Cisco Meraki MX Firewalls
Cisco Meraki Firewalls. Cloud managed security that just works.
Cisco Meraki MX appliances pair next generation firewall security with SD-WAN and a single cloud dashboard, so every site stays visible and consistent without local hardware to babysit. Connect every site with the full MX lineup, manage it all through the same Meraki dashboard.
Shop by Series
Meraki MX64
Entry-level MX with 200 Mbps firewall throughput and dual WAN for WAN failover. A practical choice for a small office that wants cloud-managed security without a lot of hardware.
Shop Meraki MX64 →
Meraki MX67
700 Mbps firewall throughput in the same compact desktop form factor. The MX67C adds a built-in LTE modem for sites that need automatic cellular failover without a separate router.
Shop Meraki MX67 →
Meraki MX68
Same 700 Mbps throughput as the MX67 with 8 LAN ports including 2 PoE+ ports for powering access points or IP phones directly from the firewall. Available with built-in Wi-Fi or cellular in the MX68W and MX68CW variants.
Shop Meraki MX68 →
Meraki MX75
Steps up to 1 Gbps firewall throughput in a desktop enclosure, making it the right fit when a branch has outgrown the MX67 or MX68 but does not yet need a rack-mount unit.
Shop Meraki MX75 →
Meraki MX84
The first rack-mount model in the MX lineup, with 500 Mbps firewall throughput and dedicated SFP uplinks for fiber WAN. A solid starting point for a branch office that needs a rack presence.
Shop Meraki MX84 →
Meraki MX85
Doubles the MX84 throughput to 1 Gbps with SFP uplinks and PoE on one of the WAN ports. A practical upgrade for sites that have grown past 250 users or need more headroom for next generation firewall features.
Shop Meraki MX85 →
Meraki MX95
2 Gbps firewall throughput with SFP+ fiber uplinks for high-bandwidth WAN circuits. Handles up to 1,000 users comfortably and is the recommended minimum for sites running the Advanced Security license at scale.
Shop Meraki MX95 →
Meraki MX100
An established 1U rack platform with 750 Mbps firewall throughput and dual SFP uplinks. A reliable choice for a midsize campus or a branch with existing infrastructure built around the MX100 platform.
Shop Meraki MX100 →
Meraki MX105
2 Gbps firewall throughput with a dual power supply option for sites that need redundancy at the firewall layer. SFP+ uplinks and high concurrent session capacity make it the right pick for a large branch that cannot afford unplanned downtime.
Shop Meraki MX105 →
Meraki MX250
4 Gbps firewall throughput with dual power supplies and SFP+ uplinks. Built for a large campus or headquarters that consolidates multiple branch VPN tunnels and runs full next generation firewall inspection across all of it.
Shop Meraki MX250 →
Meraki MX450
The flagship MX appliance, with up to 10 Gbps firewall throughput, 6.5 Gbps site-to-site VPN throughput, SFP+ uplinks, and dual power supplies. Designed for a data center edge or a headquarters aggregating a large network of branch sites.
Shop Meraki MX450 →
Meraki vMX
No hardware to rack. The vMX runs inside your cloud VPC and extends the same SD-WAN and security policy as your physical MX appliances, all managed from the same dashboard. The right choice for hybrid and cloud-first environments.
Shop Meraki vMX →Cisco Meraki Firewalls at a Glance
| Model | Best For | Recommended Users | Form Factor | Key Feature |
|---|---|---|---|---|
| MX64 | Entry-level small office | Up to 50 users | Desktop | 200 Mbps firewall throughput, simple cloud setup |
| MX67 | Small branch or remote office | Up to 50 users | Desktop | 700 Mbps firewall throughput, optional built in LTE (MX67C) |
| MX68 | Small branch needing PoE | Up to 50 users | Desktop | 700 Mbps firewall throughput, 8 PoE+ ports for APs and phones |
| MX75 | Growing branch office | Up to 200 users | Desktop | 1 Gbps firewall throughput, dual WAN for active/active links |
| MX84 | Established branch office | Up to 250 users | 1U rack | 500 Mbps firewall throughput, rack mount build |
| MX85 | Midsize branch | Up to 500 users | 1U rack | 1 Gbps firewall throughput, SFP and PoE uplink options |
| MX95 | Busy midsize site | Up to 1,000 users | 1U rack | 2 Gbps firewall throughput, SFP+ fiber uplinks |
| MX100 | Midsize campus | Up to 500 users | 1U rack | 750 Mbps firewall throughput, established rack platform |
| MX105 | Large branch needing uptime | Up to 1,000 users | 1U rack | 2 Gbps firewall throughput, dual power supply option |
| MX250 | Large campus or headquarters | Up to 2,000 users | 1U rack | 4 Gbps firewall throughput, dual power supply |
| MX450 | Enterprise data center edge | 5,000+ users | 1U rack | 10 Gbps firewall throughput, SFP+ uplinks, dual power supply |
| vMX | Cloud VPC and hybrid workloads | Scales with instance size | Virtual appliance | Deploys in AWS, Azure, or GCP for SD-WAN into the cloud |
Cisco Meraki Firewall FAQ
The difference comes down to throughput and user count. The small branch series, the MX67, MX68, and MX75, are desktop units built for a single office of up to 200 users. The midsize series, the MX84, MX85, MX95, and MX105, are 1U rack appliances for branches and regional hubs handling up to 1,000 users. The MX250 and MX450 are built for a headquarters or data center edge supporting thousands of users at multiple gigabits of throughput.
Yes. Every Meraki MX needs an active license to operate, since the firewall, content filtering, and cloud dashboard are all delivered through the subscription. We size the right license tier, Enterprise or Advanced Security, alongside your hardware so the appliance is ready to register the day it arrives.
The vMX is a virtual version of the MX that runs in AWS, Azure, or Google Cloud instead of on a physical appliance. Teams use it to extend the same SD-WAN and security policy from their branch offices into a cloud VPC, managed from the same Meraki dashboard as the hardware MX units.
Yes. Every MX model ships with SD-WAN built in, including active or active VPN across multiple WAN links, policy based routing, and dynamic path selection that reroutes traffic when a circuit degrades. No separate SD-WAN license or appliance is required.
Yes. Our certified engineers offer a Firewall Configuration Service to set up your MX before it arrives, and FireGuard Managed Services to monitor and maintain the appliance once it is live. Both work alongside Meraki's cloud dashboard rather than replacing it.
Yes. The Meraki dashboard manages every MX model, from an MX67 at a small branch to an MX450 at headquarters, inside a single organization. Policies, firmware, and reporting stay consistent across the whole network regardless of which model sits at each site.
If a Meraki license lapses, the appliance keeps passing existing traffic for a grace period, but the dashboard loses access to configuration changes, firmware updates, and security features until the license is renewed. We track renewal dates for our customers so coverage does not lapse unexpectedly.
Not sure which Cisco Meraki Firewall is right for you?
Tell us your user count, site count, and WAN setup, and a certified engineer will recommend the right MX model and license tier for your environment.
Get a Sizing Recommendation
Login and Registration Form
Existing User