Technology · Cisco Meraki

Cisco Meraki: Cloud-Managed Networking for Multi-Site Northern Ontario Businesses

A deep look at the Cisco Meraki platform: MX firewalls, MS switches, MR wireless, MV cameras, MT sensors, and Systems Manager. What it is, how it's licensed, where it excels, and how Nickel City Tech Solutions deploys and manages Meraki for multi-site businesses across Greater Sudbury and Northern Ontario.

Serving Greater Sudbury, Northern Ontario, and surrounding communities. Remote support available throughout Ontario.

Cisco Meraki is a full-stack, cloud-managed networking platform. Every device (firewall, switch, access point, security camera, IoT sensor) reports to and takes its configuration from a single web dashboard hosted by Cisco. Add a device to the dashboard, ship it to a remote site, and it downloads its configuration the moment it comes online. For a business running multiple locations, that operational model is transformative.

Meraki is one of two perimeter and network platforms we standardize on, alongside Sophos. It's our default recommendation for multi-site environments across Northern Ontario: healthcare groups with clinics in Sudbury, Espanola, and Manitoulin Island, retail operations across Greater Sudbury, manufacturers with offices and yards in different communities, and non-profits running multiple program locations.

This page is the technology view of Meraki: what each product line does, how they fit together, how licensing works, and how we deploy the platform as a managed service. If you're looking for our general Network & Wi-Fi Support service, that's a broader conversation covering all network vendors.

The Meraki product family

Meraki is not a single product. It's a family of tightly-integrated devices that share one management plane. Understanding what each line does is the first step to designing a deployment.

MX security appliances are the firewalls: SD-WAN, site-to-site VPN, stateful firewalling, and, with Advanced Security licensing, IDS/IPS, content filtering, anti-malware, and Cisco Talos threat intelligence. MS switches are enterprise-grade access and aggregation switches with cloud management. MR wireless access points cover indoor and outdoor Wi-Fi, from small offices (MR36) through high-density venues (MR46, MR56). MV cameras are cloud-managed IP video with on-device video storage and analytics, so no NVR is required. MT sensors monitor temperature, humidity, water leaks, door open/close, and power, and they're useful for server rooms, medical fridges, and unmanned sites.

Systems Manager is Meraki's endpoint management platform, comparable to Intune and purpose-built to integrate with the Meraki network. It handles iOS, Android, Windows, macOS, and Chrome OS with policy-driven enrolment and application deployment.

  • MX: SD-WAN firewalls with Auto VPN mesh and optional Advanced Security
  • MS: cloud-managed access and aggregation switches with PoE options
  • MR: indoor and outdoor Wi-Fi 6 / Wi-Fi 6E access points
  • MV: cloud-managed security cameras with on-device video storage
  • MT: environmental sensors for temperature, humidity, water, door, and power
  • Systems Manager: mobile and endpoint management
  • Meraki Insight: WAN and application performance monitoring

Why businesses choose Meraki: the operational case

The Meraki value proposition is operational. For a single-site business, a well-configured Sophos or Fortinet firewall is often as capable, and sometimes more so on deep security features. The moment you have two sites, though, the equation changes. Every additional site multiplies the operational overhead of a traditional network. With Meraki, adding a site is: order the hardware, claim the serials into the dashboard, apply a template, and ship the boxes.

For a Northern Ontario multi-site business, such as a health group with clinics across Greater Sudbury, a construction firm with a Sudbury office and satellite yards, or a retail chain across North Bay and Muskoka, Meraki turns a network refresh from a multi-year project into a series of afternoons. Every site inherits the same firewall rules, the same VLAN structure, the same Wi-Fi SSIDs. When a policy needs to change, it changes everywhere at once.

What consistency actually buys you

For the owner or executive: consistent operations across every location, one bill for networking hardware and licences (predictable), and one support relationship. Every site has the same setup, so a staff member visiting another location gets the same Wi-Fi, the same printer access, the same security posture. When you open a new location, opening the network takes days instead of weeks.

For the IT lead: one dashboard for every device across every site, real-time alerts on device health and WAN uptime, template-based configuration that keeps sites in sync automatically, and clean role-based access for delegating operational tasks to on-site staff.

For staff: reliable Wi-Fi (Meraki's radio and RF-management engineering is genuinely excellent), fast internet even during outages (SD-WAN failover happens in seconds), and clean guest access without IT involvement.

Licensing: what to know before you buy

Meraki licensing is per-device and time-based. Every MX, MS, MR, MV, and MT needs an active licence, and licences come in 1, 3, 5, 7, or 10-year terms. Longer terms carry a per-year discount. Enterprise licensing covers the base features; Advanced Security licensing (available on MX only) adds IDS/IPS, content filtering, anti-malware, geo-based firewalling, and Cisco Talos threat feeds.

The mechanics matter. Licences are pooled at the organization level (co-termed), so when you add a new device mid-term, its licence is co-termed to your existing expiry. Renewals cover the whole fleet at once. If a licence lapses, the device operates in a 30-day grace period and then goes offline until renewed. We manage renewal calendars for every client so this never happens by accident.

For most Northern Ontario businesses we recommend Advanced Security on every MX (not just the head office), consistent switch and AP tiers across sites, and 5-year licences for the balance between cash flow and per-year cost.

Deployment mistakes worth avoiding

The most common mistake is under-sizing the MX. Meraki datasheets list a maximum throughput number and a lower number 'with advanced security enabled.' For a business paying for Advanced Security, the second number is the real number, and it's often half the marketing number. We size to the second number, with headroom.

Second: mixed switch tiers across sites (MS120 at one site, MS210 at another, MS250 at a third) with no clear reason. This makes template configuration harder and stacking and uplink strategies inconsistent. Standardize where possible.

Third: MR access points placed for convenience rather than for RF. A Meraki wireless survey is quick and produces a placement plan that avoids the coverage holes and roaming problems that show up six months in.

Fourth: Auto VPN turned on without a real routing plan. Auto VPN is powerful, but a poorly-planned hub-and-spoke or full-mesh topology can send traffic on inefficient paths. We design the topology explicitly, not by default.

Security considerations

Meraki dashboard access is protected with MFA, always enforced on our tenants with no exceptions. Role-based access is used to give internal IT read-only, monitoring-only, or scoped read-write access rather than blanket administrator rights.

Firmware updates are scheduled maintenance windows rather than device-by-device manual work. Meraki firmware channels (Stable, Beta) let us choose the right cadence per network. Configuration is exported and version-controlled where practical, so an accidental change can be reverted quickly.

For MX firewalls, Advanced Security enables IDS/IPS with Cisco Talos signatures and content filtering with real-time reputation. AMP (Advanced Malware Protection) inspects file downloads. Geo-based firewalling blocks inbound connections from high-risk countries as a first line of defence. For any site with staff Wi-Fi and guest Wi-Fi on the same box, we always use VLAN separation, never a shared broadcast domain.

Best practices we apply to every deployment

Template-based configuration for multi-site deployments means we change a policy once and deploy it everywhere. Every site gets a standardized VLAN plan (management, staff, VoIP, guest, IoT, cameras), consistent SSID naming, and 802.1X or PSK-per-user for staff Wi-Fi. Guest Wi-Fi always lives on its own VLAN with a splash page, never with access to internal networks.

SD-WAN failover to a secondary WAN, whether LTE or a second ISP, goes on any site where connectivity uptime matters. MV cameras are placed against a real coverage plan with retention sized to actual investigative windows, and MT sensors go on any server room, medical fridge, or unmanned site where an outage would be expensive.

How Meraki integrates with the rest of your stack

Meraki integrates cleanly with Microsoft 365 for identity (802.1X and Meraki Auth against Entra ID), with Systems Manager for device compliance (or with Intune for organizations already invested in that ecosystem), and with SIEMs via syslog. MV cameras integrate with third-party VMS platforms when required.

Our most common Northern Ontario Meraki deployment pattern is MX firewall (Advanced Security) + MS switches + MR access points + Systems Manager or Intune + Microsoft 365 Business Premium + a third-party M365 backup platform. For clients with on-prem servers, we add Hyper-V hosts on the LAN side of the MX. For any client with meaningful physical-security needs, MV cameras and MT sensors round out the deployment.

Industry-specific use cases

Healthcare groups with multiple clinics use Meraki to enforce consistent PHIPA-aligned segmentation across every site: clinical VLAN, admin VLAN, medical-device VLAN, guest VLAN, all with identical rules everywhere.

