Cisco Meraki MX60W EoL: Migrate to the MX67W
The Meraki MX60W passed Last Day of Support on October 24, 2022 — no more security patches, no TAC, no RMA. Here's why it must come out and how to refresh cleanly to the MX67W with modern SD-WAN, Wi-Fi 5, and AnyConnect VPN.

If a Cisco Meraki MX60W (PID MX60W-HW) is still bolted to a wall in a branch closet or sitting on a teleworker's desk, it is now well past every lifecycle milestone Meraki tracks. The MX60W reached End of Sale on October 24, 2015 and crossed its Last Day of Support on October 24, 2022. From that 2022 date forward there are no firmware updates, no security fixes, no TAC assistance, and no hardware RMA for this model. The unit still routes packets and still serves Wi-Fi, which is precisely why so many of them are quietly still in service. This guide explains what those dates mean for a live network, why the MX67W is a genuine generational upgrade rather than a like-for-like swap, and how to plan a clean migration.
What the MX60W actually was
The MX60W was the wireless variant of Meraki's original small-branch security appliance. It paired the MX60 cloud-managed security gateway — stateful firewall, site-to-site and client VPN, content filtering, and basic traffic shaping — with an integrated single-radio 802.11n access point, all in one desktop unit. That all-in-one design made it the go-to for teleworkers, micro-sites, and small offices that needed both a managed security edge and local Wi-Fi without deploying a separate AP. Connectivity was a small fixed Ethernet port set: a dedicated WAN/Internet port plus a handful of LAN ports, rated for roughly 50 concurrent users and stateful firewall throughput in the low tens of megabits per second. By 2015 standards that was adequate for a coffee-shop-sized site. Against a modern broadband circuit and modern client mix, the throughput ceiling and the 2.4 GHz-leaning 802.11n radio are the bottleneck.
Why acting now matters
The danger of an end-of-support security appliance is not that it stops working — it is that it keeps working while the safety floor disappears beneath it. An MX60W is the firewall and VPN concentrator at the edge of a site, so the exposure is more acute than for an end-of-life switch or AP. Three problems compound after LDoS:
- No security patches: the MX60W's firmware is frozen at a release that has not received a PSIRT vulnerability fix since 2022. As the network security perimeter for that site, an unpatched MX is exactly the asset auditors and attackers look at first.
- No TAC or RMA: if the unit fails or misbehaves, there is no support case and no advance hardware replacement. The site goes dark until you source and stage a replacement under pressure — the opposite of a planned refresh.
- Compliance and licensing exposure: frameworks such as FedRAMP, CMMC, HIPAA, and PCI DSS expect security devices to be vendor-supported and patchable. An out-of-support edge firewall is a documented finding. It also cannot carry a current, supportable Meraki license, which undermines the cloud-management model the device depends on.
The recommended replacement: Meraki MX67W
The successor to the MX60W is the Meraki MX67W (MX67W-HW), the integrated-Wi-Fi member of the current MX67 family. It deliberately carries the MX60W's all-in-one role forward — one cloud-managed box that is both the small-site security/SD-WAN gateway and the local access point — while modernizing every dimension that aged out on the older unit.
What is concretely better
- Throughput: stateful firewall performance jumps from the MX60W's low tens of Mbps to roughly 450 Mbps on the MX67W, with recommended client capacity in the ~50-user range that comfortably saturates a modern business broadband or fiber circuit instead of throttling it.
- Wireless: the integrated radio moves from single-radio 802.11n to dual-band concurrent 802.11ac Wave 2 (Wi-Fi 5) with MU-MIMO — meaningfully higher per-client rates, better 5 GHz utilization, and support for more simultaneous devices than the 2.4 GHz-era MX60W radio.
- SD-WAN and VPN: the MX67W brings the current Meraki SD-WAN stack — Auto VPN one-click site-to-site tunnels, dual-WAN with cellular failover via USB modem, application-aware path selection and SD-WAN policies — plus AnyConnect remote-access VPN, which the MX60W generation never supported.
- Security services: Advanced Malware Protection (AMP), an integrated IDS/IPS engine powered by Snort, and current Cisco Talos-backed threat intelligence and content filtering, all licensed under the Advanced Security tier — protections that simply did not exist on the MX60W.
- Ports: a dedicated WAN/Internet port plus multiple Gigabit LAN ports and a USB port for 3G/4G LTE failover, replacing the MX60W's slower, smaller fixed port set.
Licensing: budget for it up front
Every Meraki MX is hardware plus a subscription license, and the license — not the box — is what keeps the dashboard, firmware updates, and support entitlement alive. The MX67W requires its own active license in the appropriate tier: Enterprise for core firewall, VPN, and SD-WAN, or Advanced Security (or Secure Connect) to unlock AMP, IDS/IPS, content filtering, and Cisco Umbrella integration. The MX60W's old license does not migrate to a different model, so plan the term — typically 1, 3, 5, 7, or 10 years on a co-termination or per-device basis — at the same time you buy the hardware. For a small site, Advanced Security is usually the right call given the threat-protection features it unlocks.
