Trusted by the Highest-Stakes Buyers
Federal agencies and Fortune 500 operations source through ORM Systems.
US Government & Defense
Enterprise Clients
Hand-picked by our procurement team for standout value. This unit is offered at our sharpest price on current stock, verified against live market rates.
Name:
2 In stock - Ready to Ship
Professionally inspected, bench-tested, and firmware-verified, with configurations wiped. Restored to full working order and backed by our warranty.
3 Year Extended Warranty
Same-day Shipping
30-Day Money Back Guarantee
Shipping:
Payment:
3 Year Extended Warranty
Same-day Shipping
30-Day Money Back Guarantee
Need Additional Discount on Product?
Request a quote below - Get Exclusive Pricing and Support.
Shipping:
Payment:
MX67-HW
Cisco Meraki MX67 Security and SD-WAN Appliance, 700 Mbps Fi...
Federal agencies and Fortune 500 operations source through ORM Systems.
US Government & Defense
Enterprise Clients
Regional teams and 25+ distribution partners keep stock near you and accountability in your time zone.
Pay by PayPal or Revolut with full chargeback rights. Order on PO terms, Net-30 for government.
Every registration we claim is public record — check our federal contractor status yourself before you spend a dollar.

Ten years serving buyers who audit their vendors. From federal agencies to 20,000+ enterprise clients worldwide.
MX67-HW is the Cisco Meraki MX67 cloud-managed security and SD-WAN appliance for small branch deployments that need compact wired edge security without integrated wireless, embedded cellular, or PoE hardware. The platform runs Cisco Meraki MX firmware and is administered through the Meraki Dashboard for policy, firmware, monitoring, alerting, and remote troubleshooting. Hardware includes one dedicated 1G RJ-45 WAN port, one convertible 1G RJ-45 LAN or WAN port, three dedicated 1G RJ-45 LAN ports, and one USB 3.0 port for local hardware connectivity. This bare hardware SKU does not include a bundled MX subscription, so MX Small licensing is purchased separately for Dashboard management and service entitlement. MX68-HW is the closest higher-port sibling, adding ten LAN ports and two PoE Plus LAN ports instead of the MX67 model's four-port wired layout. The compact model is suitable when edge security, VPN scale, and monitored internet access matter more than local switch density, integrated Wi-Fi, or embedded LTE options. For refurbished stock comparisons, port layout and licensing class remain key compatibility checks.
700 Mbps of firewall throughput supports small-branch internet-edge routing, NAT, VLAN segmentation, and Layer 7 policy enforcement across Gigabit Ethernet handoffs. 400 Mbps of NGFW detection throughput and 300 Mbps of prevention throughput size Advanced Security inspection for Cisco Meraki MX 19.1x test conditions, with production results shaped by firmware, traffic profile, and enabled services. 400 Mbps of VPN throughput under RFC2544 testing and 300 Mbps under EMIX testing handle Auto VPN, third-party IPsec peering, and L2TP/IPsec client VPN traffic. 25,000 maximum concurrent sessions provide flow capacity for the documented 50-device sizing point, while 50 site-to-site VPN tunnels, 50 client VPN tunnels, and 100 Cisco Secure Client AnyConnect sessions support small distributed access designs. MX67-HW also supports Dashboard-managed traffic shaping, content filtering, AMP malware protection, IDS/IPS, geo firewall rules, Active Directory integration, Syslog, NetFlow, and remote packet capture with the right license tier.
MX67-HW operates at the branch perimeter, internet edge, or segmentation gateway where WAN circuits, local Ethernet devices, site-to-site VPN, and remote access policy meet. Desktop placement, wall mounting, external 18W DC power, active-passive warm spare pairing with the same model, and one convertible LAN/WAN port support compact deployments with simple cabling. The appliance is useful when buyers need hardware-only ordering while subscription tier, term, and renewal handling stay separate from the device. ORM Systems offers this firewall in new and certified refurbished condition, with serial checks, power-on validation, interface testing, factory reset, accessory confirmation, and license-state review before dispatch. Request a quote for single-site replacement, matched spare appliances, or small-branch standardization across mixed new and refurbished Meraki MX fleets.
MX67-HW price is is available on request. Get immediate quote.
Request bulk order quote for MX67-HW for additional pricing. Browse the full Cisco Meraki Mx Security Appliances series or explore all Cisco products.
MX67-HW sits at the small-branch internet edge where a primary Gigabit WAN circuit, local Ethernet clients, and a compact VLAN design meet. The appliance routes traffic through the dedicated WAN port or the convertible LAN/WAN port, applies Layer 3 and Layer 7 firewall policy, and keeps Auto VPN traffic under Dashboard control. The 700 Mbps firewall rating and 25,000-session limit fit the documented 50-device branch profile. The site gains a compact security boundary with centralized visibility and predictable wired handoff behavior.
