Upgrade-Replace Meraki MX84 (HA-Warm Spare) to MX85 in the same network

rhamersley
Getting noticed

Upgrade-Replace Meraki MX84 (HA-Warm Spare) to MX85 in the same network

Cisco Meraki is requiring that I replace existing end‑of‑life MX84 HA pair appliances I have in my networkf with a new MX85 HA pair.   The reason is due to the firmware restriction on the MX84.   I need to upgrade to the MX85 and preserve all the same configurations.   

 

Is there any step by step procedure documentation to perform this.   I have no problem requiring down time.

Im sure there has to be documentation out there to perform this since the Meraki MX 84 and the Meraki MX 100 security appliances are coming to end of life and unable to update to the latest "Stable" firmware levels that has been released for the MX appliances.

 

Can I perform the following steps:

* Claim the (2) new Meraki MX85 appliances 

* Add the Enterprise security licenses for the MX85 appliances

* Remove the (2) Meraki MX 84 appliances from the network

* Add the (2) new MX 85 appliances into the network that the MX84 appliances were removed.

* Make sure the new MX 85 appliances have been properly updated with the circuit IP address to bring it online in the network.

 

* THIS IS WHERE I NEED CLARIFICATION

 

* Will I be able to clone the MX85 to the MX84 appliances that I removed so all the configurations load onto the new MX85 appliances?

2 Replies 2
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

Here's the doc https://documentation.meraki.com/MX/Other_Topics/MX_Cold_Swap_Replacing_an_Existing_MX_with_a_Differ...

 

You're way better off with the MX85 instead of the 84. 

 

The main thing you need to address is the port mapping difference on the LAN side which is covered in the doc. And of course if you uses static IPs on the 84s you'll need to configure those on the 85s before you move them into service.

GIdenJoe
Kind of a big deal
Kind of a big deal

If you want to use the method as you described where you want to remove the existing devices from the same network to avoid changing your dynamic dns and other stuff.

 

Then I would recommend:
- Claim your new licenses and devices
- Create a temporary network and place the new devices in there  (first primary then spare)
- If you have a testing network somewhere where you can create that public subnet behind a NAT then you can just bring them online there and already update them to the desired firmware version.
- Then plan your firmware upgrade on the old network matching the version of the temp network.  (mind that your MX84 will go to the 18.107.xx version instead but do it on an outage window.
- If you can't bring the new devices online on a test network then you will have to temporarily bring them online with another IP so they can update.  But then you will have to later change their uplinks to match the current ones.  When they fail to go online with the new IP, disconnect them and they are ready to be moved.  Then just remove the MX'es from their temp network.

Get notified when there are additional replies to this discussion.