Uniqcli

Cisco Meraki MX84 EoL: Migration Guide to the MX85

The Meraki MX84 hits Last Day of Support on October 31, 2026 — after that, no firmware, no security fixes, no TAC or RMA. Here's why the MX85 is the clean successor and how to refresh a branch fleet without downtime.

UT
Uniqcli Team
January 19, 2026 · 8 min read
Share
Cisco Meraki MX84 EoL: Migration Guide to the MX85

If you still have a Cisco Meraki MX84 (PID MX84-HW) anchoring a branch or campus edge, the clock on it is now specific and short. The MX84 reached End of Sale on October 31, 2021, and its Last Day of Support (LDoS) is October 31, 2026. After that final date Cisco provides no firmware updates, no PSIRT security fixes, and no TAC support or RMA hardware replacement for the platform. The appliance will keep forwarding packets — which is exactly why these units quietly stay in racks long past their refresh window. This guide explains what each milestone means for a device that lives at your security perimeter, why the recommended Meraki MX85 (PID MX85-HW) is a genuine upgrade rather than a like-for-like swap, and how to plan a clean cutover with no surprises.

What the MX84 actually was

The MX84 was Meraki's mid-size branch security and SD-WAN appliance: a 1U, cloud-managed unified threat management (UTM) box built around an Intel Atom-class CPU. It delivered roughly 500 Mbps of stateful firewall throughput, about 250 Mbps of site-to-site (AutoVPN) throughput, and approximately 320 Mbps with the full Advanced Security stack — IDS/IPS, content filtering, and Advanced Malware Protection (AMP) — enabled. Its interface layout was ten 1GbE copper ports plus two 1GbE SFP ports and a pair of USB ports for 3G/4G failover. Meraki rated it for around 200 clients per site. Every policy — Layer 7 firewall rules, traffic shaping, AutoVPN hub-and-spoke, group policies — lived in the Meraki dashboard, with no on-box CLI to manage. For a 2015-era mid-branch with a 200–300 Mbps WAN, it was well matched. Against a modern fiber circuit and an always-on security stack, it is now the bottleneck.

Why acting now matters

The danger of an end-of-life security appliance is not that it fails — it's that it keeps running while the support floor disappears beneath it. Three exposures stack up the moment LDoS passes on October 31, 2026:

  • No security patches: A perimeter firewall that no longer receives PSIRT fixes is the single worst place in your network to be unpatchable. New CVEs against the MX firmware family will not be remediated on the MX84, leaving a known, internet-facing gap.
  • No TAC or RMA: When the unit fails — and branch appliances run hot in closets — there is no replacement hardware and no support case. A dead MX84 after LDoS means a hard branch outage with no Cisco path to recovery.
  • Audit and compliance exposure: FedRAMP, CMMC, HIPAA, PCI-DSS, and most cyber-insurance attestations require that security infrastructure be vendor-supported and patchable. An EoL firewall at the edge is a documented finding waiting to happen and can stall an ATO or a contract renewal.

Acting before the date — not on it — also protects your migration itself: you want the old unit still under support as a fallback while you bring the new one online.

Cisco's named successor is the Meraki MX85 (MX85-HW), and it is the functionally equivalent next generation in the same 1U branch footprint. Same dashboard, same AutoVPN, same group-policy and traffic-shaping model — so your operational muscle memory transfers intact. What changes is headroom and architecture.

Throughput and a modern CPU

The MX85 runs on a newer x86 processor and roughly doubles every number that matters. Stateful firewall throughput goes from 500 Mbps to 1 Gbps. AutoVPN throughput moves from about 250 Mbps to 500 Mbps. Most importantly, advanced-security throughput — the realistic figure once IDS/IPS and AMP are on — climbs from roughly 320 Mbps to about 750 Mbps. In practice that means the MX85 can run the full Advanced Security feature set against a gigabit branch circuit, whereas the MX84 forced a trade-off between speed and protection. Recommended client capacity rises to around 250 users, and the platform supports more concurrent VPN tunnels for larger spoke topologies.

Purpose-built interfaces and PoE

The MX85 replaces the MX84's flat port layout with dedicated, redundant WAN: two 1GbE SFP ports and two RJ45 1GbE WAN ports — one of which delivers PoE+ — plus eight RJ45 1GbE LAN ports and two SFP LAN ports. The PoE+ WAN port is genuinely useful: it can power an injector or a small downstream device at the demarc without an extra outlet. Dual-WAN failover and load balancing are first-class, and the SFP cages give you fiber-handoff or 1G optics flexibility the copper-heavy MX84 lacked.

Licensing model

Licensing stays Meraki-native and per-device. You choose Enterprise/Essentials for core SD-WAN and firewalling, or Advanced Security for the IDS/IPS, AMP, and content-filtering bundle; newer orders may use the Secure SD-WAN Plus tier. Licenses are term-based (1/3/5/7/10 years) and either per-device or co-terminated across the org. An MX84 license does not carry to an MX85 SKU, so the refresh is also the moment to right-size your tier and term. Browse current MX85 options and bundles in our Cisco Meraki catalog.

