Meraki is Now Cisco Cloud – Same Simplicity, New Name, Extended Capabilities
Users of Meraki love its strengths of simplicity, cloud-management and full-stack networking. Conversely the Cisco brand is often associated with more complex, enterprise and expensive, albeit extremely reliable technology. Therefore, the news that the Meraki brand is being sunsetted in favour of Cisco Cloud has resulted in a lot of questions from the loyal user-base. This blog will attempt to address some of those questions, explaining what changes have been made, why they have been made and clarifying how that effects users day-to-day.
Anyone who has purchased a Meraki Access Point, Switch or Firewall in recent years will have noticed that the hardware has been branded "Cisco" for a while now, with no mention of the "Meraki" label on the kit. More recently, those searching for the latest generation hardware will have been directed to Cisco Catalyst products as opposed to the familiar Meraki MX, MR and MS Meraki ranges. As a Meraki user, does that mean I need to change anything?
Why Now? A Product Refresh Ripe for the Taking
Most of the traditional Meraki stack have been around for several years and are approaching their End of Sale dates. The last MR Access Points and MX firewalls were released a few years ago, and only a handful of switches such as the MS130 and MS150 can be considered latest generation. The time is ripe for a product refresh and Cisco have taken the opportunity to release the new Catalyst range. These are a single piece of unified hardware that can run either in a Cisco-controller deployment using Cisco licencing, or as part of a Meraki (or Cisco Cloud) deployment using Meraki licensing.
What Do We Gain (and Lose) From This Integration?
Firstly, we are gaining better hardware. Additionally, the potential integrations and flexibility will benefit certain users. For example, if a user wanted a dual power supply on a Meraki switch, they would need to get a relatively powerful switch to get that functionality. Whereas that is native in the Cisco switch hardware. The ability to switch between Cisco On-Prem and Cisco Cloud management modes also means that an organisation can move back and forth between them as necessary, or if one department of an organisation requires more complexity, they can still run the same unified hardware as their other departments. This integration therefore also allows for complex deployments to benefit from the simple, zero-touch provisioning and remote management found within the Cisco Cloud management dashboard.
Recent End of Sale Announcements
Meraki Systems Manager has been discontinued, and Cisco's recommended replacement is Ivanti Neurons which is a mature well-regarded product in the market. Meraki have also announced that they will not be continuing with the MT sensors and instead focusing efforts on building the sensor functionality onto other devices, for example using Access Points for occupancy monitoring, as well as integrating directly with non-Cisco devices.
Wireless: The Move to Wi-Fi 7
Moving our focus to wireless, Meraki have announced that the much-loved Wi-Fi 6 Access Point range including the MR36, MR44, MR46 and MR56 AP's will no longer be available from 2027 and have been replaced by the Catalyst Wi-Fi 7 range. The introduction of the 6 Gigahertz spectrum massively increases capacity and reduces latency on these devices. The new APs can handle more clients, more data and more complex applications, resulting in a better user experience all round.
The new Catalyst Wi-Fi 7 access point range now have unified licensing so you can be using the same license with a Meraki (Cisco Cloud) deployment one day and with a Cisco Catalyst deployment (alongside a Catalyst 9000 Controller or Virtualized equivalent) the next day. The dual-deployment opens new opportunities for large fabric networks using Cisco software-defined access, while customers preferring a simple Meraki (Cisco Cloud) deployment, can simply add the new AP to their existing Meraki dashboard and not see any changes in management of the Access Point.
Wider Network Implications of a Wi-Fi 7 Refresh
When considering a Wi-Fi 7 wireless refresh, it is important to consider the wider implications on the network at the same time. In the last few years, we have seen a massive migration from on-prem deployments to the Cloud. Traditionally, it was said that 80% of traffic would be inside the firewall and 20% through the firewall, and that has shifted in the last few years and is an important factor to consider even with Wi-Fi 5 or Wi-Fi 6 deployments.
When looking at Wi-Fi 7 specifically, some organisations get caught out with how power hungry the APs can be. While Wi-Fi 6 access points tended to consume 15-20W per AP, this has increased to around 30-35W each for Wi-Fi 7 devices which will affect deployments in two ways:
- PoE switches need to cope with 30W plus power per port without reducing capabilities of the AP
- Total power in the switch needs to be enough to accommodate total number of devices deployed — for example, a 740W switch will only be able to power around 24x Wi-Fi 7 APs
Additionally, all Wi-Fi 7 APs have M Gig ports on them — these could be 2.5 Gig, 5 Gig or 10 Gig depending on which Wi-Fi 7 AP you choose. So, if an organisation is experiencing a bottleneck currently of a 1 Gig Ethernet link between the access points and switch, and now increases the AP throughput massively, potentially that could just shift the bottleneck to the switches without seeing an improvement in performance.
