MX Cloud Managed Security Appliance Series


Cisco Meraki MX Security Appliances are ideal for organizations with large numbers of distributed sites. Since the MX is 100% cloud managed, installation and remote management is simple. The MX has a comprehensive suite of network services, eliminating the need for multiple appliances. These services include Layer 7 application firewall, content filtering, web search filtering, SNORT® based intrusion prevention, web caching, Intelligent WAN with multiple uplinks and 4G failover.

Cloud Managed Architecture

Built on Cisco Meraki’s award-winning cloud-managed architecture, the MX is the industry’s only 100% cloud-managed Unified Threat Management appliance. MX appliances self-provision, automatically pulling policies and configuration settings from the cloud. Powerful remote management tools provide network-wide visibility and control, and enable administration without the need for on-site networking expertise.

Cloud services deliver seamless firmware and security signature updates, automatically establish site-to-site VPN tunnels, and provide 24×7 network monitoring. Moreover, the MX’s intuitive browser-based management interface removes the need for expensive and time-consuming training.

Ironclad Security

The MX platform has an extensive suite of security features including IPS, content filtering, web search filtering, anti-virus / anti-phishing, geo-IP based firewalling and IPsec VPN connectivity, while providing the performance required for modern, bandwidth-intensive networks. Layer 7 fingerprinting technology lets administrators identify unwanted content and applications and prevent recreational apps like BitTorrent from wasting precious bandwidth.

The integrated Sourcefire SNORT® engine delivers superior intrusion prevention coverage, a key requirement for PCI 3.0 compliance. The MX also uses the Webroot BrightCloud® URL categorization database for CIPA / IWF compliant content-filtering, Kaspersky Safestream II® engine for anti-virus / anti-phishing, and MaxMind for geo-IP based security rules.

Best of all, these industry-leading Layer 7 security engines and signatures are always kept up-to-date via the cloud, simplifying network security management and providing peace of mind to IT administrators.

Intelligent WAN Made Simple

Intelligent path control

Use dynamic VPN path selection to choose the best VPN uplink based on packet loss, latency, and jitter. Define policies for sending the right traffic through the appropriate path (e.g., send voice via MPLS, http via VPN over broadband).

3G / 4G failover

The Cisco Meraki MX supports 3G/4G service providers globally for WAN connection failover. Web caching temporarily stores video, media, and web documents, lowering bandwidth usage and accelerating the download speed of Internet content.

Transport independence

Dual WAN ports with load balancing and failover enable the use of MPLS and redundant, commodity Internet connections, providing additional bandwidth and higher reliability.

Secure connectivity

Cisco Meraki’s unique auto provisioning site-to-site VPN (Auto VPN) connects branches securely with unmatched simplicity. MX Security Appliances automatically learn VPN parameters needed to establish and maintain VPN sessions using a 128-bit AES encryption.

A unique cloud-enabled discovery mechanism enables automatic interconnection of VPN peers and routes across the WAN, and keeps them updated in dynamic IP environments.

Application optimization

Layer 7 traffic shaping, application prioritization optimize the traffic for mission-critical applications and user experience.

Integrated 802.11ac Wireless

The MX64W and MX65W integrate Cisco Meraki’s award-winning wireless technology with the powerful MX network security features in a compact form factor ideal for branch offices or small enterprises.

• Dual-band 802.11n/ac, 2×2 MIMO with 2 spatial streams
• Unified management of network security and wireless
• Integrated enterprise security and guest access

Built-in PoE+

The MX65 and MX65W include two ports with 802.3at (PoE+). This built-in power capability removes the need for additional hardware to power critical branch devices.

• 2 (PoE+) ports capable of providing a total of 60W
• Power APs, phones, cameras, and other PoE enabled devices without the need for AC adapters, PoE converters, or unmanaged PoE switches.

Z1 Telecommuter Gateway

The Z1 Telecommuter Gateway extends the power of the Cisco Meraki dashboard and cloud-based centralized management to employees, IT staff and executives working from home. Using the patent-pending Cisco Meraki Auto VPN, Administrators can extend network services including VoIP and remote desktop (RDP) to remote employees with a single-click, provide wired and wireless access, and increase end-user productivity through Layer 7 traffic shaping and prioritization.

• 1 x 802.11b/g/n radio, 1 x 802.11a/n radio, 2×2 MIMO with 2 spatial streams
• Site-to-site (IPsec) VPN using Cisco Meraki Auto VPN
• Layer 7 application visibility and traffic shaping

Lifetime Warranty with Next-day Advanced Replacement

Cisco Meraki MX appliances include a limited lifetime hardware warranty that provides next-day advance hardware replacement. Cisco Meraki’s simplified software and support licensing model also combines all software upgrades, centralized systems management, and phone support under a single, easy-to-understand model. For complete details, please visit


The Cisco Meraki MX84, MX100, MX400, and MX600 models support pluggable optics for high-speed backbone connections between wiring closets or to aggregation switches.

Cisco Meraki offers several standards-based Gigabit and 10 Gigabit pluggable modules. Each appliance has also been tested for compatibility with several third-party modules.