A practical migration plan

1. Assess and inventory

Pull every MX84 serial and its bound network from your Meraki org. Record per-site WAN type and speed, the active feature set (IDS/IPS, AMP, content filtering, AutoVPN role as hub or spoke), VLAN and DHCP scopes, static routes, and any 3G/4G failover in use. Note which sites are saturating the MX84's security throughput today — those are your first cutovers.

2. License transition

Map each MX84 license to the equivalent MX85 tier and confirm remaining term. If you co-term, the MX85 license pro-rates into your existing date; if you per-device license, align the new term to your refresh budget cycle. Validate everything before hardware ships so there's no licensing gap at cutover.

3. Config and feature parity

Because the MX85 lives in the same dashboard, the cleanest path is to claim the new serial into the organization, bind it to the same network (or clone the network from a template), and let configuration replicate. Verify firewall rules, traffic-shaping policies, AutoVPN participation, and group policies came across exactly. The one area requiring deliberate work is port mapping: translate the MX84's port assignments onto the MX85's dedicated WAN/LAN layout, and decide which WAN ports use SFP versus RJ45.

Both are 1U, so rack space is a wash. Confirm power and confirm optics: if the MX84 used SFP uplinks, verify the same module types seat and link on the MX85 (1G SFP). Plan whether to use the MX85's PoE+ WAN port. Pre-stage and label all cabling for the cutover window so the swap is mechanical, not investigative.

5. Phased cutover

Pilot one or two representative branches first. Keep the MX84 in place (still under support through LDoS) as an immediate rollback during the pilot. Once validated, schedule per-site maintenance windows, swap the appliance, confirm WAN comes up and AutoVPN re-establishes, then verify client traffic and security logging in the dashboard before declaring the site done. Roll the fleet in waves rather than all at once.

6. Secure decommission

Remove the retired MX84 from its network and unclaim the serial from the org so it cannot rejoin or leak configuration. Then sanitize the device per NIST SP 800-88 before it leaves your facility, and retain a certificate of destruction for audit. For DoD and federal sites, document the sanitization in your asset-disposition records.

Procurement notes for regulated buyers

For federal, DoD, and SLED buyers, confirm TAA compliance and country of origin on the MX85-HW up front, and use Government Purchase Card (GPC) thresholds or your contract vehicle as appropriate. Buying through an authorized Cisco partner matters here: it guarantees genuine hardware with valid, registrable licenses and protects warranty and support eligibility — counterfeit or gray-market Meraki gear frequently fails license claiming. Lead times on MX-class appliances can swing with supply cycles, so order against your LDoS date with margin, not at the deadline. See the full milestone record on the MX84-HW end-of-life page, or browse our complete Cisco end-of-life library to plan adjacent refreshes.

The MX84 still works today, and that is precisely the risk. Lock in your MX85 hardware and licensing now so the swap happens on your schedule and well before Last Day of Support. Request your MX84-to-MX85 migration quote and we'll handle the sizing, licensing, and phased rollout end to end.

Frequently asked questions

When does the Cisco Meraki MX84 actually stop working?

It does not stop passing traffic on any date — that's the trap. End of Sale was October 31, 2021, and Last Day of Support (LDoS) is October 31, 2026. The hardware keeps routing after LDoS, but Cisco stops shipping firmware and security fixes, stops honoring RMAs, and TAC stops taking cases. The unit becomes an unsupported, unpatchable device sitting at your network edge. You should be cut over to an MX85 before October 31, 2026, not on it.

Is the MX85 a drop-in replacement for the MX84?

Functionally yes, physically mostly. Both are 1U rack appliances managed entirely from the Meraki dashboard, so your existing org, network templates, firewall rules, traffic-shaping policies, and AutoVPN topology carry over by binding the new serial to the same network. The differences that matter: the MX85 has dedicated WAN ports (2x SFP + 2x RJ45, one of them PoE+) instead of the MX84's general-purpose layout, and it roughly doubles every throughput number. Plan your port mapping and you can swap in a maintenance window.

How much faster is the MX85 than the MX84?

Stateful firewall throughput goes from 500 Mbps to 1 Gbps. Site-to-site VPN throughput goes from about 250 Mbps to 500 Mbps. Advanced security throughput — the number that matters once you turn on IDS/IPS and Advanced Malware Protection — jumps from roughly 320 Mbps to about 750 Mbps. So the MX85 lets you run the full Advanced Security feature set at line rates the MX84 could only hit with security features disabled.

Do I need new Meraki licenses when I move from MX84 to MX85?

You need licensing that matches the MX85 model and your desired tier (Essentials or Advanced Security, or the newer Secure SD-WAN Plus). Meraki licensing is per-device and per-term; an MX84 license does not transfer to an MX85 SKU. If you co-term your org, the new device's license folds into your existing co-termination date and is pro-rated. We'll confirm the exact license mapping and remaining term as part of the quote so you don't double-pay or leave a gap.

What's the right way to decommission the old MX84 for compliance?

After the MX85 is live and verified, remove the MX84 from the Meraki network in the dashboard, then unclaim the serial from the organization so it can't rejoin or leak config. Physically, the MX84 holds configuration and logs in flash, so wipe or destroy the unit per NIST SP 800-88 media sanitization before it leaves your facility. For federal and DoD environments, document the sanitization and retain the certificate of destruction in your asset records.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote