Trusted by the Highest-Stakes Buyers
Federal agencies and Fortune 500 operations source through ORM Systems.
US Government & Defense
Enterprise Clients
Hand-picked by our procurement team for standout value. This unit is offered at our sharpest price on current stock, verified against live market rates.
Name:
2 In stock - Ready to Ship
Professionally inspected, bench-tested, and firmware-verified, with configurations wiped. Restored to full working order and backed by our warranty.
3 Year Extended Warranty
Same-day Shipping
30-Day Money Back Guarantee
Shipping:
Payment:
3 Year Extended Warranty
Same-day Shipping
30-Day Money Back Guarantee
Need Additional Discount on Product?
Request a quote below - Get Exclusive Pricing and Support.
Shipping:
Payment:
MX95-HW
Cisco Meraki MX95 Security and SD-WAN Appliance, 3 Gbps Fire...
Federal agencies and Fortune 500 operations source through ORM Systems.
US Government & Defense
Enterprise Clients
Regional teams and 25+ distribution partners keep stock near you and accountability in your time zone.
Pay by PayPal or Revolut with full chargeback rights. Order on PO terms, Net-30 for government.
Every registration we claim is public record — check our federal contractor status yourself before you spend a dollar.

Ten years serving buyers who audit their vendors. From federal agencies to 20,000+ enterprise clients worldwide.
MX95-HW is the Cisco Meraki MX95 cloud-managed security and SD-WAN appliance for medium to large branch deployments that need rack-mounted wired edge security with higher-speed uplinks. The platform runs Cisco Meraki MX firmware and is administered through the Meraki Dashboard for policy, firmware, monitoring, troubleshooting, and remote packet capture. Hardware includes four dedicated WAN uplinks, with two 10G SFP+ ports and two 2.5G RJ-45 ports, plus four 1G RJ-45 LAN ports and two 10G SFP+ LAN ports for distribution or aggregation connections. One 2.5G WAN port provides PoE Plus for supported upstream equipment. This bare hardware SKU does not include a bundled MX subscription, so Essential or Advantage licensing is purchased separately for entitlement, cloud management, and security services. Cisco maps the appliance to the MX Large licensing class, which helps quote teams align LIC-MX-L subscription terms, security tier, and renewal planning with hardware during branch refreshes. MX105-HW is the closest larger sibling, while MX85-HW sits below it for smaller edge sizing.
3 Gbps of firewall throughput supports branch internet-edge routing, NAT, VLAN segmentation, and policy enforcement across high-speed WAN handoffs. 2 Gbps of NGFW detection throughput and 1.5 Gbps of prevention throughput size Advanced Security inspection for documented Cisco Meraki MX 19.1x test conditions, with actual results dependent on traffic profile, firmware, and enabled services. 2.5 Gbps of VPN throughput handles Auto VPN, third-party IPsec peering, and L2TP/IPsec client VPN traffic for distributed sites. 200,000 maximum concurrent sessions provide flow capacity for up to 500 recommended devices, while 500 maximum site-to-site VPN tunnels and 250 recommended tunnels support multi-site SD-WAN designs. MX95-HW also supports client VPN and Cisco Secure Client AnyConnect sessions for remote access, static routing, DHCP, VLAN services, traffic shaping, content filtering, AMP malware protection, IDS/IPS, geo firewall policy, Active Directory integration, Syslog, and NetFlow visibility.
MX95-HW operates at the branch perimeter, segmentation gateway, or Auto VPN hub where WAN links, site-to-site tunnels, remote user access, and cloud-managed security policy meet. Rack mounting, internal AC power, one PoE Plus WAN port, active-passive warm spare pairing, and compatible 1G or 10G Meraki SFP modules support standardized edge designs across refresh projects. The appliance is useful when procurement needs hardware-only ordering while subscription terms, security tier, and license co-termination are handled separately. ORM Systems offers this firewall in new and certified refurbished condition, with boot checks, interface testing, factory reset, cosmetic grading, accessory confirmation, and license-state verification before dispatch. Request a quote for single-appliance replacement, matched HA pairs, or volume branch refresh projects across mixed new and refurbished Meraki MX fleets.
