Upgrading MX Firewall To New Firewall

jamesb33
Here to help

Upgrading MX Firewall To New Firewall

Hi I'm not sure if this is the right place

 

We currently have an MX-67 i'm needing to upgrade our firewall to 8 ports intead of 4 

 

Or can I extend the firewall if i'm needing more ports for our Switches? 

 

I'm needing up to 6/7 ports so an 8 Port MX Firewall would be ideal 

 

Also how do I migrate the existing settings from our MX67 to the new MX we purchase?

 

Thank you,

James

11 Replies 11
Brash
Kind of a big deal
Kind of a big deal

For 8 lan ports you'll need and MX68/W/CW or 75

For migrating to a different model, you can follow the below doc

https://documentation.meraki.com/MX/Other_Topics/MX_Cold_Swap_Replacing_an_Existing_MX_with_a_Differ...

KarstenI
Kind of a big deal
Kind of a big deal

The main question is why do you need more ports on the firewall? I assume that you connect your devices directly to the firewall and now have more than four devices. An MS120-8 is the device that I would use in this situation.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
GIdenJoe
Kind of a big deal
Kind of a big deal

The only use case you have is when you have a very small environment without switches where you have a few endpoints that need connection.

 

For all other use cases, only connect each firewall with two ports downstream and use switches for more connectivity.

jamesb33
Here to help

So right now I have 1 MX67 and 6 Switches


We only only have 4 ports on the back of the firewall and I need each switch to be connected to the back of the firewall so this leaves me with only 2 ports needed. 

Is there a way that I don't need to use all the Ports on the back of the firewall and just daisy chain the connection to each switch? 

I hope that makes sense

PhilipDAth
Kind of a big deal
Kind of a big deal

>Or can I extend the firewall if i'm needing more ports for our Switches? 

 

I'm confused by this bit.  Have you already got network switches?  Are they short on ports?

 

Or have you got a bunch of network switches, and you plug them directly into the MX?  If this is the case, I would nominate one of those switches to be the "core" switch, and plug all the other switches into that switch.  Then you'll only need a single port on the MX67.

jamesb33
Here to help

So right now I have 1 MX67 and 2 meraki switches and 4 offbrand Switches


We only only have 4 ports on the back of the MX firewall and I need each switch to be connected to the back of the firewall so this leaves me with only 2 ports needed. 

Is there a way that I don't need to use all the Ports on the back of the firewall and just daisy chain the connection to each switch? 

I hope that makes sense

PhilipDAth
Kind of a big deal
Kind of a big deal

>Is there a way that I don't need to use all the Ports on the back of the firewall and just daisy chain the connection to each switch? 

 

Nominate one switch to be the core switch.  Only plug that switch into the MX.  Plug all other switches into the core switch.

jamesb33
Here to help

So what you are saying is connect the firewall into switch 1 

 

Then all other switches go into switch 1 ? Correct


Do i need to do any configure in the MX firewall to set this?

 

Thank you, 

PhilipDAth
Kind of a big deal
Kind of a big deal

Correct.  You are not likely to need to make any changes on the MX.

jamesb33
Here to help

So i found our our switches are the MS-220-48LP model and are not layer 3 based which I believes carries down the information right?

Mike6116
Getting noticed

Yo will have the same functionality and performance  if you nominate 1 sw as the core  and then connect other sw to the core sw,   also you can daisy chain the switches and you will have good performance as they will run in a 1gig speed between them, you can make some Vlan arrange for the swithces to have a different ip for managment also

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels