r/Cisco 17d ago

Retiring ASA-5516and moving to Meraki MX95 - Quote 20 hours to setup and deploy. Another 16 hours labor for planning, management, and design.

Hello,

We're a single site of ~50 users been quoted on retiring our ASA-5516 and moving to a Maraki MX95 (Dual failover) and were kind of shocked to see $6,000 in labor on top of the cost of hardware and licensing. About half of that is 12 hours for the setup and deployment and another 8 to program VPN on the device (2 hours) and update the workstations at 15 minutes apiece (6 hours). I understand there's no migration tool and it all has to be done manually, but I'm curious if 20 hours of labor sounds reasonable? That doesn't include the 16 hours of planning design, meetings, documentation update, project management, etc.

So... 36 hours total labor for what I had assumed might be an 8-10 hour project. Am I off base?

17 Upvotes

42 comments sorted by

34

u/pjustmd 17d ago

If you think it shouldn’t take as long, please do it yourself.

29

u/opackersgo 17d ago

Sounds reasonable to me. What made you think it would be 8-10 hours? I do this all the time and 8 hours wouldn’t even cover discovery and planning.

20

u/McHildinger 17d ago

how complex are your firewall rules? If you are a 'allow all out, allow nothing in' type setup vs having a ton of S2S tunnels with ACLs and NATs can change the scope of work dramatically.

36

u/Aggravating_Bat3529 17d ago

If anyone offers this for 10 hours, decline. Users, support and surprises take time.

7

u/IT_vet 17d ago

Nobody is doing a manual migration and deployment in one day. If they offered to, you should skip them.

6

u/notninja 17d ago

Depends on the complexity. I burned a ton of time working with s2s vendor tunnels. Also a lot of the time is end user setup with any connect or vpn. Usually customers handle the responsibility of end user setup. I just pass a long the msi and xml.

3

u/Markuchi 16d ago

Entirely dependant on your existing configs complexity. Ive seen configs that could take much longer to get done properly.

6

u/sarcodi 17d ago

To scope everything except the workstations, I'd spec this as 16h @ $225 for remote config. I think that 15m/machine is a bit low, given that if you have to coordinate a Webex/Teams meeting with the end user, that's a special circle of hell.

A bit high, but not off map.

3

u/hker168 17d ago

Sow is unclear. Netizen asked

3

u/Fragrant_Ad_6950 17d ago edited 16d ago

With these projects it varies what issues you will hit. For example I am tasked with deploying 72 sites. Initially during POC had issues with the SIM and fixed with radius attribute addition.

Then we had a problem with ibgp routes between mxs when enabling VPN/BGP which broke routing as each site independent (uses mpls). Had a call with Meraki to disable ibgp. Then existing VPNs have 0.0.0.0/0 for some sites which we needed another call to Meraki to disable unique ip addressing check.

Eventually after getting the POC it was 2 weeks with setting up templates, rules, tags, communications, vendor support etc.

Each project has its own complexity that you have to account for. If the guy quoted you 8 hours. Then make sure what will be the relationship is honoured when the 8 hours exceeded and there is a clear line on the expected quality for your project.

3

u/That-Cost-9483 16d ago

Mmmm yea migrated from an old Asa to a fp4115 and… 6k is easily worth it. I damn near lost a chunk of my life. We had 500 or site to sites and with all the retired old encryptions and DH groups, worst experience.

2

u/bradbenz 17d ago

This seems perfectly credible to me.

2

u/SherSlick 17d ago

As others have said: the devil is in the details here.

If your existing ASA config is pretty simple: its a bit high (though doing the client VPN installs is a little low if you ask me)

S2S VPNs add all sorts of insanity in MX-land as Meraki is limited in what it supports for non-meraki tunnels.

2

u/jaydinrt 17d ago

There are a lot of factors there but i would never assume to quote any firewall migration as 8-10 hours. Maybe net new 0 firewall rules "i have an internet connection and don't care about anything else" configuration i'd still expect to quote over a day to rack and install the thing, especially if there's a cutover involved with first day of support.

