
The Cisco Meraki MX80 (PID MX80-HW) was a workhorse cloud-managed security and SD-WAN appliance for small and medium branch offices. It folded a stateful firewall, site-to-site and client VPN, traffic shaping, and an Internet gateway into a single fanless desktop box managed entirely from the Meraki dashboard. That convenience is exactly why so many MX80s are still racked in closets and back rooms years after they should have been retired. As of August 30, 2023, the MX80 has reached its Last Day of Support, and continuing to run it is now an operational and compliance liability rather than a cost savings.
Where the MX80 stands in its lifecycle
Cisco and Meraki publish three milestones that govern the life of any product. Understanding what each one means is the difference between a planned refresh and an emergency replacement after an incident.
- End of Sale (2016-08-30): The last date the MX80-HW could be ordered through Cisco or an authorized partner. After this point you could still buy licenses for installed units, but no new hardware shipped.
- Last Day of Support / LDoS (2023-08-30): The hard cutoff. After this date the MX80 receives no firmware updates, no PSIRT security fixes, no TAC support cases, and no RMA hardware replacement. A dead MX80 today cannot be RMA'd, and a newly disclosed vulnerability in its firmware will never be patched.
Why acting now matters
The MX80 is a security appliance, which makes a stale one uniquely dangerous. Unlike a switch that simply forwards traffic, this device terminates your branch VPN, enforces your firewall policy, and runs intrusion prevention. When firmware stops receiving fixes, the very control plane protecting the branch becomes the soft target. There is no longer a SNORT signature update path, no malware-engine refresh, and no fix for any TLS or VPN-stack flaw discovered after LDoS.
For regulated buyers this is an audit finding waiting to happen. FedRAMP, CMMC, HIPAA, and PCI DSS all expect supported, patchable security infrastructure. An auditor who sees an end-of-support firewall terminating cardholder or PHI traffic will flag it, and self-attestation packages that list unsupported hardware tend to stall. The clean answer is a supported appliance under an active Cisco support contract.
The recommended replacement: Meraki MX85
Cisco's direct successor for branch deployments of this class is the Cisco Meraki MX85 (PID MX85-HW). It stays in the same cloud-managed, single-pane operating model your team already knows, so there is no new controller, no CLI relearning, and no change to the dashboard workflow. The jump in capability, however, is generational.
Throughput and capacity, side by side
- Stateful firewall: MX80 delivered roughly 250 Mbps; the MX85 delivers 1 Gbps, a 4x increase that finally keeps pace with modern branch broadband and fiber circuits.
- Advanced security throughput: With the full next-generation stack (IPS, AMP, content filtering) enabled, the MX85 sustains about 750 Mbps. The MX80 had no headroom for this once you turned everything on.
- VPN throughput: The MX85 pushes up to 1 Gbps of VPN versus roughly 80 Mbps on the MX80, removing the WAN bottleneck that throttled hub-and-spoke and Auto VPN designs.
- Site-to-site tunnels: Up to 200 concurrent Auto VPN tunnels on the MX85, comfortably supporting larger SD-WAN fabrics.
- Recommended scale: The MX80 was sized for about 100 users; the MX85 is rated for small-to-medium branches of up to 250 clients.
Ports, PoE, and uplink flexibility
This is where the physical refresh pays off. The MX80 offered dual WAN and a handful of 1GbE copper ports with 3G/4G USB modem failover, and no fiber or PoE. The MX85 brings genuine uplink choice: 2x 1GbE SFP plus 2x 1GbE RJ45 dedicated WAN ports (one RJ45 with PoE+ for powering an upstream device), 8x 1GbE RJ45 plus 2x 1GbE SFP on the LAN side, a dedicated management port, and USB 3.0 for cellular failover. The SFP cages let you terminate fiber handoffs directly instead of forcing a media converter into the path, and the appliance is a fanless 1U rack-mount unit drawing only about 12W idle and 55W max.
Licensing: what carries over and what is new
Meraki licensing remains per-device and subscription-based, so the model is familiar. Historically the MX line offered Enterprise (core networking, SD-WAN, site-to-site VPN) and Advanced Security (adds Cisco Talos-powered IPS, Advanced Malware Protection, content and URL filtering). Cisco has since introduced the Secure SD-WAN Plus tier for SASE-leaning deployments. Two practical points for budget owners: a Meraki license is bound to the dashboard and the device serial, and any unused term from a co-terminated or per-device license generally transfers to the replacement serial during a swap. Confirm exact credit and co-termination treatment with your partner before you order, because it directly affects the net cost of the refresh.
A practical migration plan
1. Assessment and inventory
Export every MX80 from the dashboard with its serial, network, firmware version, license type, and license expiry. Capture the active configuration of each site: WAN settings and static IPs, VLANs and DHCP scopes, firewall rules, traffic-shaping policies, Auto VPN and non-Meraki VPN peers, content-filtering categories, and any port-forwarding or 1:1 NAT entries. This inventory is also your scope document for the full EoL list if you have mixed Meraki gear aging out together.