Retail chains use Meraki for consistent Wi-Fi and secure PoS network segmentation across every store, with SD-WAN failover so a downed ISP doesn't stop card payments.

Construction firms use Meraki for site-office trailers: an MX with an LTE modem gives a job-site trailer real corporate connectivity, joined into the Auto VPN mesh, in an afternoon.

Manufacturers use Meraki for the office layer alongside more specialized OT/ICS networking on the production floor, keeping the two cleanly segmented.

Non-profits and multi-site professional services use Meraki because it lets a lean IT function operate multiple locations without adding headcount.

What's included

MX Sizing & Deployment

Right-sized MX security appliances with Advanced Security, deployed with documented VLANs and rules.

MS Switch Design

Access and aggregation switch design, stacking, PoE budgeting, and uplink strategy.

MR Wireless Design

Wi-Fi 6 / 6E coverage design, SSID architecture, 802.1X or PSK-per-user, and RF-tuned placement.

Cloud Dashboard Management

Ongoing dashboard administration, template management, and role-based access for internal IT.

Auto VPN Mesh

Multi-site Auto VPN topology design, hub-and-spoke or full mesh, with SD-WAN traffic steering.

Advanced Security

IDS/IPS, content filtering, AMP anti-malware, and Cisco Talos threat intelligence.

SD-WAN & Failover

Dual-WAN and LTE failover for any site where uptime matters, with per-application traffic steering.

MV Camera Deployment

Cloud-managed IP cameras with on-device storage, retention planning, and coverage design.

MT Environmental Sensors

Temperature, humidity, water, door, and power monitoring for server rooms and unmanned sites.

Systems Manager MDM

iOS, Android, Windows, and macOS enrolment with compliance and app-deployment policies.

Licensing & Renewal Management

Co-termed licence tracking, renewal calendars, and never-let-a-device-expire management.

Managed Firmware & Monitoring

Scheduled firmware windows, proactive alerting, and monthly reports on uptime and security events.

Who it's for

  • Multi-site businesses across Greater Sudbury and Northern Ontario
  • Healthcare groups with clinics across multiple communities
  • Retail and hospitality chains needing consistent operations across locations
  • Construction and industrial businesses with site-office trailers and remote yards
  • Non-profits and professional services running multiple program or office locations
  • Businesses replacing a mixed vendor network with a unified cloud-managed stack
  • Organizations where a lean IT team needs to operate multiple sites without adding headcount

Common problems we solve

  • Inconsistent network configuration and security posture across multiple locations
  • Painful, weeks-long site rollouts for every new office or clinic
  • Firmware updates and rule changes that have to be applied device by device across every site
  • No visibility into WAN uptime or application performance across the fleet
  • Guest Wi-Fi that shares broadcast domain or DHCP with internal networks
  • Ad-hoc IP camera deployments with tape drives, NVRs, and no central management
  • Environmental incidents (temperature, water) at unmanned sites that go unnoticed until damage is done
  • Meraki licences lapsing unnoticed and taking devices offline

Why Nickel City Tech Solutions

  • Cisco Meraki partner with real deployment experience across Northern Ontario
  • Multi-site deployment methodology using templates, standard VLAN plans, and consistent SSID architecture
  • Vendor-neutral advice: we'll recommend Sophos when it's the better fit for your environment
  • Managed licence renewals so no device ever lapses
  • Local Ontario team for on-site cutovers, hardware swaps, and after-hours emergencies
  • Integrated with our cybersecurity, Microsoft 365, and backup practices: one team, one plan
  • Predictable pricing and transparent Meraki hardware and licence pass-through

Frequently asked questions

What is Cisco Meraki and how is it different from traditional networking?

Meraki is Cisco's cloud-managed networking line: firewalls (MX), switches (MS), wireless access points (MR), security cameras (MV), IoT sensors (MT), and endpoint management (Systems Manager), all managed from a single web dashboard. Traditional Cisco (Catalyst switches, ASA firewalls) is managed by CLI or on-premises tools; Meraki is managed entirely from the cloud, which makes multi-site deployments dramatically simpler to operate.

Are you a Meraki partner?

