Uniqcli

Meraki Z1 EoL: Migrating to the Z3 Teleworker Gateway

The Meraki Z1 (Z1-HW) passed Last Day of Support on July 27, 2025. Here is what that means for your remote sites and how to refresh cleanly to the Z3 — and plan ahead for the Z4.

UT
Uniqcli Team
January 21, 2026 · 8 min read
Share
Meraki Z1 EoL: Migrating to the Z3 Teleworker Gateway

If you still have Cisco Meraki Z1 Cloud Managed Teleworker Gateways (PID Z1-HW) sitting on home-office desks, at remote clinics, or in small satellite sites, they are now past every Meraki lifecycle milestone that matters. The Z1 reached its Last Day of Support on July 27, 2025. From that date forward Cisco Meraki provides no firmware updates, no security fixes, no TAC support, and no RMA hardware replacement for this model. The little gateway keeps establishing its tunnel back to headquarters, which is precisely why these units quietly outlive their support window. This guide explains what the end-of-life dates mean for a fleet still in production, why the recommended Z3 is a genuine upgrade rather than a like-for-like swap, and how to plan a clean refresh — including why, in 2026, you should be looking past the Z3 to the Z4.

What the Meraki Z1 actually was

The Z1 (Z1-HW) was a compact, fanless, cloud-managed security appliance built for the single-employee remote office. Hardware-wise it offered five 10/100/1000 LAN ports plus one Gigabit Ethernet WAN/internet uplink, an integrated dual-band 2x2 802.11n radio for local Wi-Fi, and a USB port for a 3G/4G cellular modem as a backup uplink. It carried no PoE output, a single WAN interface, and a modest stateful-firewall throughput in the neighborhood of 50 Mbps. Its whole reason for existing was that it was managed entirely from the Meraki dashboard alongside the corporate MX firewalls, so a teleworker site could be provisioned with the same VLANs, firewall policy, content filtering, and Auto VPN tunnel as the rest of the estate — zero-touch, no on-site CLI.

For 2014-era home broadband and 802.11n laptops, that was a clean fit. The problem is what has changed underneath it: gigabit home broadband, Wi-Fi 6 clients, AnyConnect/Cisco Secure Client remote access, and a threat landscape where an unpatched edge device is a foothold. The Z1's 802.11n radio and ~50 Mbps firewall ceiling are now the bottleneck at exactly the sites where remote workers expect office-grade performance.

Why acting now matters

The dangerous thing about an end-of-life gateway is not that it stops working. It is that it keeps working while the support floor disappears beneath it. Three exposures stack up after LDoS:

  • No security firmware. When a new vulnerability is disclosed in the MX/Z firmware family, the Z1 will not receive a fixed build. Because the device is internet-facing and terminates a VPN tunnel into your corporate network, an unpatchable edge appliance is a direct lateral-movement risk, not a theoretical one.
  • No TAC or RMA. A failed Z1 cannot be opened as a support case or swapped under contract. Your only recovery is a spare you bought before LDoS or a dead-end secondary-market unit of the same retired model.
  • Cloud-management drift. This is the Meraki-specific trap. The dashboard firmware moves forward continuously, and end-of-life hardware eventually falls off the supported firmware trains. A Z1 can lose features, stop receiving config pushes cleanly, or fail to check in — with no remediation path — purely because the cloud moved on without it.

What each milestone means in practice

  • End of Sale (2018-07-27): the last day Cisco Meraki accepted new Z1 orders. Everything after this date was consuming the support tail.
  • Last Day of Support / LDoS (2025-07-27): the hard cutoff. No firmware, no security fixes, no TAC, no RMA. Every Z1 in service today is past this line and running fully unsupported.

Cisco's documented successor to the Z1 is the Cisco Meraki Z3 Cloud Managed Teleworker Gateway (PID Z3-HW). It keeps the same dashboard-managed, zero-touch model the Z1 pioneered, so your operations team manages it exactly the same way — but the hardware is a generation ahead in every way that matters at a remote site.

What the Z3 does better than the Z1

  • Wi-Fi: the Z3 upgrades the local radio from 802.11n to dual-band 2x2:2 802.11ac Wave 2, a real-world throughput and client-density jump for the laptops and devices on a teleworker's desk.
  • PoE: the Z3 adds one 802.3at PoE+ output port — something the Z1 entirely lacked — so the gateway can power a downstream Meraki AP or IP phone at the remote site without a separate injector.
  • Throughput and security services: the Z3 roughly doubles usable firewall/VPN throughput (about 100 Mbps stateful firewall, with VPN and threat-inspection performance scaled accordingly), keeping pace with gigabit home broadband where the Z1's ~50 Mbps ceiling chokes.
  • Remote access: the Z3 supports modern client VPN including AnyConnect / Cisco Secure Client termination alongside Meraki Auto VPN site-to-site tunnels, which matters for hybrid-work access patterns the Z1 was never designed for.
  • Cellular failover: both retain USB-based cellular backup, but the Z3 supports current LTE modems where the Z1's options were 3G/4G-era and increasingly stranded on sunset carrier networks.

One important procurement note: the Z3 is itself now end-of-sale (announced September 4, 2024, with end-of-support September 4, 2029), and its functionally equivalent successor is the Z4 — which brings Wi-Fi 6 and higher throughput. For net-new purchases in 2026, standardize on the Z4 unless you specifically need a same-generation match to an existing Z3 fleet. The Z3 remains a valid, fully-supported landing spot through 2029; we will steer you to whichever fits your timeline and budget.

A practical migration plan

1. Inventory and assess

Pull a dashboard report of every Z1 serial, its bound network, and its license expiry. Note each site's WAN type (does it need cellular failover?), whether any downstream device wants PoE, and the remote user's broadband speed — sites on gigabit fiber are the ones whose performance the Z1 is actively capping. This list is your bill of materials and your cutover schedule in one.

2. Plan licensing

Meraki licenses per device, by term, in Enterprise or Advanced Security tiers. You cannot migrate a Z1 license onto new hardware — each Z3 or Z4 needs its own current license. Choose Advanced Security where you want the full threat-inspection feature set (IDS/IPS, AMP, content filtering) at the remote edge; Enterprise where basic SD-WAN, VPN, and management suffice. Align all new license terms to a common renewal date to simplify future budgeting.

3. Clone config, don't rebuild

The advantage of staying in the Meraki dashboard is that policy lives in the cloud. Create the new appliance network (or clone the existing Z1 network), claim the new Z3/Z4 serial, and the VLANs, firewall rules, traffic shaping, content filtering, and Auto VPN settings push down on first check-in. Verify feature parity explicitly — confirm the VPN tunnel comes up, client VPN authenticates, and any port-forwarding or static routes carried over correctly before you remove the old unit.

4. Physical and phased cutover

The Z3/Z4 footprint is similar to the Z1, so most sites are a straight swap: move the WAN uplink and LAN drops, plug in cellular if used, and connect any PoE device to the new PoE+ port. Because these are unstaffed remote sites, ship the pre-claimed appliance to the user with a one-page swap sheet, or have them keep the Z1 cabled until the new unit checks in green. Cut over in waves — a pilot site first, then by region — so any surprise is caught on one desk, not the whole fleet.

5. Secure decommission

Once a site is confirmed on its replacement, remove the Z1 from the dashboard, factory-reset the hardware to wipe stored config and keys, and dispose of it through a documented, asset-tracked process. For regulated environments, capture the wipe and disposal in your asset records — a retired-but-undocumented gateway is its own audit gap.

Procurement notes for regulated buyers

Lead times on Meraki teleworker hardware fluctuate, and the Z3's end-of-sale status means remaining stock is finite — another reason net-new buyers should plan around the Z4. For federal and DoD work, confirm TAA compliance and country-of-origin on the specific units you order, and route the buy through GPC or your contract vehicle as appropriate. As an authorized Cisco partner, uniqcli sources genuine, warranty-backed Meraki hardware with correct licensing attached, validates TAA status, and can bundle the right Enterprise or Advanced Security term so the appliance arrives ready to claim.

Browse current teleworker and Meraki options in our catalog, review the full lifecycle record for this model on the Z1-HW EoL detail page, or see all retiring Cisco hardware on our Cisco end-of-life hub. When you are ready to scope the refresh, get a quote and we will return a sized bill of materials — Z3 or Z4, correct licensing, TAA confirmation, and lead times — for your remote-site fleet.

Frequently asked questions

Is the Meraki Z1 still usable after July 27, 2025?

It will keep passing traffic, but it is fully unsupported. After Last Day of Support, Cisco Meraki issues no firmware or security fixes, no TAC assistance, and no RMA hardware replacement for the Z1. Because Meraki is cloud-managed, there is also real risk that future dashboard firmware trains drop the Z1 entirely, at which point the device can stop checking in or lose features without any path to remediate. Treat any Z1 still in service as a liability to retire, not an asset to keep.

Do I have to replace the Z1 with the Z3, or can I jump straight to the Z4?

Either works, and for new purchases in 2026 the Z4 is the better target because the Z3 itself is now end-of-sale (announced September 4, 2024, with support through September 4, 2029). The Z3 is the direct documented successor and is a clean like-for-function swap; the Z4 is the current-shipping model with Wi-Fi 6 and faster throughput. We typically recommend standardizing new deployments on the Z4 while using remaining Z3 stock only where a same-generation match to an existing fleet matters. Our team can confirm availability and TAA status for either.

Will my existing Meraki licenses and dashboard config carry over?

The dashboard configuration concept carries over, but the hardware is licensed per device, so each new Z3 or Z4 needs its own current Meraki license (Enterprise or Advanced Security, by term). You cannot move a Z1 license onto new hardware. The good news is that network policy — VLANs, firewall rules, Auto VPN, traffic shaping, content filtering — lives in the cloud dashboard, so you clone the Z1's network settings to the new appliance rather than rebuilding from scratch. Claim the new serial, bind it to the network, and the config pushes down on first check-in.

What is the security and compliance risk of leaving a Z1 deployed?

An unpatchable internet-facing gateway at a remote worker's home or a small remote site is exactly the kind of finding that FedRAMP, CMMC, HIPAA, and PCI DSS assessors flag. After Last Day of Support there is no mechanism to remediate a newly disclosed vulnerability on the Z1 — 'the vendor no longer ships fixes' is not an acceptable mitigation. For federal, DoD, SLED, and healthcare buyers, that turns every remaining Z1 into audit exposure that compounds the longer it stays online.

Does the Z3 add PoE, and does that matter for a teleworker site?

Yes. The Z3 includes one 802.3at PoE+ output port, which the Z1 lacked entirely. At a remote or home-office site that lets the gateway power a small downstream device — a Meraki access point or an IP phone — without a separate injector or brick. It is a small hardware change with an outsized impact on cable-clutter and reliability at unstaffed remote desks, and it is one of the concrete reasons the Z3 is a real upgrade rather than a like-for-like box.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote