
If you are still running a Cisco RV042 Dual WAN VPN Router (PID RV042-G5) at a branch, remote site, or small office, that hardware is now well past the point where Cisco can help you keep it secure or running. The RV042 reached End of Sale on January 30, 2020, but the more consequential date already passed: its Last Day of Support (LDoS) was June 30, 2019. After LDoS, there are no more firmware fixes, no PSIRT security patches, and no TAC or RMA coverage. This guide explains what the milestones mean for this specific platform and lays out a concrete migration to its named successor, the Cisco RV340 Dual WAN Gigabit VPN Router (RV340-K9-NA).
Why acting now matters for the RV042
The RV042 is a 10/100 Fast Ethernet dual-WAN router. Its design predates the threats and bandwidth realities of today's branch. Because it is past LDoS, Cisco will not issue firmware for newly discovered vulnerabilities in its web management, IPsec stack, or PPTP/QuickVPN services. The RV042 has been the subject of multiple published advisories over its life (command injection and authentication weaknesses in the web UI among them), and any vulnerability found from here on will simply remain unpatched. For a router that terminates site-to-site and remote-access VPN tunnels and sits at the WAN edge, that is an unacceptable exposure.
There is also a hard operational ceiling. The RV042 tops out at 100 Mbps WAN ports, so even with two ISP links it cannot pass the gigabit (or even modest 200-500 Mbps) circuits most carriers now provision to small sites. Its IPsec throughput (roughly 60 Mbps aggregate) and limited tunnel count throttle any meaningful site-to-site or work-from-home growth.
Compliance and audit exposure: For federal, DoD, SLED, and healthcare buyers, running unsupported, unpatchable edge gear is a direct finding risk. Frameworks such as NIST 800-53 (SI-2, flaw remediation), CMMC, FedRAMP, HIPAA Security Rule, and PCI-DSS all expect vendor-supported software with a patch path. An RV042 at the WAN edge cannot satisfy that, and 'no patch available from vendor' is not an accepted compensating control.
What each milestone date means
- End of Sale (EoS) - January 30, 2020: Cisco stopped selling the RV042-G5 through normal channels. Units after this date are remaining inventory, used, or gray market.
- End of Software Maintenance: not applicable / already elapsed for this platform - no further firmware or maintenance releases are produced.
- Last Day of Support (LDoS) - June 30, 2019: the contractual end of all Cisco support. No TAC cases, no RMA hardware replacement, no security fixes, no bug fixes. This date has already passed, so the RV042 is fully out of support today.
Note the unusual ordering: for the RV042 the Last Day of Support (2019) actually precedes End of Sale (2020). That means even units sold near EoS shipped without a forward support runway. Treat every RV042 in your environment as unsupported regardless of when it was purchased.
The recommended replacement: Cisco RV340
Cisco's designated migration path is the RV340 series, and the closest one-for-one swap is the RV340 Dual WAN Gigabit VPN Router (RV340-K9-NA). It keeps the familiar RV-series simplicity and web management while removing the RV042's two biggest limits: speed and modern VPN support.
What is concretely better
- Gigabit everywhere: two configurable Gigabit Ethernet WAN ports (one doubles as a USB-paired failover/3G/4G option) and four Gigabit LAN ports, versus the RV042's 10/100 ports. This unlocks the gigabit circuits the RV042 physically cannot use.
- Far higher VPN throughput: the RV340 delivers roughly 900 Mbps NAT/firewall throughput and on the order of 100+ Mbps of IPsec VPN, with support for up to 50 site-to-site IPsec tunnels and up to 50 concurrent client tunnels - a large jump over the RV042's ~60 Mbps and far smaller tunnel budget.
- Modern remote access: native support for AnyConnect SSL VPN (client licenses available), OpenVPN, and IPsec, replacing the RV042's legacy QuickVPN/PPTP approach that modern OS clients no longer support cleanly.
- Dual-WAN done right: load balancing and policy-based routing across both WAN links plus automatic failover, the same resilient-branch use case the RV042 was bought for, now at gigabit speed.
- USB port for 4G LTE/3G dongle failover, giving a true out-of-band backup WAN for sites with a single wired circuit.
- Stronger platform: a dual-core CPU, more RAM/flash for current firmware, hardware-accelerated VPN, and an actively maintained firmware line that still receives security updates.
Licensing is refreshingly simple for this class: the RV340 base features (dual-WAN, firewall, IPsec/OpenVPN, VLANs, QoS) are included with the hardware - no Smart Licensing tier or DNA subscription is required to run it. The only add-on most sites consider is AnyConnect client licensing if you want the Cisco SSL VPN client for remote workers. Budget for that per-user count up front rather than discovering it at cutover.