Network teams deploy MX67-HW as a small-site VPN edge where local users, remote client sessions, and branch-to-hub tunnels need consistent Meraki policy. The platform supports 400 Mbps RFC2544 VPN throughput, 50 recommended site-to-site VPN tunnels, 50 client VPN tunnels, and 100 AnyConnect sessions in current sizing guidance. Dashboard templates define firewall, VLAN, and Auto VPN settings before the appliance arrives. The deployment gives operations teams a measured tunnel boundary with clear scale limits and repeatable configuration for support teams, auditors, and branch users.
Infrastructure teams place the Cisco Meraki MX67 on a desk, wall, or shelf during small-branch firewall replacement projects that preserve simple Gigabit Ethernet wiring. MX67-HW keeps hardware ordering separate from LIC-MX-S subscription planning, while the base wired design avoids wireless and cellular variant assumptions. Factory reset checks, serial review, and interface validation support refurbished replacement planning before shipment. The refresh creates a consistent Meraki MX appliance standard for branch rollout, spare alignment, lifecycle replacement, and staged swaps with fewer cabling changes.
Mon–Fri: [09:00-16:00]
Avg. response under 30 mins
| Product Type | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / SMB Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall |
| Architecture | Fixed | Fixed | Fixed | Fixed | Fixed |
| Deployment Type | Branch Office | Branch Office | Branch Office | Branch Office | Branch Office |
| Use Case | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection |
| Firewall Layer Supported | Layer 3 / Layer 7 | Layer 3 / Layer 7 | Layer 3 / Layer 7 | Layer 3 / Layer 7 | Layer 3 / Layer 7 |
| Power Source | DC Power Supply | AC Power Supply | AC Power Supply | DC Power Supply | DC Power Supply |
| Redundant Power Supply Supported | Redundant PSU Not Supported | Redundant PSU Not Supported | Redundant PSU Supported | Redundant PSU Not Supported | Redundant PSU Not Supported |
| Firewall Throughput | 700 Mbps RFC2544 1518-byte; 700 Mbps EMIX | 3 Gbps RFC2544 1518-byte; 3 Gbps EMIX | 5 Gbps RFC2544 1518-byte; 5 Gbps EMIX | 700 Mbps RFC2544 1518-byte; 700 Mbps EMIX | 1 Gbps RFC2544 1518-byte; 1 Gbps EMIX |
| Threat Protection Throughput | 400 Mbps detection; 300 Mbps prevention | 2 Gbps NGFW detection; 1.5 Gbps prevention | 2.5 Gbps detection; 2 Gbps prevention | 400 Mbps detection; 300 Mbps prevention | 1 Gbps detection; 800 Mbps Advanced Security; 500 Mbps prevention |
| VPN Throughput | 400 Mbps RFC2544 1400-byte; 300 Mbps EMIX | 2.5 Gbps RFC2544 1400-byte; 2.5 Gbps EMIX | 3.5 Gbps RFC2544 1400-byte; 3.5 Gbps EMIX | 400 Mbps RFC2544 1400-byte; 300 Mbps EMIX | 1 Gbps RFC2544 1400-byte; 1 Gbps EMIX |
| Concurrent Sessions | 25,000 | 200,000 | 250,000 | 25,000 | 50,000 |
| Supported VPN Types | IPsec / Auto VPN | IPsec / Auto VPN | IPsec / Auto VPN | IPsec / Auto VPN | IPsec / Auto VPN |
| Routing Protocols Supported | Static Routing | Static Routing | Static Routing | Static Routing | Static Routing |
| Security Services | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection |
| High Availability | Active-Passive | Active-Passive | Active-Passive | Active-Passive | Active-Passive |
| Interfaces | RJ-45 | RJ-45 / SFP+ | RJ-45 / SFP+ | RJ-45 | RJ-45 / SFP |
| WAN Ports | 1 x 1G RJ-45; 1 x 1G RJ-45 convertible LAN/WAN | 2 x 10G SFP+; 2 x 2.5G RJ-45 | 2 x 10G SFP+; 2 x 2.5G RJ-45 | 2 x 1G RJ-45 | 1 x 1G SFP; 2 x 1G RJ-45 |
| LAN Ports | 3 x 1G RJ-45; 1 x 1G RJ-45 convertible LAN/WAN | 4 x 1G RJ-45; 2 x 10G SFP+ | 4 x 1G RJ-45; 2 x 10G SFP+ | 8 x 1G RJ-45; 2 x 1G RJ-45 PoE Plus | 10 x 1G RJ-45; 2 PoE Plus |
| Management Options | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard |
| Logging & Monitoring | Syslog / NetFlow | Syslog / NetFlow | Syslog / NetFlow | Syslog / NetFlow | Syslog / NetFlow |
| Users Supported | 50 | 500 | 750 | 50 | 200 |
| Form Factor | Desktop | Rack-Mount 1U | Rack-Mount 1U | Desktop | Desktop |
| Device Type | Firewall | Firewall | Firewall | Firewall | Firewall |
| Product Name | Cisco Meraki MX67 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX95 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX105 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX68 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX75 Security and SD-WAN Enterprise Security Appliance |
| Height | 1.1 in | 1.7 in | 1.7 in | 1.1 in | 1.1 in |
| Width | 9.4 in | 19.0 in | 19.0 in | 11.2 in | 11.1 in |
| Depth | 5.1 in | 11.2 in | 12.4 in | 5.8 in | 5.8 in |
| Weight | 0.8 kg | 3.2 kg | 4.9 kg | 1.1 kg | 0.9 kg |
Every unit is authentic, sourced through trusted and authorised channels, and serial-verified on request. Genuine networking and IT hardware, guaranteed, or your money back.
New products are backed by up to 3 years of extended warranty, and certified refurbished units by up to 3 months, for dependable protection on every order. Coverage is clear, honoured in full, and confirmed on each product page.
If a unit ever falls short, our streamlined RMA process gets a replacement to you fast, with advance replacement available to keep your network running. No jargon, no runaround.
Every device is inspected, bench-tested, and firmware-verified, with configurations wiped before dispatch. Additional testing can be arranged to confirm full working condition on request.
Our specialists assist with compatibility, configuration, licensing, and installation, before and after you buy. Real hardware expertise, whenever you need it.
dispatched quickly and shipped worldwide from regional hubs, fully tracked and insured.
Compact Meraki firewall with clear Dashboard controls and enough ports for a small wired branch.
The MX67-HW unit arrived reset, tested, and matched the documented base wired model.
Good option for a small Auto VPN site after confirming MX Small licensing.
The convertible LAN/WAN port helped keep the branch layout simple during replacement.
Refurbished condition was clean, and the appliance passed our receiving checks quickly.
Worked as expected after reviewing the license and accessory requirements.
Useful replacement for matching existing MX67 sites without changing Dashboard templates.
MX67-HW is the Cisco Meraki MX67 hardware security and SD-WAN appliance for small branch networks. It provides cloud-managed firewalling, WAN failover, Auto VPN, content filtering, AMP malware protection, IDS/IPS, Syslog, NetFlow, and remote packet capture. The SKU is hardware only, so Meraki MX licensing is purchased separately for Dashboard management and service entitlement.
The MX67-HW model number identifies the base Cisco Meraki MX67 appliance hardware, not a wireless model, cellular model, subscription bundle, or renewal. Cisco maps MX67-HW to the MX Small licensing class, which uses LIC-MX-S subscription licensing. That distinction matters because the appliance and Meraki license remain separate order items unless a bundle SKU states otherwise.
MX67-HW is a hardware security appliance in the Cisco Meraki MX Security and SD-WAN family. It performs routing and SD-WAN functions, but the product role is firewall, unified threat management, VPN, and small-branch edge security. That makes it appropriate for firewall SKU processing rather than router, switch, access point, power supply, or accessory content.
MX67-HW sits in the small-branch Meraki MX class with MX68-HW, MX67W-HW, and MX67C regional cellular variants. Cisco sizing data places MX67 and MX68 at 700 Mbps firewall throughput, 25,000 maximum concurrent sessions, and 50 recommended devices. MX68-HW is the closest higher-port wired sibling for sites needing more LAN ports and PoE Plus.
MX67-HW supports 700 Mbps firewall throughput in Cisco Meraki MX sizing data for both RFC2544 1518-byte and EMIX testing. Cisco bases those figures on specific test conditions with Layer 3 firewalling, QoS, and DPI. Production planning should still account for traffic mix, firmware release, enabled services, and proof-of-concept validation before standardizing deployments.
Cisco Meraki sizing data lists MX67 at 400 Mbps NGFW detection throughput and 300 Mbps NGFW prevention throughput under Advanced Security EMIX testing. Those figures apply to inspected traffic scenarios, not plain stateful firewall forwarding. Security services such as IDS/IPS, AMP, content filtering, application enforcement, and HTTPS inspection require the appropriate active Meraki entitlement.
MX67-HW supports 25,000 maximum concurrent sessions in Cisco Meraki MX sizing data. Meraki defines a flow as a transmission on an open socket within the last five minutes, and the published figure is a maximum capacity rather than a recommended operating target. Network planners should size below that ceiling for production stability.
MX67-HW provides 400 Mbps VPN throughput under RFC2544 1400-byte testing and 300 Mbps under EMIX testing. Current Cisco Meraki sizing data also lists 50 maximum site-to-site VPN tunnels, 50 recommended site-to-site VPN tunnels, 50 client VPN tunnels, and 100 maximum Cisco Secure Client AnyConnect sessions for the MX67 and MX68 class.
MX67-HW includes one dedicated 1G RJ-45 WAN port, one convertible 1G RJ-45 LAN or WAN port, and three dedicated 1G RJ-45 LAN ports. The rear panel also includes USB 3.0 for external modem hardware, power input, and reset. The base MX67-HW does not include SFP, PoE, Wi-Fi, or embedded cellular interfaces.
MX67-HW is managed through the Cisco Meraki Dashboard for configuration, monitoring, firmware handling, traffic visibility, alerts, and troubleshooting tools. The local status page supports initial WAN configuration when the appliance is being installed. Operational visibility includes historical client usage, Syslog, NetFlow, security event monitoring, and remote packet capture through the Meraki platform.
MX67-HW is used as a compact small-branch firewall and SD-WAN edge appliance where internet access, local VLANs, Auto VPN, and security policy meet. It fits locations that need 700 Mbps firewall throughput, four Gigabit Ethernet LAN positions with one convertible LAN/WAN port, centralized Dashboard operations, and license-gated threat protection from the Meraki MX platform.
Cisco Meraki sizing data recommends MX67 for up to 50 devices, with 25,000 maximum concurrent sessions and 10,000 maximum routes. That places it in a small-branch class rather than a campus, concentrator, or larger distributed-edge role. Final sizing should consider VPN use, security inspection, application behavior, and expected growth.
MX67-HW suits branch perimeter security where a small site needs Gigabit Ethernet WAN access, local segmentation, and centralized policy control from Meraki Dashboard. The appliance supports Layer 3 and Layer 7 firewalling, NAT, geo firewall rules, content filtering, AMP, IDS/IPS, and application enforcement with the correct Meraki license tier.
MX67-HW supports Meraki Auto VPN and third-party IPsec peering, with current sizing data listing 400 Mbps maximum VPN throughput and 50 recommended site-to-site VPN tunnels. It suits small branch edge roles where tunnel counts and client populations remain within MX67 limits. Larger VPN hubs should compare MX75-HW, MX85-HW, or higher models.
Cisco maps MX67-HW to the MX Small product class for subscription licensing, using LIC-MX-S license SKUs. The hardware does not include a subscription by default. Buyers should align the license model, feature tier, subscription term, organization state, and Dashboard binding requirements before installation or replacement.
MX67-HW does not include integrated Wi-Fi. Cisco lists wireless capability on MX67W-HW, while the base MX67-HW remains a wired security and SD-WAN appliance. Buyers needing integrated 802.11ac Wave 2 Wi-Fi should compare the wireless sibling SKU, while buyers standardizing on separate access points usually keep the wired MX67-HW model.
MX67-HW does not include an embedded cellular modem. Cisco lists built-in LTE on cellular MX67C regional models, while the base MX67-HW is a wired model. Cisco also documents that third-party USB cellular modem support is deprecated as of June 30, 2026, so buyers should avoid treating USB cellular as a current support path.
MX67-HW supports Meraki MX warm spare high availability with another MX67 appliance of the same model. Cisco describes MX warm spare as an HA pair using VRRP with active and passive roles. Only one MX license is required for the HA pair, while the secondary unit still requires matching hardware and correct Dashboard configuration.
MX67-HW and MX68-HW share the same 700 Mbps firewall throughput, 400 Mbps maximum VPN throughput, 25,000 maximum concurrent sessions, and 50-device sizing class. The key difference is wired access layout: MX67-HW provides four Gigabit LAN positions with one convertible LAN/WAN port, while MX68-HW provides ten Gigabit LAN ports including two PoE Plus ports.
MX67-HW is the wired base appliance, while MX67W-HW adds integrated 802.11ac Wave 2 wireless for local client access. The firewall and small-branch sizing class remain aligned across the MX67 family. Buyers choose MX67-HW when wireless is delivered by separate access points or when a wired-only edge appliance simplifies branch standardization.
