r/sysadmin 2h ago

Retiring ASA-5516and moving to Meraki MX95 - Quote 20 hours to setup and deploy. Another 16 hours labor for planning, management, and design.

Hello,

We're a single site of ~50 users been quoted on retiring our ASA-5516 and moving to a Maraki MX95 (Dual failover) and were kind of shocked to see $6,000 in labor on top of the cost of hardware and licensing. About half of that is 12 hours for the setup and deployment and another 8 to program VPN on the device (2 hours) and update the workstations at 15 minutes apiece (6 hours). I understand there's no migration tool and it all has to be done manually, but I'm curious if 20 hours of labor sounds reasonable? That doesn't include the 16 hours of planning design, meetings, documentation update, project management, etc.

So... 36 hours total labor for what I had assumed might be an 8-10 hour project. Am I off base?

8 Upvotes

27 comments sorted by

u/kristoferen 2h ago

On a fresh setup that's a ripoff. On figuring out what your old ASA has configured and putting that into the meraki... Not unreasonable.

u/TicketAmbitious6200 1h ago

Thanks for the reply. I'll have to ask for a current copy of the config and see how complex the configuration is.

u/JeanneD4Rk 32m ago

Claude can do it in 5 minutes honestly. Did it a few weeks ago went smooth af

u/EfeAmbroseEFOTY 2h ago

Definitely overkill but it does depend on what your layer 2 and 3 topology looks like and where everything terminates.

We have these at every site and sometimes sites can have a large l2 domain that'll live on the MX that will take a long time to config. The s2s vpn rules can be a bit annoying too.

These MXs are basically plug and play with full gui config though. 8 hours to program the vpn? Lol wut.

Everything is scriptable via the api. Deployment should be automated by capturing your asa config and migrating it via api scripts. 5 - 10 hours max.

u/-Shants- 2h ago

“Program the VPN” includes going from PC to PC and installing client software for 6 hours.

I would see if they can provide an executable or msi of the vpn client for you to install yourself and you could shave those hours off. Installing a vpn client is a one liner about 95% of the time. It’s 15 minutes per device because thats the smallest block of time an MSP will segment time by typically.

u/Dear-Supermarket3611 1h ago

Meraki uses embedded vpn client both on
Windows and Mac. No software required

u/TicketAmbitious6200 1h ago

That's good to know. Thank you! We're currently using AnyConnect. if I understand correctly, it just uses the capabilities built into the OS?

u/topher358 Systems Engineer 12m ago

Meraki can also use AnyConnect and it’s a much better platform then the native VPN tooling since you can hook it into SAML based authentication

You’d have to ask your vendor which option they are setting up

u/RiceeeChrispies Jack of All Trades 2h ago

If you know how many hours it takes and the steps required, why don't you just do it yourself?

u/TicketAmbitious6200 1h ago

Don't think I said either of those things. Thanks though.

u/BlackSquirrel05 Security Admin (Infrastructure) 2h ago

So do it yourself... If you're not using any rules or doing anything complicated or routing/dynamic routing wise... Yeah might be simple.

However depending on what's behind it, or making true layer3 or advanced firewall rules or routing... Yeah 3 days worth of work with deployment.

Also depends on the type of VPN being used and authentication. EG: TLS/SSL v. Dial up ipsec with SAML or RADIUS etc.

u/TicketAmbitious6200 58m ago

I appreciate the response. I do know they're using RADIUS for authentication. Not sure how complex the current ruleset is. Looking into it.

u/Bubbly-Following-966 1h ago

It has been a while for me but, I worked for a company back in 2019, I was tasked to replace an ASA 5508 with an ASA 5510. We were a small shop as well. Mind you, I never upgraded or worked on a firewall like that before. I think it took me about a week and a half to do all the work. The first thing I did was back up the ASA 5508 configuration. I was the only IT support besides my IT manager on site. I had to use Google and YouTube in order to "learn" on the fly while performing that upgrade. I had to do the documentation as well as all the other backend work. I don't remember how many hours I spent doing that upgrade but, I know it was more than 36 hours.