MX95-HW price is is available on request. Get immediate quote.
Request bulk order quote for MX95-HW for additional pricing. Browse the full Cisco Meraki Mx Security Appliances series or explore all Cisco products.
MX95-HW sits at the branch internet edge where carrier handoffs, VLAN boundaries, and user segments meet. The appliance routes traffic through four dedicated WAN uplinks, applies L3 and L7 firewall policy, and separates internal networks before traffic exits through Auto VPN or direct internet paths. The 3 Gbps firewall rating and 200,000 maximum concurrent sessions fit a busy 500-device site. Dashboard policy control, Syslog, NetFlow, and remote packet capture give operations teams a consistent way to maintain edge segmentation and service visibility.
Network architects deploy MX95-HW as a regional Auto VPN hub for branch traffic that needs cloud-managed path selection and encrypted site connectivity. The platform supports 2.5 Gbps VPN throughput, 500 maximum site-to-site VPN tunnels, and 250 recommended tunnels for planned production sizing. Dual active WAN support and mixed SFP+ plus 2.5G RJ-45 uplinks connect the appliance to diverse provider circuits. The result is a controlled SD-WAN aggregation point with repeatable tunnel policy, monitored failover behavior, and clear dashboard operations.
Infrastructure teams use the Cisco Meraki MX95 as a rack-mounted replacement for older branch firewalls that lack 10G SFP+ uplinks or centralized Meraki Dashboard operations. The appliance preserves wired edge security while adding 10G LAN connectivity, one PoE Plus WAN port, cloud-managed policy, and active-passive warm spare design with a matching MX95 unit. Hardware-only ordering keeps the appliance separate from LIC-MX-L subscription planning. MX95-HW also keeps the rollout tied to a precise procurement identifier. The refresh produces a standardized firewall platform for branch rollout, HA sparing, and lifecycle replacement.
Mon–Fri: [09:00-16:00]
Avg. response under 30 mins
| Product Type | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall / Wireless Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / SMB Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall | Next-Generation Firewall / UTM Firewall / Enterprise Firewall / Branch Firewall / VPN Firewall / SD-WAN Firewall |
| Architecture | Fixed | Fixed | Fixed | Fixed | Fixed |
| Deployment Type | Branch Office | Branch Office | Branch Office | Branch Office | Branch Office |
| Use Case | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection | Perimeter Security / Secure Access / Network Segmentation / Threat Protection |
| Firewall Layer Supported | Layer 3 / Layer 7 | Layer 3 / Layer 7 | Layer 3 / Layer 7 | Layer 3 / Layer 7 | Layer 3 / Layer 7 |
| Power Source | AC Power Supply | DC Power Supply | DC Power Supply | DC Power Supply | DC Power Supply |
| Redundant Power Supply Supported | Redundant PSU Not Supported | Redundant PSU Not Supported | Redundant PSU Not Supported | Redundant PSU Not Supported | Redundant PSU Not Supported |
| Firewall Throughput | 3 Gbps RFC2544 1518-byte; 3 Gbps EMIX | 700 Mbps RFC2544 1518-byte; 700 Mbps EMIX | 1 Gbps RFC2544 1518-byte; 1 Gbps EMIX | 700 Mbps RFC2544 1518-byte; 700 Mbps EMIX | 700 Mbps RFC2544 1518-byte; 700 Mbps EMIX |
| Threat Protection Throughput | 2 Gbps NGFW detection; 1.5 Gbps prevention | 400 Mbps detection; 300 Mbps prevention | 1 Gbps detection; 800 Mbps Advanced Security; 500 Mbps prevention | 400 Mbps detection; 300 Mbps prevention | 400 Mbps detection; 300 Mbps prevention |
| VPN Throughput | 2.5 Gbps RFC2544 1400-byte; 2.5 Gbps EMIX | 400 Mbps RFC2544 1400-byte; 300 Mbps EMIX | 1 Gbps RFC2544 1400-byte; 1 Gbps EMIX | 400 Mbps RFC2544 1400-byte; 300 Mbps EMIX | 400 Mbps RFC2544 1400-byte; 300 Mbps EMIX |
| Concurrent Sessions | 200,000 | 25,000 | 50,000 | 25,000 | 25,000 |
| Supported VPN Types | IPsec / Auto VPN | IPsec / Auto VPN | IPsec / Auto VPN | IPsec / Auto VPN | IPsec / Auto VPN |
| Routing Protocols Supported | Static Routing | Static Routing | Static Routing | Static Routing | Static Routing |
| Security Services | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection | IPS / Antivirus / Web Filtering / Application Control / SSL Inspection |
| High Availability | Active-Passive | Active-Passive | Active-Passive | Active-Passive | Active-Passive |
| Interfaces | RJ-45 / SFP+ | RJ-45 | RJ-45 / SFP | RJ-45 | RJ-45 |
| WAN Ports | 2 x 10G SFP+; 2 x 2.5G RJ-45 | 2 x 1G RJ-45 | 1 x 1G SFP; 2 x 1G RJ-45 | 1 x 1G RJ-45; 1 x 1G RJ-45 convertible LAN/WAN | 2 x 1G RJ-45 |
| LAN Ports | 4 x 1G RJ-45; 2 x 10G SFP+ | 8 x 1G RJ-45; 2 x 1G RJ-45 PoE Plus | 10 x 1G RJ-45; 2 PoE Plus | 3 x 1G RJ-45; 1 x 1G RJ-45 convertible LAN/WAN | 8 x 1G RJ-45; 2 x 1G RJ-45 PoE Plus |
| Management Options | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard | Web GUI / Cloud Dashboard |
| Logging & Monitoring | Syslog / NetFlow | Syslog / NetFlow | Syslog / NetFlow | Syslog / NetFlow | Syslog / NetFlow |
| Users Supported | 500 | 50 | 200 | 50 | 50 |
| Form Factor | Rack-Mount 1U | Desktop | Desktop | Desktop | Desktop |
| Device Type | Firewall | Firewall | Firewall | Firewall | Firewall |
| Product Name | Cisco Meraki MX95 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX68W Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX75 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX67 Security and SD-WAN Enterprise Security Appliance | Cisco Meraki MX68 Security and SD-WAN Enterprise Security Appliance |
| Height | 1.7 in | 1.1 in | 1.1 in | 1.1 in | 1.1 in |
| Width | 19.0 in | 11.2 in | 11.1 in | 9.4 in | 11.2 in |
| Depth | 11.2 in | 6.8 in | 5.8 in | 5.1 in | 5.8 in |
| Weight | 3.2 kg | 1.2 kg | 0.9 kg | 0.8 kg | 1.1 kg |
Every unit is authentic, sourced through trusted and authorised channels, and serial-verified on request. Genuine networking and IT hardware, guaranteed, or your money back.
New products are backed by up to 3 years of extended warranty, and certified refurbished units by up to 3 months, for dependable protection on every order. Coverage is clear, honoured in full, and confirmed on each product page.
If a unit ever falls short, our streamlined RMA process gets a replacement to you fast, with advance replacement available to keep your network running. No jargon, no runaround.
Every device is inspected, bench-tested, and firmware-verified, with configurations wiped before dispatch. Additional testing can be arranged to confirm full working condition on request.
Our specialists assist with compatibility, configuration, licensing, and installation, before and after you buy. Real hardware expertise, whenever you need it.
dispatched quickly and shipped worldwide from regional hubs, fully tracked and insured.
Stable branch firewall performance with clear dashboard policy control after the MX95-HW went into production.
The 10G SFP+ uplinks helped standardize our Meraki edge refresh across larger branch sites.
Good fit for Auto VPN aggregation, with straightforward licensing checks before deployment.
Interface testing and factory reset details were confirmed before the refurbished unit shipped.
Policy management through the Meraki Dashboard kept the branch cutover organized and predictable.
Worked well after confirming the MX Large subscription and compatible SFP+ modules.
Solid appliance choice for a rack-mounted Meraki branch edge with VPN requirements.
MX95-HW is the Cisco Meraki MX95 hardware security and SD-WAN appliance for medium to large branch networks. It provides cloud-managed firewalling, WAN failover, Auto VPN, content filtering, AMP malware protection, IDS/IPS, Syslog, NetFlow, and remote packet capture. The SKU is hardware only, so Meraki MX licensing is purchased separately for cloud management and service entitlement.
The MX95-HW model number identifies the Cisco Meraki MX95 appliance hardware, not a subscription bundle or renewal. Cisco maps MX95-HW to the MX Large licensing class, which uses LIC-MX-L subscription licensing. That distinction matters for ordering because the appliance and the Meraki subscription are separate line items unless a specific bundle SKU states otherwise.
MX95-HW is a hardware security appliance in the Cisco Meraki MX Security and SD-WAN family. It performs routing and SD-WAN functions, but the product role is firewall, unified threat management, VPN, and branch edge security. That makes it appropriate for firewall SKU processing rather than router, switch, wireless, power supply, or accessory content.
MX95-HW sits above MX85-HW and below MX105-HW in the Meraki MX appliance range. Cisco sizing data places MX95 at 3 Gbps firewall throughput, 200,000 maximum concurrent sessions, and 500 recommended devices. MX105 increases the firewall figure to 5 Gbps and the recommended device count to 750 for larger branch requirements.
MX95-HW supports 3 Gbps firewall throughput under Cisco Meraki MX sizing data for both RFC2544 1518-byte and EMIX testing. Earlier product-page highlights and installation material may show lower planning figures, so the current sizing guide is the stronger reference for performance modeling. Final selection still depends on traffic profile, enabled features, and proof-of-concept validation.
Cisco Meraki sizing data lists MX95 at 2 Gbps NGFW detection throughput and 1.5 Gbps NGFW prevention throughput under Advanced Security EMIX testing. Those figures apply to inspected traffic scenarios, not plain stateful firewall forwarding. Security services such as IDS/IPS, AMP, content filtering, and application enforcement require the appropriate active Meraki entitlement.
MX95-HW supports 200,000 maximum concurrent sessions in Cisco Meraki MX sizing data. Meraki defines a flow as a transmission on an open socket within the last five minutes, and the published number is a maximum capacity rather than a recommended operating target. Network planners should size below that ceiling for production stability.
MX95-HW provides 2.5 Gbps VPN throughput in current Cisco Meraki sizing data for RFC2544 1400-byte and EMIX measurements. The same sizing guide lists 500 maximum site-to-site VPN tunnels, 250 recommended site-to-site VPN tunnels, 250 client VPN tunnels, and 500 maximum Cisco Secure Client AnyConnect sessions for the MX95 model.
MX95-HW includes four dedicated WAN uplinks, made up of two 10G SFP+ ports and two 2.5G RJ-45 ports, with one 2.5G WAN port supporting PoE Plus. The LAN side provides four 1G RJ-45 ports and two 10G SFP+ ports. It also includes one RJ-45 management port and one USB 3.0 port.
MX95-HW is managed through the Cisco Meraki Dashboard, with local status-page access available through the dedicated RJ-45 management port. Operational features include remote packet capture, historical client usage statistics, Syslog integration, and NetFlow support. Dashboard management also handles firmware operations and policy configuration when the appliance is properly licensed.
MX95-HW suits a medium to large branch internet edge where the same appliance handles WAN handoff, stateful firewall policy, Auto VPN, client VPN, NAT, VLAN segmentation, and cloud-managed monitoring. The four WAN uplinks and mixed 2.5G RJ-45 plus 10G SFP+ interfaces support diverse provider handoffs without moving to a larger chassis.
