12-11-2025 06:02 AM
Hi ,
We have a fairly large Meraki setup. Approx 5500 APs scatered on 800 sites. Some sites are super small , and some have more than 40-50 APs.
https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2025/pdf/BRKEWN-2046.pdf
This document seems to suggest that we should block mDNS to save some airtime.
This video is also a great one : https://www.youtube.com/watch?v=miRV8qDOKBE
We have 4 SSIDs. 2 of them are for Guests with L2 isolation , 1 for IOT and 1 for Corp ( no L2 isolation on both ).
We have 0 use case for mDNS on Corp.
For people that have medium to large campuses , what do you do about it ?
EDIT : IGMP snooping is enabled , Flood unknown multicast is disabled , Multicast to Unicast conversion is enabled.
12-11-2025 06:53 AM
In my case, I usually do the following:
On the corporate network: I completely block mDNS.
On guest networks: With Layer 2 isolation, mDNS is irrelevant, so I block it anyway.
On the IoT network: I allow mDNS, but I use Bonjour Gateway and filter only the necessary services.
Consider enabling IGMP snooping and multicast-to-unicast conversion, when available.
12-11-2025 07:18 AM
So you did create a L3 rule to block UDP 5353 on your corp ssid ?
And yes M2U is enabled and is enabled by default
12-11-2025 08:18 AM
Yes, to be honest, our network is quite restricted, so we only allow what is necessary.
12-11-2025 07:53 AM
Thanks for sharing the video (had not seen it before) but have seen BRKEWN-2046 slide deck before.
Good stuff.
12-11-2025 11:53 AM
That is a great video and provides a lot to think about.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide