Uniqcli

Meraki MX100 EoL: Migration to the Meraki MX95

The Meraki MX100 hits Last Day of Support on February 1, 2027 — after that, no firmware patches, no TAC, no RMA. Here's why it must come out and how to migrate cleanly to the higher-throughput Meraki MX95.

UT
Uniqcli Team
January 12, 2026 · 9 min read
Share
Meraki MX100 EoL: Migration to the Meraki MX95

If you still have Cisco Meraki MX100 appliances (PID MX100-HW) carrying traffic at a campus core or a large branch, the clock on them is now explicit. The MX100 went End of Sale on February 1, 2022, and its Last Day of Support (LDoS) is February 1, 2027. After that date Cisco provides no firmware fixes, no PSIRT security patches, and no TAC support or RMA hardware replacement for this platform. The appliance will keep forwarding packets and the dashboard will keep showing it online, which is exactly the trap: an MX100 quietly stays in production long after the support floor has dropped away. This guide explains what each milestone actually means for a running fleet, why the recommended Meraki MX95 (PID MX95-HW) is a genuine throughput and security upgrade rather than a like-for-like swap, and how to plan a clean cutover.

What the MX100 actually was

The MX100 was Meraki's campus and large-branch security/SD-WAN appliance: a 1U rackmount box rated at up to 750 Mbps of stateful firewall throughput, roughly 650 Mbps with the advanced security (Layer 7 / IPS / AMP) stack engaged, and about 500 Mbps of site-to-site VPN. It was sized for up to 500 users and 250 concurrent Auto VPN / IPsec tunnels. Physically it offered 8x 1 Gigabit Ethernet RJ45 LAN ports plus 2x 1G SFP slots, with a dedicated WAN port and the option to repurpose a second port for dual-WAN. Like every MX, it was cloud-managed through the Meraki dashboard with zero-touch provisioning, integrated Auto VPN, content filtering, IDS/IPS, and Advanced Malware Protection. For a 2014-era design it was a capable aggregation firewall. The problem is not that it stopped being useful; it is that every interface, the throughput ceiling, and the silicon are a decade old, and the support window is closing.

Why acting now matters

LDoS is not a soft recommendation — it is the date the platform becomes unpatchable. Three concrete exposures stack up the moment February 1, 2027 passes:

  • No PSIRT security patches. When a new vulnerability is disclosed in the MX firmware family, the MX100 will no longer receive a fixed build. Because Meraki firmware is a managed cloud service, an unsupported model gets frozen off the patch track entirely — there is no 'last good image' you can self-maintain. Any CVE touching that code path on this hardware becomes permanent.
  • No TAC or RMA. A failed unit cannot be opened as a support case or swapped under contract after LDoS. Your only recovery is a spare you stockpiled before the deadline or a secondary-market unit of the same dead-end model.
  • Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under — FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS 4.0, and CISA directives — expect supported, patchable infrastructure at the network edge. An internet-facing firewall that cannot be patched is a finding waiting to happen, and 'the vendor no longer ships fixes' is not a defensible remediation plan during an assessment.

What each milestone means in practice

  • End of Sale (2022-02-01): the last day Cisco accepted new MX100-HW orders. Everything since has been consuming the support tail.
  • End of Software Maintenance (n/a for this PID): because MX firmware is cloud-delivered rather than version-pinned per box, there is no separately published software-maintenance date — the meaningful cutoff is LDoS, when the model leaves the supported firmware train.
  • Last Day of Support / LDoS (2027-02-01): the hard floor. After this date, no patches, no TAC, no RMA. Plan to have the MX100 fully out of production before it arrives, not on the day.

Cisco's updated successor notice names the Meraki MX95 (MX95-HW) as the MX100's replacement, and the spec jump is real. The MX95 is built for the same campus/medium-branch role but on current silicon and current interfaces:

  • Throughput: up to 2 Gbps stateful firewall (versus 750 Mbps on the MX100) and roughly 800 Mbps of SD-WAN/VPN throughput (versus ~500 Mbps). That is a 2.5x+ firewall headroom increase on the same rack footprint — enough to stop the firewall being the bottleneck on a 1 Gbps+ internet circuit.
  • Modern interfaces: 2x 10 Gigabit Ethernet SFP+ WAN ports and 2x 2.5 GbE RJ45 WAN ports (one of which delivers PoE+ out), plus on the LAN side 4x 1 GbE RJ45 and 2x 10 GbE SFP+. The MX100's all-1G copper LAN with 1G SFP slots is replaced by true 10G fiber uplinks and multi-gig copper — the difference between matching today's switching and re-capping throughput at the wire.
  • Security and SD-WAN: next-gen Layer 7 firewall, content filtering, IDS/IPS, Advanced Malware Protection with Cisco threat intelligence, and Auto VPN, all managed from the same Meraki dashboard. Native integration with Cisco Umbrella / SASE on-ramp is first-class on this generation.
  • Licensing model: the MX95 lives in Meraki's per-device subscription licensing with three editions — Enterprise, Advanced Security, and Secure SD-WAN Plus (SD-WAN+). This is the most important non-hardware change versus an MX100 that may still sit under the legacy co-termination model. Pick the edition deliberately: Advanced Security unlocks the IPS/AMP/content-filtering stack; SD-WAN+ adds dynamic path selection enhancements and the broader SASE feature set. Editions are uniform across the Meraki org, so plan the whole organization, not just one box.

A practical migration plan

1. Assessment and inventory

Export the MX100 configuration and topology from the dashboard. Document every VLAN and subnet, the WAN configuration (single or dual-WAN, static vs DHCP/PPPoE), all Auto VPN and non-Meraki IPsec peers, firewall and Layer 7 rules, content-filtering and IPS policy, traffic-shaping rules, and any client VPN / AnyConnect configuration. Capture peak throughput and concurrent tunnel counts from the dashboard analytics so you size the MX95 against measured load, not nameplate. Note the current license edition and organization co-termination/expiration date.

2. License transition

Confirm whether your Meraki org is on co-termination or per-device subscription licensing, and decide the target edition (Enterprise, Advanced Security, or SD-WAN+) for the whole organization. Moving from a legacy co-term MX100 to a per-device MX95 subscription is the right time to consolidate the org onto one model. Source the MX95 device license and support term alongside the hardware so the appliance activates the moment it claims into the dashboard.

3. Config and feature parity

Most MX configuration ports cleanly between models because it lives in the cloud dashboard, not on the box — the cleanest path is to add the MX95 to the same network or use a configuration template so VLANs, firewall rules, content filtering, and traffic shaping replicate. Re-validate the items that are interface- or peer-specific: WAN uplink settings on the new 10G/2.5G ports, Auto VPN re-establishment, and any non-Meraki IPsec peers (re-key Phase 1/Phase 2 with the partner). Confirm the advanced-security feature set you relied on is licensed on the new edition.

The MX95 is a 1U rackmount like the MX100, so rack space and basic power carry over. The interface change is the real planning item: budget for SFP+ optics or DACs for the 10G WAN/LAN ports (the MX100's 1G SFPs do not give you the new headroom), confirm your upstream switch and ISP handoff can take 10G or 2.5G, and verify the PoE+ source port if you intend to power a downstream device from the MX95. Run fiber or Cat6A where you want the new throughput — a 10G port behind a Cat5e patch is wasted.

5. Phased cutover

Stage and fully configure the MX95 offline (claim it into the dashboard, replicate config, license it) before it sees production traffic. For a single MX100, schedule a maintenance window: physically swap, move WAN and LAN cabling to the new ports, and bring the MX95 online — Auto VPN tunnels re-register automatically once the appliance is reachable. For an HA pair, build the MX95 HA pair in parallel and swing traffic during the window, keeping the MX100 cabled and powered as an immediate rollback for 24-72 hours. Validate in order: WAN/uplink state, routing and VLAN reachability, NAT/firewall, then VPN tunnels (confirm every Auto VPN and IPsec peer re-keys), then client VPN logins, then logging/SNMP/syslog to your SIEM.

6. Secure decommission

Only retire the MX100 after a full business cycle has passed clean. Remove it from the Meraki dashboard / network, then wipe and release the device. For federal, DoD, and healthcare environments, follow your media-sanitization standard (NIST SP 800-88) for any persistent storage and document chain of custody for the decommissioned hardware to satisfy audit requirements.

Procurement notes

For US public-sector and regulated buyers, confirm Trade Agreements Act (TAA) compliance and verify the unit and license are eligible for your contract vehicle (GSA, NASPO, GPC card purchases under micro-purchase thresholds, or your agency's BPA). MX95 hardware and subscription lead times move with Cisco supply cycles, so order hardware and the matching license term together and build buffer into the cutover date — do not let the LDoS deadline compress your window. Source through an authorized Cisco partner so warranty, Meraki license registration, and support entitlement land correctly from day one. You can review current MX95 availability in our catalog, confirm the full MX100 lifecycle record on its EoL detail page, and browse other end-of-life Cisco migrations we support. When you're ready to scope the refresh, get a quote and we'll size the MX95 edition and optics to your measured load.

Frequently asked questions

When does the Cisco Meraki MX100 reach end of support?

The MX100 (MX100-HW) went End of Sale on February 1, 2022, and reaches Last Day of Support (LDoS) on February 1, 2027. After LDoS, Cisco provides no firmware fixes, no PSIRT security patches, and no TAC support or RMA hardware replacement. Because Meraki firmware is a cloud-delivered service, an unsupported model is frozen off the patch track entirely — plan to have it out of production before that date.

Is the Meraki MX95 a real upgrade over the MX100?

Yes. The MX95 raises stateful firewall throughput from 750 Mbps to up to 2 Gbps and SD-WAN/VPN throughput from roughly 500 Mbps to about 800 Mbps. It also replaces the MX100's all-1G copper LAN and 1G SFP slots with 2x 10G SFP+ plus 2.5 GbE WAN ports and 10G SFP+ LAN uplinks, so the firewall stops being the bottleneck on modern circuits.

Can I run the MX95 as a warm spare for my existing MX100 during migration?

No. Meraki HA (warm spare) is only supported between identical MX models, so an MX95 cannot back up an MX100. A single MX100 migrates as a cold swap during a maintenance window; an HA MX100 pair migrates to a parallel HA MX95 pair, keeping the old units cabled as rollback for 24-72 hours.

How does MX95 licensing differ from the MX100?

The MX95 uses Meraki's per-device subscription licensing with three editions: Enterprise, Advanced Security, and Secure SD-WAN Plus (SD-WAN+). Many MX100 deployments still sit under the legacy co-termination model, so the refresh is the right time to consolidate the organization onto one model and edition. License editions are uniform across the whole Meraki org, so plan it org-wide, not per box.

Will my MX100 configuration transfer to the MX95?

Largely, yes — MX configuration lives in the Meraki cloud dashboard rather than on the appliance, so VLANs, firewall and Layer 7 rules, content filtering, and traffic shaping replicate via the same network or a configuration template. You must re-validate interface-specific settings on the new 10G/2.5G ports, confirm Auto VPN and any non-Meraki IPsec peers re-key, and verify the advanced-security features you used are covered by the new license edition.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote