 0.0.1.255 host 10.17.90.12
permit icmp 192.168.202.0 0.0.1.255 host 10.17.127.85
permit tcp 192.168.202.0 0.0.1.255 host 10.17.90.12 eq 9100
permit tcp 192.168.202.0 0.0.1.255 host 10.17.90.12 eq 631
permit tcp 192.168.202.0 0.0.1.255 host 10.17.90.12 eq lpd
permit udp 192.168.202.0 0.0.1.255 host 10.17.90.12 eq 5353
permit tcp 192.168.202.0 0.0.1.255 host 10.17.127.85 eq 9100
permit tcp 192.168.202.0 0.0.1.255 host 10.17.127.85 eq 631
permit tcp 192.168.202.0 0.0.1.255 host 10.17.127.85 eq lpd
permit udp 192.168.202.0 0.0.1.255 host 10.17.127.85 eq 5353
deny ip any 10.0.0.0 0.255.255.255
deny ip any 172.16.0.0 0.15.255.255
deny ip any 192.168.0.0 0.0.255.255
permit ip 192.168.202.0 0.0.1.255 any
ip access-list extended vlan77-in
permit udp any eq bootpc any eq bootps
permit icmp 192.168.80.0 0.0.3.255 host 192.168.80.1
deny ip any 10.0.0.0 0.255.255.255
deny ip any 172.16.0.0 0.15.255.255
deny ip any 192.168.0.0 0.0.255.255
permit tcp 192.168.80.0 0.0.3.255 any eq www
permit tcp 192.168.80.0 0.0.3.255 any eq 443
permit udp 192.168.80.0 0.0.3.255 any eq domain
ip access-list extended vlan899-in
permit ip 192.168.224.0 0.0.31.255 10.17.128.0 0.0.0.255
permit ip 192.168.224.0 0.0.31.255 10.17.127.0 0.0.0.255
permit ip 10.19.9.80 0.0.0.15 10.0.0.0 0.255.255.255
!
!
ip prefix-list DEFAULT-ROUTE seq 5 permit 0.0.0.0/0
logging trap errors
logging source-interface Vlan10
logging host 10.26.33.178
access-list 99 permit 10.140.5.245
access-list 99 permit 10.140.40.101
!
route-map internet-only permit 10
match ip address internet-only
set ip next-hop 10.19.9.66
!
route-map DEFAULT-ONLY permit 10
match ip address prefix-list DEFAULT-ROUTE
set tag 105
!
!
banner motd ^C
This system is for authorized use only. Any use of this system and all information
stored or processed on this system may be monitored, recorded, retrieved and disclosed
to authorized personnel, law enforcement officials, or other authorized entities.
Users should have no expectation of privacy as to any communication or information
stored or processed within this system. Unauthorized or improper use of this system
may result in administrative disciplinary actions, civil and criminal penalties.
By continuing to use this system you indicate your awareness of and consent to
these terms and conditions of use. Log off immediately if you do not agree to the
conditions stated in this warning.^C
!
line con 0
exec-timeout 15 0
logging synchronous
login local
line vty 0 4
exec-timeout 15 0
logging synchronous
login local
transport input ssh
transport output telnet ssh
line vty 5 15
logging synchronous
login local
transport input ssh
transport output ssh
!
!
end

US-SFC-MPOE-CS1#

Thank you for the additional information, especially for the configuration. The most important thing that I see in it is this:

ip routing

Which means that layer 3 processing is enabled. In a previous post you say "I issued the "no ip routing" command from my MLS". For some reason that did not take effect. You were in config mode when you entered that command?

Let me explain several things:

-on the 3750 switch the default is that ip routing is not enabled

- many things do not show up in show run if they are the default. Things that are not the default do show up in show run.

So "no ip routing" is the default and would not show up in show run. "ip routing" is not the default and so does show up in the running config. And that means that layer 3 processing is enabled.

Looking at the running config I realize that I have been taking a pretty simplistic view of the issue. In the original post you asked "What would be the best way to disable layer 3 on the 3750X". And the answer to that is to use "no ip routing" which disables layer 3 processing. But I realize that this would still leave many layer 3 things in the config (such as IP addresses on vlan interfaces) and these might cause problem in shifting to Meraki.

So you need to start with no ip routing, but you probably then need to follow up with removing more layer 3 things like IP addresses on interfaces. And if fact if layer 3 processing is disabled then there is need for only 1 vlan with a vlan interface, so I would suggest removing all vlan interfaces except one.

HTH

Rick