Uniqcli

Cisco Meraki MX90 End-of-Life: Migrating to the MX85

The Meraki MX90 hit Last Day of Support on April 26, 2021 — no firmware, no PSIRT fixes, no RMA. Here is a concrete, partner-built plan to refresh mid-size branches to the cloud-managed Meraki MX85, with throughput, licensing, and cutover specifics.

UT
Uniqcli Team
May 24, 2026 · 6 min read
Share
Cisco Meraki MX90 End-of-Life: Migrating to the MX85

If you still have a Cisco Meraki MX90 (PID MX90-HW) terminating WAN and VPN at a branch, you are running infrastructure that Cisco stopped supporting on April 26, 2021. The MX90 was a capable cloud-managed branch security and SD-WAN appliance in its day — integrated stateful firewall, site-to-site VPN, and application-aware traffic shaping for mid-size sites — but it is now multiple firmware generations behind, cannot receive security fixes, and is ineligible for TAC and RMA. For regulated buyers in federal, DoD, SLED, and healthcare environments, that combination is no longer just a performance question; it is an audit and risk-acceptance question. This guide explains what each milestone date actually means, why the Meraki MX85 (MX85-HW) is the right modern replacement, and exactly how to execute the refresh.

The EoL situation for the MX90 — and why it is urgent now

Cisco published two milestone dates for the MX90. End of Sale was April 26, 2016 — the last day the unit could be ordered new. The decisive date is Last Day of Support (LDoS): April 26, 2021. After LDoS, three things stop, all of them material to a security appliance specifically.

  • No more firmware or security fixes. The MX90 no longer receives Meraki dashboard firmware updates. When Cisco PSIRT discloses a vulnerability that affects the MX firewall, VPN, or content-inspection stack, there is no patched build for this hardware. The exposure simply accumulates.
  • No TAC and no hardware RMA. An out-of-support appliance cannot open a support case or receive an advance replacement. A power-supply or interface failure at a branch becomes an unplanned outage with no SLA behind it.
  • Licensing and dashboard risk. Meraki MX licenses are subscriptions tied to the device. An expired or non-renewable license on EoL hardware can disable cloud management — and an MX whose license lapses stops passing the very traffic the branch depends on.

This is a compliance finding, not just tech debt: FedRAMP, CMMC, HIPAA, and PCI-DSS all expect security-relevant systems to be patchable and vendor-supported. An internet-facing firewall that can no longer receive PSIRT fixes is a documented control gap an assessor will flag. Refreshing the MX90 closes it before the audit does.

You can confirm the exact milestone data for your serial and PID on our MX90 end-of-life page, and browse the broader Cisco EoL library for any other branch gear in the same refresh wave.

The recommended replacement: Cisco Meraki MX85

For the mid-size branch role the MX90 filled, the modern equivalent is the Meraki MX85. It is still a single cloud-managed appliance driven entirely from the Meraki dashboard — so the operational model your team already knows is preserved — but the hardware and security feature set are a different class.

Throughput and capacity

  • Stateful firewall throughput jumps from roughly 250 Mbps on the MX90 to about 1 Gbps on the MX85 — a 4x headroom increase that matters as branch internet circuits have grown from tens of Mbps to gigabit fiber.
  • Advanced security throughput (with IDS/IPS, AMP, and content filtering all enabled) is roughly 600 Mbps on the MX85 — the MX90 simply lacked an equivalent modern inspection engine.
  • Site-to-site AutoVPN throughput rises to about 500 Mbps, with recommended branch client capacity in the ~250-user range, comfortably above the MX90's mid-size design point.

Security features the MX90 never had

  • Snort-based IDS/IPS with Cisco Talos signature feeds, kept current automatically through the dashboard.
  • Cisco Advanced Malware Protection (AMP) for file reputation and retrospective alerting.
  • Cisco AnyConnect / Secure Client remote-access VPN termination — increasingly the default for hybrid-work branches, and not available on the older MX90.
  • Modern SD-WAN with dynamic path selection, application-aware policies, and SmartProbes for circuit health, plus a USB port for cellular (4G/LTE) failover.

Interfaces and licensing

The MX85 provides dual WAN uplinks (RJ45 plus a 1G SFP for fiber handoff), eight GbE LAN ports, and additional SFP LAN connectivity — flexible enough to land both copper and fiber drops without an external media converter. Licensing follows the current Meraki MX tiers: Enterprise (core SD-WAN, firewall, and VPN) and Advanced Security (adds IDS/IPS, AMP, content filtering, and geo-IP), sold as per-device-term or co-termination subscriptions. Plan for a new MX85 license; a legacy MX90 license cannot be ported to a different hardware model.