MX95-HW suits Cisco Meraki SD-WAN deployments that use Auto VPN, WAN link balancing, automatic WAN failover, and dashboard policy control across distributed sites. The appliance supports 500 maximum site-to-site VPN tunnels and 250 recommended tunnels, which fits many hub-and-spoke or regional branch designs where a cloud-managed operational model is required.
MX95-HW supports VPN concentrator and routed gateway deployment models within the Meraki MX architecture. Cisco Meraki high-availability guidance describes one-armed concentrator and routed warm spare modes for MX appliances. The model's 2.5 Gbps VPN throughput and 500 maximum site-to-site VPN tunnel count make it suitable for regional Auto VPN aggregation when sized correctly.
MX95-HW suits segmented branch or campus-edge networks that require VLAN support, static routing, L3 and L7 firewall policy, content filtering, and application-aware traffic controls. The appliance sits at the security boundary between internal access networks, WAN services, and Auto VPN overlays. Its 200,000 maximum concurrent sessions provide flow capacity for documented 500-device planning.
MX95-HW maps to the MX Large subscription class in Cisco Meraki subscription licensing. The licensing table associates MX95-HW with LIC-MX-L, alongside MX90-HW, MX100-HW, MX105-HW, MX400-HW, VMX100, and vMX-L. The appliance itself remains a hardware SKU, so the subscription term and feature tier must be ordered separately.
MX95-HW does not include a subscription by default when ordered as the bare hardware SKU. Meraki MX cloud management, support entitlement, and security feature access require a matching active subscription. Buyers should specify the needed MX Large license tier and term during quoting, especially when Advanced Security services are part of the intended deployment.
Cisco Meraki lists MX95 and MX105 support for pluggable optics used in high-speed backbone or aggregation connections. Compatible Meraki examples include MA-SFP-1GB-SX, MA-SFP-1GB-LX10, MA-SFP-1GB-TX, MA-SFP-10GB-SR, MA-SFP-10GB-LR, MA-SFP-10GB-LRM, MA-SFP-10GB-ER2, and MA-SFP-10GB-ZR. Exact optical selection depends on fiber type, reach, and port design.
MX95-HW supports Meraki warm spare high availability when paired with another MX95 appliance in the same dashboard network. Cisco Meraki describes MX warm spare as an active-passive design using VRRP heartbeats. Only one MX license is required for the HA pair, and the spare must be the same MX model as the primary.
MX95-HW is the higher-performance option compared with MX85-HW. Cisco Meraki sizing data lists MX95 at 3 Gbps firewall throughput and 200,000 maximum concurrent sessions, while MX85 is listed at 1 Gbps firewall throughput and 125,000 maximum concurrent sessions. MX95 also moves the uplink design to 10G SFP+ WAN and LAN options.
MX105-HW is the next larger sibling above MX95-HW. Cisco Meraki sizing data lists MX105 at 5 Gbps firewall throughput, 250,000 maximum concurrent sessions, and 750 recommended devices. MX95-HW remains the better fit when 3 Gbps firewall throughput, 200,000 maximum concurrent sessions, and 500 recommended devices match the site design.
MX95-HW targets larger branch requirements than MX75-HW. Cisco Meraki sizing data lists MX75 at 1 Gbps firewall throughput, 50,000 maximum concurrent sessions, and 200 recommended devices. MX95-HW raises those planning figures to 3 Gbps firewall throughput, 200,000 maximum concurrent sessions, and 500 recommended devices for busier edge deployments.
MX250-HW sits above MX95-HW for larger sites or hub roles. Cisco Meraki sizing data lists MX250 at 7.5 Gbps RFC2544 firewall throughput, 500,000 maximum concurrent sessions, and 2,000 recommended devices. MX95-HW keeps the deployment in a lower MX Large hardware class with 3 Gbps firewall throughput and 500 recommended devices.
MX95-HW pricing depends on condition, requested quantity, sourcing channel, license requirements, and current Cisco Meraki hardware availability. ORM Systems quotes the appliance after confirming whether the buyer needs hardware only, a matching LIC-MX-L subscription, compatible SFP modules, power cords, or an HA pair. Submit the bill of materials for accurate commercial terms.
Yes, ORM Systems sources MX95-HW in new condition when channel availability supports the request. New units suit refresh projects, standardized branch rollouts, and procurement policies that require unused hardware. The quote should confirm appliance condition, included accessories, licensing requirements, lead time, destination, and any compatible optics needed for the deployment.
Refurbished MX95-HW is often a practical option for replacement, HA sparing, and lifecycle extension projects. ORM Systems checks boot status, physical condition, interface operation, factory-reset state, and license-state expectations before dispatch. Refurbished Meraki hardware still requires an appropriate active subscription for dashboard management and entitled security services.
ORM Systems supports volume procurement for MX95-HW across branch refreshes, spare pools, and matched high-availability rollouts. Bulk quoting accounts for condition mix, shipment destinations, requested delivery windows, power cord requirements, license add-ons, and compatible SFP modules. Providing the full project quantity helps align sourcing with deployment phases and warranty expectations.
Lead time for MX95-HW depends on market supply, requested condition, order quantity, accessory requirements, and destination. ORM Systems confirms availability and dispatch timing during the quote process rather than assuming a fixed ship date. Urgent replacement requests should include the target arrival date, site location, appliance condition preference, and required LIC-MX-L subscription details.
Warranty coverage for MX95-HW depends on the quoted condition, sourcing route, and commercial package. ORM Systems states warranty terms on the quote and supports tested new or refurbished supply for eligible projects. Cisco Meraki documentation also describes MX95 and MX105 hardware warranty coverage separately from accessories, which have their own coverage period.
Refurbished MX95-HW should pass full boot checks, port inspection, interface testing, physical chassis review, factory reset, and license-state verification before dispatch. Those checks help confirm that the appliance is ready for dashboard claiming and deployment planning. Buyers should still confirm serial status, licensing requirements, and accessory needs before purchase approval.
Cisco Meraki installation documentation states that MX95 and MX105 devices have been tested to comply with FCC Part 15 Class A digital device limits. The hardware also requires appropriate site power protection and use of provided power cables for regulatory compliance. Additional project-specific compliance requirements should be checked before ordering.
Before installing MX95-HW, the team should create or confirm the Meraki Dashboard network, assign the appropriate MX Large subscription, check firmware requirements, prepare upstream firewall rules, and plan WAN addressing. Cabling should match the 10G SFP+, 2.5G RJ-45, 1G RJ-45, management, and power connections used at the site.
MX95-HW deployments may require regional power cords, compatible Meraki SFP or SFP+ optics, passive twinax cables, and the optional MA-RCKMNT-KIT-1 rack mount screws kit. Cisco Meraki documentation notes the rack mount screws kit is optional and not included with MX95 and MX105. The exact accessory list should follow the site cabling plan.
MX95-HW setup should include the intended MX Large subscription tier, term, dashboard organization, network assignment, and whether Advanced Security features are required. The appliance is hardware only, so subscription entitlement controls cloud management and service access. Providing those details before shipment reduces delays during claim, staging, and production cutover.
MX95-HW can be requested from ORM Systems for UK procurement, replacement, branch refresh, or high-availability projects. The quote should specify hardware condition, quantity, delivery destination, required LIC-MX-L subscription, power cord type, optics, and any matched-pair requirements. ORM Systems returns pricing and availability after checking the current sourcing options.
ORM Systems supports international sourcing requests for MX95-HW, with shipping options confirmed during quotation based on destination, quantity, condition, customs requirements, and accessory selection. Buyers should provide delivery country, target date, import details, and any licensing or optics requirements. The team then confirms realistic availability, transit options, and commercial terms.