Meraki Z Series in a MX Advanced Security Environment

Here to help

Meraki Z Series in a MX Advanced Security Environment


I am currently designing a MX Environment that will make use of the features in the Advanced Security Licence.
Specifically the following:
URL Content Filtering
Intrusion Prevention
Advanced Malware Protection (AMP) with Threat Grid support
Layer 7 Geo-IP Firewall Rules.

I believe that you can't have an MX customer environment where you are using both Enterprise an Advanced Security Licences.

However the customer has asked for an alternative device to the MX for sites with 1-2 users, where the MX64 is seen as providing over capacity. We are considering the Z series for these site types, however we have noticed that the Advanced Security Licence is not available.

I have looked into this a little, and have seen discussions that say you can mix the Z Series with an Enterprise Licence in a customer environment that is also using the MX Appliances with Advanced Security Licences.

Firstly is this correct, can you mix the Z Series and MX with Sec Licences?

Secondly, if you can mix them, do you loose the support for URL Content Filtering Intrusion Prevention
Advanced Malware Protection and Layer 7 Geo-IP Firewall Rules on the Z Series?

Kind of a big deal

Yes to both questions.  You can mix them in your environment, but they don't support advanced features.


*However, you may still get advanced feature use if tunneling Z traffic through an MX.



Kind of a big deal

I believe the recommended method for this deployment is one network for the MX and main office. Then one network for each branch/satellite office with one Z device. Then utilize AutoVPN back to MX. This should keep your security features if setup correctly.

Can the Remote MX's with the Advanced Security Licence connect to the same central MX as the Remote Z Series that are running the Enterprise S/w. i.e. can the same Central MX support the two networks that are running differing s/w types?

Kind of a big deal
Kind of a big deal

Yes the SD-WAN features currently available don't differ for Enterprise or Advanced licenses, though with the new SD-WAN license on top that might change.  I don't see even that change affecting the ability of Zs to connect.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.