A practical migration plan
1. Assessment and inventory
Catalog every RV042 by site, firmware version, WAN circuit speeds, and the VPN topology it terminates (which peers, which remote-access users). Export the running config from each unit's web UI so you have a record of WAN settings, static routes, port-forwarding/NAT rules, firewall ACLs, VLANs, and IPsec policies. This inventory becomes your parity checklist.
2. License and feature parity
Map each RV042 feature to its RV340 equivalent. Dual-WAN load balancing, port forwarding, DHCP, VLANs, and IPsec site-to-site map directly. For remote users, decide now whether you will land them on AnyConnect (purchase client licenses), OpenVPN, or IPsec - QuickVPN does not carry over, so this is the one place you must redesign rather than copy.
3. Physical refresh
The RV340 is a comparable desktop/rack-edge form factor and is single-AC-powered, so power and space are rarely a constraint. Confirm WAN handoff types: if your ISP delivers via SFP or you need fiber, note that the base RV340 uses RJ-45 gigabit WAN ports (the RV340W adds Wi-Fi; the RV345 adds more LAN ports and PoE if you need to power a phone or AP at the edge). Re-terminate WAN and LAN cabling to gigabit-rated runs so you actually realize the speed gain.
4. Phased cutover
Stage and pre-configure each RV340 in the lab from your parity checklist, then cut over site by site during a maintenance window. Bring up the new IPsec tunnels alongside the old ones where possible, validate routing and a remote-access login, then decommission the RV042. Keep the old unit on standby for one cycle in case of rollback - but do not return it to production.
5. Secure decommission
Before disposal, factory-reset each RV042 to wipe stored VPN pre-shared keys, certificates, admin credentials, and configs. For federal/DoD and healthcare environments, follow your media-sanitization policy (NIST 800-88) and document the disposal chain. Do not resell or redeploy these units - they are unpatchable and would simply reintroduce the same exposure elsewhere.
Procurement notes for regulated buyers
Source the RV340 through an authorized Cisco partner so you get genuine, warranty-backed hardware with a clean support path - not the gray-market RV042 inventory still floating around. For US public-sector buyers, confirm TAA compliance and country of origin, and the -NA SKU (RV340-K9-NA) for North American power and regulatory domain. RV340-series lead times are generally short, but verify current availability and any AnyConnect license SKUs before committing a cutover date. Government purchase card (GPC) thresholds make the RV340 an easy single-card buy for most single-site refreshes.
To check the exact EoL milestones for your unit, see our RV042-G5 end-of-life page, browse the broader Cisco end-of-life catalog to plan the rest of your refresh, or compare RV340 configurations in our shop.
Ready to refresh your branch?: uniqcli is an authorized Cisco partner serving federal, DoD, SLED, healthcare, and enterprise buyers. We will validate your RV042 inventory, scope AnyConnect licensing, and quote TAA-compliant RV340 hardware with the right SKUs. Get a tailored migration quote at /get-a-quote.
Frequently asked questions
Is the Cisco RV042 still supported in 2026?
No. The RV042 (RV042-G5) reached its Last Day of Support on June 30, 2019, and End of Sale on January 30, 2020. There are no further firmware updates, no security patches, and no TAC support or RMA replacement. Any new vulnerability discovered in it will remain unpatched, which is why it should be replaced rather than kept in production.
What is the direct replacement for the Cisco RV042?
Cisco's recommended successor is the RV340 Dual WAN Gigabit VPN Router (RV340-K9-NA). It keeps the same dual-WAN VPN role but upgrades the 10/100 ports to gigabit, raises NAT throughput to roughly 900 Mbps, supports up to 50 IPsec site-to-site tunnels, and adds modern remote-access VPN (AnyConnect SSL, OpenVPN, IPsec).
Does the RV340 require Smart Licensing or a DNA subscription?
No. The RV340's core features - dual-WAN, firewall, IPsec and OpenVPN, VLANs, and QoS - are included with the hardware and need no recurring license. The only common add-on is AnyConnect client licensing if you want Cisco's SSL VPN client for remote workers, which is purchased per user.
Will my RV042 VPN configuration carry over to the RV340?
Most of it maps directly: dual-WAN load balancing and failover, port forwarding, VLANs, DHCP, and IPsec site-to-site tunnels all have RV340 equivalents. The exception is legacy QuickVPN/PPTP remote access, which the RV340 does not use - you will redesign remote users onto AnyConnect, OpenVPN, or IPsec instead. Export your RV042 config first to use as a parity checklist.
Why does the RV042's Last Day of Support come before its End of Sale date?
It is an unusual but real ordering for this product: LDoS was June 30, 2019, while End of Sale was January 30, 2020. The practical takeaway is that units sold near End of Sale shipped with no remaining support runway, so every RV042 should be treated as fully unsupported regardless of purchase date.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read