2. License transition
Decide the target tier (Advanced Security or Secure SD-WAN Plus) per site, then work with your partner to apply or migrate licensing to the new MX85 serials. Because Meraki ties licensing to the organization and serial, plan this before hardware arrives so the units claim cleanly into the right network on day one.
3. Configuration and feature parity
The cleanest path is to claim the MX85 into the same dashboard network and replace the MX80 in place; the dashboard pushes the existing network configuration to the new serial. Validate parity item by item: firewall and outbound rules, VLAN-to-port mappings, DHCP reservations, traffic shaping, IPS rulesets, and VPN peer definitions. Where the MX80 used a USB cellular dongle, re-validate failover on the MX85's USB 3.0 modem support.
4. Physical: rack, power, uplinks, optics
The form factor changes from desktop to 1U rack-mount, so confirm rack space, rail kit, and a clean power feed at each branch. Inventory optics early: if you intend to use the SFP cages, order Meraki-compatible 1GbE SFP modules and the correct fiber or DAC for the handoff. If a WAN circuit will power downstream gear, plan to use the PoE+ WAN port. Pre-label uplinks to avoid swapping WAN and LAN during the cutover.
5. Phased cutover
Pilot one or two representative branches first, run them for a week, then roll the fleet in waves. Cloud management makes this low-touch: stage the MX85 config in the dashboard, ship the unit to the site, and have local hands swap cables during a maintenance window. Keep the MX80 on a shelf until the MX85 has proven stable, then decommission.
6. Secure decommission
Remove each retired MX80 from the dashboard organization to free the network slot and stop any lingering license association, then perform a factory reset to wipe stored config, keys, and VPN secrets before the unit leaves your custody. For federal and DoD environments, document the wipe and follow your media-sanitization and disposal policy for chain-of-custody.
Procurement notes for regulated buyers
As an authorized Cisco and Meraki partner, uniqcli sources MX85-HW and licensing through legitimate Cisco distribution, which matters for warranty validity and for keeping gray-market hardware out of your environment. For federal and SLED buyers, confirm TAA compliance and request country-of-origin documentation up front, and align purchasing with your GPC thresholds and contract vehicles. Build lead time into the schedule: appliance plus license plus optics can have separate availability, and you do not want a cutover stalled waiting on SFP modules. You can review device-level detail on the MX80 EoL page and check current availability on the catalog.
Ready to scope your refresh? Tell us your branch count, license expiries, and circuit types, and we will return a TAA-compliant MX85 bill of materials with license and optic options. Get a quote and we will turn your MX80 inventory into a clean, supported migration plan.
Frequently asked questions
Is the Cisco Meraki MX80 still supported?
No. The MX80-HW reached End of Sale on 2016-08-30 and Last Day of Support (LDoS) on 2023-08-30. Since that date it receives no firmware or PSIRT security updates, no Meraki/TAC support, and no RMA hardware replacement. Any vulnerability discovered after LDoS will never be patched, which makes a production MX80 both a security and a compliance risk.
What is the recommended replacement for the Meraki MX80?
Cisco's direct successor for this branch class is the Meraki MX85 (PID MX85-HW). It stays in the same cloud-managed dashboard model but delivers roughly 4x the stateful firewall throughput (1 Gbps vs 250 Mbps), about 750 Mbps of advanced security throughput, up to 1 Gbps VPN, support for up to 250 clients, and adds SFP fiber uplinks and a PoE+ WAN port in a 1U rack-mount chassis.
Will my existing Meraki licenses transfer to the MX85?
Meraki licensing is per-device and bound to your dashboard organization and the appliance serial. In most cases the remaining term from a co-terminated or per-device license can be applied to the new MX85 serial during the swap, though exact credit and co-termination handling vary. Confirm the treatment with your authorized partner before ordering, since it affects the net cost of the refresh, and decide whether you want Advanced Security or the newer Secure SD-WAN Plus tier.
How hard is the MX80-to-MX85 migration?
It is straightforward because both run on the Meraki dashboard. You claim the MX85 into the same network, the dashboard pushes the existing configuration to the new serial, you validate feature parity (firewall rules, VLANs, DHCP, VPN peers, IPS), then a local swap of cables during a maintenance window completes the cutover. The main physical changes are the move from desktop to 1U rack-mount and the option to use SFP optics and PoE+ uplinks.
Does running an end-of-support MX80 cause compliance problems?
Yes. Frameworks such as FedRAMP, CMMC, HIPAA, and PCI DSS expect security infrastructure to be supported and patchable. An end-of-support firewall terminating sensitive traffic is a common audit finding and can stall attestation packages. Replacing the MX80 with a supported MX85 under an active Cisco contract removes that finding.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read