A practical migration plan
1. Assess and inventory
Pull every MX60W serial from the Meraki dashboard and confirm the firmware, current license status, and per-site configuration. Note WAN circuit type and speed at each site — many MX60W locations have been upgraded to faster broadband since 2015, which is exactly the throughput the old appliance cannot use. Capture VLANs, firewall and L7 rules, content-filtering categories, Auto VPN topology, traffic-shaping policies, and the existing SSID config for the integrated radio.
2. License and procure
Order MX67W-HW units with matching license terms so each unit is ready to claim on arrival. For multi-site rollouts, decide whether to use configuration templates so a single policy set pushes to every new appliance. Source through an authorized partner to guarantee genuine hardware, valid licensing, and — for government buyers — TAA-compliant stock and contract-vehicle eligibility. Browse current MX options in our catalog.
3. Achieve config parity in the dashboard
Because both generations live in the same Meraki dashboard, there is no CLI config to convert. Create the new network (or clone the MX60W's network/template), claim the MX67W by serial, and verify that VLANs, firewall rules, VPN, content filtering, traffic shaping, and SSIDs carry over. Validate Auto VPN tunnels and any AnyConnect client profiles in a staging network before touching production, and confirm the new SD-WAN and security features (AMP, IDS/IPS) are enabled per your policy.
4. Physical swap, uplinks, and power
The MX67W is a compact desktop appliance like the MX60W, so rack space is rarely an issue; confirm the power adapter and mounting for each location, label the WAN and LAN cabling, and stage the cellular failover USB modem if a site needs it. For teleworker units, ship pre-claimed and pre-configured so the end user simply plugs in WAN and power — the appliance pulls its config from the cloud automatically.
5. Phased cutover
Migrate one site (or a pilot teleworker) first, confirm internet, VPN reachability, Wi-Fi association, and security logging, then roll the rest in waves. Keep the MX60W on standby briefly per site until the MX67W is proven, then remove it from the dashboard.
6. Secure decommission
Remove each retired MX60W from the Meraki organization so it stops consuming a license slot and cannot rejoin the network. Factory-reset the unit, wipe any local configuration, and dispose of it through a certified e-waste or asset-disposition process with a certificate of data destruction for your records — important for regulated environments.
Procurement notes for regulated buyers
For federal, DoD, and SLED purchasers, the MX67W's current-generation status is an advantage: it is readily available with TAA-compliant documentation, GSA/contract-vehicle alignment, and GPC card acceptance for buys under the micro-purchase threshold. Lead times and license provisioning are predictable when sourced from an authorized partner, and buying through one keeps the warranty, license, and support entitlement clean. See the full milestone record for this appliance on its EoL detail page, or browse other affected models in the Cisco EoL lookup.
Frequently asked questions
Is the Cisco Meraki MX60W still supported?
No. The MX60W (MX60W-HW) reached End of Sale on October 24, 2015 and its Last Day of Support (LDoS) on October 24, 2022. Past LDoS, Cisco Meraki provides no firmware updates, no security patches, no TAC support, and no advance hardware replacement (RMA). An MX60W in production today carries firmware that has not received a vulnerability fix in years and cannot be covered by a current license.
What replaces the Meraki MX60W?
The recommended successor is the Meraki MX67W (MX67W-HW), the integrated-Wi-Fi member of the current MX67 family. Like the MX60W it combines a small-branch security/SD-WAN gateway with a built-in wireless radio in one cloud-managed unit — but the MX67W moves from the MX60W's 802.11n radio to dual-band 802.11ac Wave 2, raises stateful firewall throughput to roughly 450 Mbps, and adds modern SD-WAN, AnyConnect remote-access VPN, and Advanced Malware Protection.
Can I keep my MX60W configuration when moving to the MX67W?
Largely, yes. Because both appliances are managed in the same Meraki dashboard, network-level policy — VLANs, firewall and L7 rules, content filtering, site-to-site Auto VPN, traffic shaping, and SSID settings — is reproduced through the dashboard rather than pasted from a CLI. The practical work is claiming the new MX67W by serial into the organization, binding it to a network (or cloning the MX60W's config to a new template-bound network), and re-licensing. There is no IOS-style config file to convert.
Does the MX67W need a separate license?
Yes. Every Meraki MX is sold as hardware plus a co-termination or per-device subscription license (Enterprise or Advanced Security/Secure Connect tier). The MX67W requires its own active license; the MX60W's expired or expiring license does not transfer to a different model. Plan the license term — typically 1, 3, 5, 7, or 10 years — at the same time you order the hardware so the new unit is operational the moment it is claimed.
Are TAA-compliant MX67W units available for federal and SLED buyers?
Yes. Uniqcli supplies the MX67W with the documentation federal, DoD, and SLED buyers need — TAA compliance, GSA/contract-vehicle alignment, and GPC card acceptance for purchases under the micro-purchase threshold. Because the MX67W is a current-generation product, lead times and license provisioning are predictable; request a quote and we'll confirm stock, TAA status, and the right license tier and term for your sites.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read