In summary, to maximise the benefits of a Wi-Fi 7 wireless upgrade, you will need to ensure that the rest of the deployment including firewalls and switching can handle the increased throughput available as well. While the newer Meraki switches such as the MS130 and MS150 can manage a Wi-Fi 7 deployment in limited mode, for those looking at denser Wi-Fi deployments, we would recommend the Catalyst 9300 switch range. As well as having the option of dual power supply which would double the overall PoE budget (e.g. from 740W to 1480W), the Cat 9K range also have smart features meaning that you can prioritise which ports get PoE and intelligently manage PoE budget that way as well.
Firewalls: The MX Range and the Move to C8000
Meraki haven't released new MX firewalls for several years. The MX84 and MX100 lines are due to go End of Life shortly, and even the MX75, MX85, MX95 and MX105 cannot be considered latest generation. Throughput of these firewalls haven't kept pace with the trending move towards larger internet lines. A small business using a 1 Gig line would need to look at a MX95 or larger unit to ensure no bandwidth bottleneck on their firewall, even if that firewall would otherwise be overkill for their needs.
One way to maximise throughput on an existing MX firewall is to apply smart policies to bypass the IPS for certain things such as trusted traffic going to a cloud tenancy. Additionally, many organisations are also massively improving firewall throughput by going down the SASE route with the likes of Secure Access and Cisco Umbrella and pushing complicated policies to the Cloud. This is done by building a secure tunnel from the edge device to one of Cisco's Umbrella towers and configuring the secure policies there. The benefit of doing this is that the policy only needs to be configured once for multiple sites and then all the MX devices and remote users can be aligned to those policies as well, giving you a central point of control and visibility for all secure security policies, whether it's a core site, remote site or remote user.
Currently many organisations will rely on VPNs connecting a branch office firewall to the head office. The problem with this is that it is reliant on user behaviour or a local file on the device to control the traffic and where they are going. Conversely, when deploying a SASE or SSE solution, an agent on the endpoint directs all traffic through a secure tunnel to a cloud-based firewall. So regardless of where the user is and how they connect (home broadband, customer guest network, 4G/5G tethering, coffee shop or hotel etc), the same security policies are applied with the same filtering and same visibility in the single Cisco Secure Access management portal.
For fully remote organisations where every single asset is cloud-based such as Office 365, AWS, Google Suite and the like, Cisco Secure Access can also be used and the policy can be configured to, for example, allow view-only files but block downloading the customer database, payment details, credit card details etc, removing the need for a firewall altogether.
We also expect the Meraki MX firewall range to be going End of Sale soon and Cisco have begun launching the first of the new C8000 firewall range which will replace them. With very similar features, faster throughput and a cheaper price-point, they represent the next step of the Cisco Cloud Security evolution.
Licensing Changes: Subscription vs Co-term
Organisations approaching renewal will have also noticed that the Meraki dashboard is now recommending the new Subscription licensing rather than the default co-term option. Both options are still available, but the main benefit of the Subscription choice is the flexibility that it offers in terms of fixing a renewal date and allowing users to keep the same license but upgrade (or downgrade) devices mid-term without losing the balance of their existing license. Devices are now grouped in sizes with one license covering all devices within that group, allowing flexibility within the license.
Once an organisation has a subscription, they can also change tiers within that subscription without changing the end date, or extend the end date without changing the devices within it, giving organisations far more control over when the license is going to run to and from. Lastly, within an organisation on the dashboard, you can create multiple tiers meaning that the network is now the license boundary, and an organisation can have multiple networks. Unlike traditional co-term licensing, this means that an organisation can run branch office firewalls with a different license to the main HQ if they set up the configuration as separate networks.
In Summary
The new changes from Meraki to Cisco Cloud are part of the wider trend towards cloud managed deployments with flexible provisioning. The slogan "Simple by Default, powerful when needed" sums up the Cisco Cloud opportunities which are available if required, but do not remove the much-loved simplicity that Meraki has offered until now.