A practical migration plan

1. Assessment and inventory

Export the MX90 configuration from the dashboard as your reference: WAN settings and static IPs, VLANs and DHCP scopes, firewall and outbound rules, traffic-shaping policies, content-filtering categories, and the AutoVPN/site-to-site topology. Capture which branches are hubs versus spokes, and note circuit speeds so you size MX85 licenses (Enterprise vs Advanced Security) correctly per site.

2. License transition

Procure MX85 licenses ahead of hardware so claiming is not on the critical path. Decide between per-device-term and co-termination to match your existing org model, and align renewal dates across sites to simplify future budgeting. Confirm the Advanced Security tier wherever you intend to run IDS/IPS and AMP.

3. Config and feature parity

Add the MX85 to the same Meraki organization and stage its configuration before it ships to the branch. Because the MX85 is a newer model, rebuild rather than blind-clone the config: most policy maps over cleanly, but validate firewall rule order, VPN subnet participation, and traffic-shaping behavior against newer firmware. This is also the moment to enable the inspection features the MX90 lacked — turn on IDS/IPS in detection mode first, then move to prevention after a baseline.

4. Physical: rack, power, uplinks, optics

The MX85 is a 1RU appliance. Confirm rack space and a clean power feed, and pre-stage optics: if a branch uses fiber WAN or LAN handoff, order Meraki-compatible 1G SFP modules so the SFP ports are ready on day one. Label uplinks and document the cutover wiring before you touch the live circuit.

5. Phased cutover

Migrate one or two low-risk branches first to validate AutoVPN re-establishment to the hubs and confirm application performance. Schedule each cutover in a maintenance window: swap the appliance, let the MX85 register to the dashboard and pull its staged config, verify the VPN tunnels rebuild and the firewall and shaping policies apply, then monitor. Roll the remaining sites in waves once the pattern is proven.

6. Secure decommission

For each retired MX90: remove it from the organization, then factory-reset/wipe so no residual configuration, keys, or PSK material leave with the hardware. In federal and DoD contexts follow your media-sanitization standard (for example NIST SP 800-88) and retain disposition records for the audit trail.

Procurement notes for regulated buyers

  • TAA compliance: specify TAA-compliant MX85-HW SKUs for GSA, federal, and DoD purchases, and request country-of-origin documentation up front.
  • Acquisition vehicles: the MX85 is procurable via GSA schedule and within micro-purchase / GPC thresholds for smaller branch counts; larger refreshes are typically better handled as a quoted bundle with co-termed licensing.
  • Lead times: plan for hardware and license-claim timelines, especially when staging dozens of branches — order optics and licenses in parallel with appliances.
  • Authorized partner: buy through an authorized Cisco/Meraki partner so warranty, license registration, and TAC entitlement are clean from day one.

You can review configurations and pricing in our catalog, and when you are ready to size the refresh, our team can build a per-branch bill of materials with TAA-compliant MX85 hardware, the right license tier, and optics.

Ready to retire the MX90?: Get a partner-built MX85 migration quote — hardware, licensing, and optics scoped per branch. Start at Get a Quote.

Frequently asked questions

When did the Cisco Meraki MX90 reach end of life?

The MX90 went End of Sale on April 26, 2016, and reached its Last Day of Support (LDoS) on April 26, 2021. Since LDoS, it no longer receives firmware or security fixes and is not eligible for Cisco TAC support or hardware RMA.

What is the recommended replacement for the Meraki MX90?

The Cisco Meraki MX85 (MX85-HW). It serves the same mid-size branch role but raises stateful firewall throughput from about 250 Mbps to roughly 1 Gbps and adds modern security — Snort/Talos IDS/IPS, AMP, content filtering, and AnyConnect/Secure Client remote-access VPN — that the MX90 never offered.

Can I transfer my MX90 license to the new MX85?

No. Meraki MX licenses are tied to a specific hardware model, so a legacy MX90 license cannot be ported to an MX85. You will purchase a new MX85 license, choosing the Enterprise or Advanced Security tier and either per-device-term or co-termination to match your organization.

Will the MX85 keep my existing SD-WAN and VPN setup?

Yes, functionally. The MX85 is managed from the same Meraki dashboard and supports AutoVPN, so it rejoins your existing hub-and-spoke topology. Because it is a newer model on newer firmware, the best practice is to rebuild and validate the config rather than blind-clone it, then enable IDS/IPS and AMP that the MX90 lacked.

Is the Meraki MX85 available in a TAA-compliant configuration for federal buyers?

Yes. Specify TAA-compliant MX85-HW SKUs and request country-of-origin documentation. The MX85 is procurable via GSA schedule and within GPC thresholds for smaller deployments; an authorized partner can supply hardware, licensing, and optics with clean warranty and TAC entitlement.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote