Overview:
The Cisco Meraki MX are multifunctional security and SD-WAN enterprise appliances with a wide set of capabilities to address multiple use cases–from an all-in-one device. Organizations of all sizes and across all industries rely on the MX to deliver secure connectivity to hub locations or multi-cloud environments, as well as application quality of experience (QoE), through advanced analytics with machine learning.
The MX is 100% cloud-managed, so installation and remote management is truly zero touch, making it ideal for distributed branches, campuses, and data center locations. Natively integrated with a comprehensive suite of secure network and assurance capabilities, the MX eliminates the need for multiple appliances. These capabilities include application-based firewalling, content filtering, web search filtering, SNORT®-based intrusion detection and prevention, Cisco Advanced Malware Protection (AMP), site-to-site Auto VPN, client VPN, WAN and cellular failover, dynamic path selection, web application health, VoIP health, and more. SD-WAN can be easily be extended to deliver optimized access to resources in public and private cloud environments with virtual MX appliances (vMX). Public clouds supported with vMX include Am
MX85 Highlights
Hardware
- Stateful firewall throughput: 1 Gbps
- Recommended for up to 250 users
Cloud-based centralized management
- Managed centrally over the web
- Classifies applications, users and devices
- Zero-touch, self-provisioning deployments
Networking and security
- Stateful firewall
- Auto VPN™ self-configuring site-to-site VPN
- Active Directory integration
- Identity-based policies
- Client VPN (IPsec)
- 3G / 4G failover via USB modem
Traffic shaping and application management
- Layer 7 application visibility and traffic shaping
- Application prioritization
Advanced security services1
- Content filtering
- Google SafeSearch and YouTube for Schools
- Intrusion detection & prevention (IDS/IPS)
- Advanced Malware Protection (AMP)
- Cisco Threat Grid2
Secure Cisco SD-WAN powered by Meraki
Secure Cisco SD-WAN powered by Meraki is delivered by the MX appliances. SD-WAN powered by Meraki has helped thousands of organizations rapidly save costs by reducing their dependence on MPLS without compromising on performance. As enterprises continue to shift from hub-centric architectures interconnected with VPN to ones that leverage public internet connectivity, SD-WAN powered by Meraki delivers advanced analytics with ML to monitor and optimize quality of experience (QoE) for applications, regardless of where they might be hosted.
Transport independence
Leverage more than one uplink of any type with automatic failover–MPLS, broadband, fiber, or cellular.
Advanced analytics
Coming soon: at-a-glance health of web applications with ML thresholds, VoIP, and WAN with predictive analytics
Native security
Integrated with next-gen firewall, content filtering, and Advanced Malware Protection (AMP) and IDS/IPS informed by Cisco Talos.
SaaS quality of experience
Manual and performance-based path selection using advanced analytics.
1 Requires Advanced Security License
2 Requires Threat Grid cloud subscription
MX Cloud Managed Security Appliance Series Solutions:
Cisco Meraki MX Security Appliances are ideal for organizations considering a Unified Threat Managment (UTM) solution, for distributed sites, campuses or datacenter VPN concentration. Since the MX is 100% cloud managed, installation and remote management is simple. The MX has a comprehensive suite of network services, eliminating the need for multiple appliances. These services include SD-WAN capabilities, application-based firewalling, content filtering, web search filtering, SNORT® based intrusion detection and prevention, Cisco Advanced Malware Protection (AMP), web caching, 4G cellular failover and more. Auto VPN and SD-WAN features are available on our hardware and virtual appliances, configurable in Amazon Web Services.
Ironclad Security
The MX platform has an extensive suite of security features, including IDS/IPS, content filtering, web search filtering, anti-malware, geo-IP-based firewalling, IPsec VPN connectivity, and Cisco Advanced Malware Protection, while providing the performance required for modern, bandwidth-intensive networks.
Layer 7 fingerprinting technology lets administrators identify unwanted content and applications, and prevents recreational apps like BitTorrent from wasting precious bandwidth.
The integrated Cisco SNORT® engine delivers superior intrusion prevention coverage, a key requirement for PCI 3.2 compliance. The MX also uses the Webroot BrightCloud® URL categorization database for CIPA/IWF-compliant content filtering, Cisco Advanced Malware Protection (AMP) engine for anti-malware, AMP Threat Grid Cloud, and MaxMind for geo-IP-based security rules.
Best of all, these industry-leading layer 7 security engines and signatures are always kept up-to-date via the cloud, simplifying network security management and providing peace of mind to IT administrators.


Cloud Managed Architecture
Built on Cisco Meraki’s award-winning cloud architecture, the MX is the industry’s only 100% cloud-managed solution for unified threat management (UTM) and SD-WAN in a single appliance. MX appliances self-provision, automatically pulling policies and configuration settings from the cloud. Powerful remote-management tools provide network-wide visibility and control, and enable administration without the need for on-site networking expertise.
Cloud services deliver seamless firmware and security signature updates, automatically establish site-to-site VPN tunnels, and provide 24x7 network monitoring. Moreover, the MX’s intuitive browser-based management interface removes the need for expensive and timeconsuming training.
For customers moving IT services to a public cloud service, Meraki offers a virtual MX for use in Amazon Web Services and Microsoft Azure, enabling Auto VPN peering and SD-WAN for dynamic path selection.
Integrated 802.11ac Wave 2 Wireless
The MX67W, MX68W, and MX68CW integrate Cisco Meraki‘s award-winning wireless technology with the powerful MX network security features in a compact form factor ideal for branch offices or small enterprises.
- Dual-band 802.11n/ac Wave 2, 2x2 MU-MIMO with two spatial streams
- Unified management of network security and wireless
- Integrated enterprise security and guest access

MX68CW security and SD-WAN appliance

MX67C SIM slot
LTE Advanced
While all MX models feature a USB port for 3G/4G failover, the MX67C and MX68CW include a SIM slot and internal LTE modem. This integrated functionality removes the need for external hardware and allows for cellular visibility and configuration within the Meraki dashboard.
- 1 x CAT 6, 300 Mbps LTE modem
- 1 x Nano SIM slot (4ff form factor)
- Global coverage with individual orderable SKUs for North America and Worldwide
Power over Ethernet
The MX68, MX68W, and MX68CW include two ports with 802.3at (PoE+). This built-in power capability removes the need for additional hardware to power critical branch devices.
- 2 x 802.3at (PoE+) ports capable of providing a total of 60W
- APs, phones, cameras, and other PoE-enabled devices can be powered without the need for AC adapters, PoE converters, or unmanaged PoE switches

MX68 Port Configuration
Lifetime Warranty with Next-day Advanced Replacement
Cisco Meraki MX appliances include a limited lifetime hardware warranty that provides next-day advance hardware replacement. Cisco Meraki’s simplified software and support licensing model also combines software upgrades, centralized systems management, and phone support under a single, easy-to-understand model.
Licensing:
Given the range of use cases that can be solved, there are three options for the MX appliance that give customers the flexibility to select the license most appropriate for their intended use.
The licensing structure for MX appliances is the same as that of any other Meraki device–1:1 ratio of devices to licenses. Pair your chosen MX appliance(s) with the relevant license for your use case.