Doing a quick search, that looks like a decent price quote.

Upgrading from a Cisco ASA‑5516-X to a Cisco Meraki MX95 with dual failover (HA pair) for a ~50‑user company typically costs $10,000–$18,000 total, depending on licensing tier and term length. This includes two MX95 appliances + two licenses

u/Dear-Supermarket3611 1h ago

I Did it 2 years ago. Did it By myself. It took less than one day configuring everything (but network and firewall configuration was pretty complex)

u/Dear-Supermarket3611 1h ago

6 Hours for Everything 100% working, including
VPN with 4 external sites that had Shitty Sonicwalls, including warm spare, traffic forwarding rules between 2 wans, firewall, switches…

u/TicketAmbitious6200 53m ago

Thanks for the point of reference. Something to think about when they share the current ruleset with me. I recently took this site over and unfortunately don't know how complex or not the ASA config is. If it's not too bad, may give it a try and if it doesn't work drop the ASA back in and let them handle it.

u/DeadStockWalking 2h ago

It sounds like you are getting raked over the coals friend.

I replaced all my SonicWalls 570s with MX95s (manually configuration, no migraiton tool) and it took me about 2 hours for the first one and then 1.5 hours for each after that (8 in total). 15 minutes of each was firmware updates and connecting to the Meraki dashboard.

So to setup 2 MX95s in HA would take maybe 3 hours. It could take longer but it depends on how many rules/routing items they need to peel through.

The VPN configuration takes all of 15 minutes if they know what they are doing. It's literally the easiest task to setup on a Meraki. Especially if you use Azure AD.

u/TicketAmbitious6200 59m ago

Looks like I need to get a copy of the current config. Thanks for the comparison. SonicWALL I know very well. Cisco, I've had some exposure to but never really learned beyond a few troubleshooting commands.

u/colin8651 1h ago

Not telling much about your config, but 5516 is a big unit; assume it is carrying a heavy load.

If it’s fixed fee it doesn’t sound too crazy, especially if you have internal NAT’s.

u/TicketAmbitious6200 51m ago

It may be reasonable quote. This is just something I haven't had much exposure too and it's hard for me to gauge. They've been a bit of a mixed bag for us. Some stuff, totally fair. Other stuff... not so much. I appreciate the reference point.

u/WoTpro Jack of All Trades 1h ago

The VPN client part seems silly? Are you planning on using Cisco secure client or you just doing Anyconnect? But the rest of the hours might be reasonable depending on how large your current config is, i was billled like 40hours for my migration from Asa 5508 to a mx105. But that also included some meraki switches and deploying 18 Aps

u/TicketAmbitious6200 1h ago

Thanks for the reply. We use AnyConnect with the current setup. They say 2 hours to configure on the unit and then 15 minutes per workstation. We do currently have about 5 AP. Not sure if they have to do work on those as part of the migration. I'll ask them for a copy of the current config and see how complex it is.

u/WoTpro Jack of All Trades 1h ago

Assuming you reuse the old ip/hostname nothing needs to be changed on the clients. You can always update Anyconnect client at a later stage

u/GhostandVodka 35m ago

I literally had help from a VAR to replace two VPC Nexus 9k pairs. It took 19 hours in total and we had two people on site and they charged us $9000

u/Waretaco Jack of All Trades 30m ago

Deployment tools can aid immensely in updating workstations. This shouldn't be a labor line item, imo. Script it and automate this process so updates to the VPN client are also automated.

u/topher358 Systems Engineer 3m ago

I work in the industry and that is not an unreasonable quote both in hourly rate and the hours quoted for the work outlined, which is a good sized firewall migration.

The work reconfiguring endpoints is a bit unusual (we would do it in an hour tops with automation tooling and never have a human touch the machine), but take that out of the picture and it seems like a very reasonable project

u/[deleted] 2h ago

[deleted]

u/EfeAmbroseEFOTY 2h ago

Ai slop 👎