Yes. We deploy and manage the full Meraki stack for businesses across Northern Ontario, most commonly for multi-site operations, retail chains, distributed offices, and any environment where consistent operations across locations matters more than deep single-site security customization.

How does Meraki licensing work?

Every Meraki device requires an active licence: no licence, no cloud dashboard, no device operation. Licences come in 1, 3, 5, 7, and 10-year terms, and are per-device (per MX firewall, per MS switch, per MR access point, and so on). MX firewalls have two tiers: Enterprise (base features) and Advanced Security (adds IDS/IPS, content filtering, anti-malware, geo-based firewalling, and Cisco Talos threat intelligence). For a business handling client data we recommend Advanced Security. Licensing must be maintained continuously, because a lapsed licence stops the device from operating.

Which Meraki MX model is right for our office?

MX sizing depends on internet bandwidth, number of users, VPN topology, and whether you're using advanced security features. For a typical small office up to 25 users on a 500 Mbps circuit, an MX67 or MX75 is usually right. For 50–100 users or gigabit circuits, MX85 or MX95. For multi-site headquarters or larger throughput, MX105 and above. We'll size based on real workload, not just user count.

How does Meraki compare to Sophos Firewall?

Both are excellent, and we deploy both. Meraki wins on cloud-managed simplicity, on multi-site consistency, and on unified stack (switching, Wi-Fi, cameras, and IoT all in one dashboard). Sophos wins on deep security features (better IPS, TLS inspection, Synchronized Security with Sophos endpoint) and on total cost of ownership for security-first single-site deployments. For a multi-clinic healthcare group or a distributed retail chain, Meraki is usually the pick. For a single-site law firm or manufacturing plant where deep inspection matters, Sophos usually wins. We'll recommend based on your workload, not our preference.

What is Meraki Auto VPN and why does it matter for multi-site businesses?

Auto VPN is Meraki's site-to-site VPN mesh: every MX at every site automatically establishes IPsec tunnels to every other MX in your organization, without manual configuration of tunnels, keys, or routes. Add a new site and it joins the mesh automatically. For a Northern Ontario business with head office in Sudbury and satellite sites in Espanola, Elliot Lake, and Manitoulin Island, Auto VPN turns what used to be a weeks-long VPN mesh project into an afternoon.

Can Meraki handle a full-office deployment: firewall, switches, Wi-Fi, cameras?

Yes, that's exactly what it's designed for. A typical Meraki deployment we run is one MX firewall, one or more MS switches (usually MS120 or MS210 series for access, MS250 for aggregation), MR access points sized for coverage, and optionally MV cameras and MT environmental sensors. Everything is managed from one dashboard, everything is configured with consistent templates, and everything is monitored proactively from Meraki's cloud.

What happens if a Meraki device fails?

Failed devices are replaced under Meraki's warranty. Because configuration lives in the cloud, a replacement device inherits the exact same config the moment you claim its serial into the dashboard, with no manual reconfiguration and no waiting for a specialist. For businesses where downtime is expensive, we deploy MX firewalls in warm-spare pairs (two firewalls, automatic failover) or MS switches in stacks with redundant uplinks.

How does Meraki handle guest Wi-Fi and BYOD?

Meraki's MR wireless includes a full-featured guest portal (splash pages, terms-of-use acceptance, sponsored access, PSK per user), integration with Facebook/Google login where appropriate, and Layer-7 policy so guest devices can be limited to internet only. For BYOD, Systems Manager can enrol iOS, Android, Windows, and macOS devices with compliance policies before granting network access.

Do you handle Meraki dashboard co-management with an internal IT team?

Yes. We regularly share Meraki dashboard access with in-house IT staff, giving them read-write or read-only permissions at the organization or network level. Our team handles the deep configuration, security tuning, firmware updates, and after-hours alerts; internal IT handles day-to-day operational tasks. Meraki's role-based access makes clean handoff simple.

Case studies

Related real-world projects

Let's talk about your environment

Free 30-minute consultation. Serving Greater Sudbury, Northern Ontario, and surrounding communities. Remote support available throughout Ontario.

Internal links

Related services, locations, and resources

Related services

Helpful resources

Resources

Latest IT Insights

Cybersecurity guides, Microsoft 365 tips, and managed IT advice from our Ontario team.

Browse all resources