MX67-HW is the non-cellular base model. MX67C-HW-NA and MX67C-HW-WW are regional cellular variants with built-in LTE hardware and carrier-band differences. Buyers choose MX67-HW for wired WAN deployments, while cellular variants fit designs that require embedded LTE failover and the correct regional model for the deployment country.
MX75-HW is a larger small-branch Meraki MX appliance than MX67-HW. Current Cisco Meraki sizing data lists MX75 at 1 Gbps firewall throughput, 50,000 maximum concurrent sessions, and 200 recommended devices. MX67-HW remains smaller, with 700 Mbps firewall throughput, 25,000 maximum concurrent sessions, and 50 recommended devices.
ORM Systems quotes MX67-HW in new condition when channel availability supports the request. New condition suits planned branch rollouts, warranty-sensitive procurement, and deployments that require unused hardware. The sales team confirms part identity, condition, accessories, license status, and commercial terms before purchase approval because Meraki hardware and subscriptions remain separate.
Refurbished MX67-HW is available from ORM Systems when tested inventory is present. Refurbished units suit branch replacements, spare pools, warm spare pairs, and lifecycle projects that need matching Meraki MX hardware. ORM Systems verifies boot behavior, ports, factory reset state, cosmetic grade, accessory set, and license status before dispatch.
MX67-HW pricing depends on condition, quantity, sourcing channel, accessory requirements, destination, and current market availability. ORM Systems provides a quote after confirming whether the buyer needs new hardware, certified refurbished hardware, or mixed-condition supply. License requirements should be quoted separately because MX67-HW is a hardware SKU rather than a subscription bundle.
Lead time for MX67-HW depends on requested condition, order quantity, available stock, and delivery destination. ORM Systems checks new and refurbished sourcing options before confirming dispatch timing. For urgent replacement projects, buyers should provide quantity, target delivery date, destination country, required accessories, and whether a matched warm spare appliance is needed.
ORM Systems supports bulk MX67-HW orders for branch rollouts, replacement programs, spare pool builds, and mixed new or refurbished procurement. Volume quoting accounts for matched quantities, condition mix, testing requirements, accessory expectations, and delivery phasing. Buyers should provide the bill of materials and deployment schedule to align sourcing with rollout milestones.
Cisco Meraki documentation lists MX67 and MX68 hardware warranty coverage as lifetime with next-day advanced replacement, subject to Cisco Meraki warranty processes and eligibility. ORM Systems warranty coverage depends on the quoted condition and commercial package. Buyers should confirm warranty term, return process, support expectations, and license transfer assumptions before purchase order release.
ORM Systems checks refurbished MX67-HW units for successful boot behavior, visible chassis condition, port availability, power-adapter presence, factory reset state, serial identification, and license-state concerns before dispatch. Interface checks matter because the appliance has one dedicated WAN port, one convertible LAN/WAN port, and three dedicated LAN ports.
Cisco Meraki documentation reviewed for MX67-HW does not publish a detailed safety, EMC, or telecom compliance table in the same way some hardware datasheets do. Buyers with strict regulatory requirements should request project-specific compliance documentation before deployment. The product documentation does identify MX67 and MX68 as enterprise security appliances for distributed deployments.
MX67-HW is added to a Meraki Dashboard network before installation, then connected to power and a wired internet connection for firmware and configuration updates. The local status page supports basic WAN setup, VLAN tagging, PPPoE, web proxy, and Ethernet link settings. Dashboard claiming requires order or serial information and proper licensing.
MX67-HW requires a Meraki license for normal Dashboard-managed operation. Cisco maps this hardware to the MX Small class under subscription licensing, and traditional MX licensing uses security appliance licenses such as Enterprise, Advanced Security, or Secure SD-WAN Plus. The hardware-only SKU does not include an active or transferable subscription by itself.
The MX67 package contents include the appliance, power adapter, and two CAT5e Ethernet cables, with no power cable listed in the installation guide. Buyers should confirm the required regional power cord, Ethernet cabling, mounting hardware, license entitlement, Dashboard access, and any warm spare requirements before scheduling an installation window.
Buyers can purchase MX67-HW from ORM Systems for UK procurement, subject to available new or certified refurbished supply. The quote should identify the exact SKU, requested condition, quantity, license requirements, accessories, delivery destination, and warranty expectations. ORM Systems confirms hardware availability and commercial terms before order placement.
ORM Systems supports international MX67-HW sourcing and shipment when export, carrier, and destination requirements are workable for the order. Buyers should provide destination country, quantity, preferred condition, delivery deadline, and any documentation requirements during quotation. Shipping speed, cost, and availability are confirmed from actual stock and logistics options.