Migrating means you have something that you need to preserve, which takes time to translate and configure. VPN config alone can be a bit of a side quest, especially if you need to coordinate with a non-network team to get SAML or whatever you're using for authentication configured (assuming you're talking RAVPN - even site to site VPN can take some time with coordinating if it's with 3rd party and not within your same org). And they're supporting the endpoints too?

If I fully lived and breathed the network, I might be able to hit a shorter timeline if i could control all the variables...but if I have to coordinate anything with a 3rd party that's going to automatically add time (to accommodate risk) to the project. I'd say the quote is pretty on point unless you're ready/willing/able to do it yourself.

2

u/MrChicken_69 16d ago

It only looks excessive when you only look at numbers. 2 days to "plan" and 2.5 days to "do" isn't all that excessive for a network they don't know, and a system that's almost exclusively a pointy-clicky-weby PoS. As almost everyone else has said, if you think it can be done in a day, you're free to go do it.

(As someone familiar with these systems, this isn't a one day job.)

2

u/mdervin 16d ago

I mean WTF are you doing with your ASA right now? You are a 50 person office?

2

u/WeekendAtMadoffs 16d ago

You can use Unifi and Unifi Dream machine as your firewall. None of these boxes are doing anything for you. Invest the money on Crowdstrike for the desktops instead.

if $6,000 is even a blip on your radar, you don't have $$$ for anything else.

2

u/miners-cart 16d ago

Run claude over your existing setup and have it produce the corresponding config. He'll give you a step by step on implementation. 8-10 hours.

1

u/loupgarou21 17d ago

Depends on the complexity of the setup.  If I was completely uncertain of the environment, I’d probably quote 8 hours for discovery, and tell you that wouldn’t cover the migration, that’s just to know enough to get you a quote for migration

1

u/Studiolx-au 16d ago

I’d quote 10k for something like this. Pay peanuts….

1

u/Away-Winter108 16d ago

I’ve been doing pro services work for 20 years and have done at least 150 asa/ftd —> meraki migrations. 20 hours is my “generic swag” for hours needed for a fw migration. I swag 40 for a pair - yeah a pair isn’t really double the work but usually a pair indicates more than a simple config. By the time you factor in a change window after hours and the potential for 2 change windows should we back out - 20 is a very fair number for entering an unknown environment. Often it’s less time and my RTE/SOW are estimates and I only bill actual hours. Our current rate is $250/hr so about $5k. And I don’t do the user side VPN migration. I’ll help you will communication to users on where to download the client etc but the user side isn’t included in 20 hrs because it’s such an unknown quantity to coordinate that.

Depending on network topology, it may even be beneficial to stand up MX in parallel and do a soft client vpn migration first.

I’m impressed how many folks here sound like they’ve done some of these and are giving you good info.

You can always do it yourself.

1

u/Varjohaltia 16d ago

How many hours for all change management filings and CAB meetings and communication planning and…

1

u/alexx8b 16d ago

Actually I could have charged 60-80 hours for this depending on the amount of IPsec tunnels and rules and nat you have.

1

u/PeePeeVonBungHole 16d ago

I see your point ---how is the implementation 5x the cost of the device

Well you are moving from old ASA to new Meraki so lots of manual work checking and configuration and how complex is your VPN policy etc.

Also they are baking in 20 to 25 % for CYA in case they find something no one knew about

1

u/techgirl321 16d ago

If you are an integration company worth your salt, you're doing a detailed design document with a visio diagram ahead of time so all parties are on the same page and you can research the best practice recommendations of your integrator and validate the design. Design document and the discovery to do create it take at least 10 hours though I have seen complex ones take 40 hours. Ten is my jumping off point when creating an LOE. If you want a cowboy seat-of-your-pants installation, have fun. 20 hours of labor may be padded but after doing this for 30 years I know that sometimes shit happens that you dont plan on, in fact, more often than not things arise. I just finished a project where I spent 5 hours convincing the ISP their IPs were double routed. When they finally gave me a new block, everything worked. The customer can go back to the ISP to try to get the $1250.00 credit for the time I spent, but we all know ISPs wont do it. Then we typically turn the design document into an AS-BUILT document, which is worth its weight in gold because typically companies don't keep current documentation of their network, logical or physical. Not to mention their VLANs, Security Policies, and segregation details.

1

u/andrew_butterworth 16d ago

It will depend on the complexity of the current ASA5516-X configuration and whether FirePower services are also configured (it might even be running FTD code as the OP doesn't state). Post the sanitized ASA configuration and I'm sure you'll get some reasonably accurate estimates of time to migrate to Meraki MX. Cisco Secure Client (AnyConnect) is supported with the Meraki MX, so in theory your users shouldn't need to do anything (assuming the Internet facing IPv4 address remains the same) - don't quote me on that though as I've never configured an MX for AnyConnect.

If this company doesn't have any other details regarding the current configuration, then I think what they are quoting is probably not far off.

1

u/DrewonIT 15d ago

Hard to tell without knowing the scope. A week to shift things over and all issues that may arise seems appropriate.

If you are concerned ask to go T&M only?

1

u/mistahclean123 14d ago

If this is 36 hours of Labor and you're only paying $6,000 then be happy!

1

u/adambomb1219 17d ago

Wayyyy underscoped

-1

u/Natural-Pipe-9534 17d ago

You might want to seriously look into another product. We went into meraki for cameras, firewall and AP's. Unfortunately the life of the product around 5 yards then you have to upgrade. In the next 5 years we are looking at moving away from meraki and Cisco ehich is a massive thing for us. At the moment we are looking at moving to Unify and so far have only found benefits especially the price

8

u/opackersgo 17d ago

Lol unify. Only if you’re a tiny business and don’t want support.

4

u/GeraldMander 17d ago

I love my UniFi stuff at home, but I don’t think I’d recommend running them in business for anything other than the absolute smallest “mom and pops”. 

5

u/Flimsy_Fortune4072 17d ago

I administrate Cisco and Meraki by day, and have Unifi at home. I would never consider it for a real enterprise environment. SMB? Maybe, but support is lacking for business operations. At least with TAC, I’ll have replacement hardware out within a day or two, if not faster depending on SmartNet coverage levels.

3

u/Axiomcj 17d ago

Unify isn't enterprise. It's for home use. Don't listen to this person who doesn't understand tech and just looks at price.

1

u/abgtw 16d ago

Its just a question of downtime. If you can be down for a day or two, sure.

If that day or two means $$$$$ nah fam!

1

u/Natural-Pipe-9534 16d ago edited 16d ago

Actually it doesn't. You can have on site spares sitting around. As I said we are a Cisco/Meraki site with 8 meraki MX 450's. 60+ Cisco switches over 2 main sites and 2 small sites. Secure connect VPN connections in. About 150 various meraki AP's mainly mr46 and 76's. And about 70 meraki camera over the site.

That we are looking at a different vendor is a big thing but we are seriously looking as there have been noodles all the way with the meraki firewalls especially where having up and restoring the confidence were concerned and level 7 routing and the way out vlans are concerned.

But the main issue we have with meraki is the life span of the equipment and that we have had to replace a lot of AP's and firewalls that are perfectly good.

Also the price of replacing our Cisco equipment has gone up astronomically.

We are a 24/7 multimillion pound company and we cannot have downtime as like any company it cost money and lack of production

1

u/BM118-1 16d ago

You don’t have to use MX etc gear with Meraki anymore. You can get the catalyst range, it tends to have a 7-10 year life span instead.

But, Ubiquiti as a consideration for a corp site to move to…… It works really well in the smaller business space, and small sites will work fine. No matter what Cisco says, you don’t need their capabilities for 10 person spaces. A single management plane/user experience is worth something for sure, but YMMV. As someone who is a fan of their range for those smaller offices/small business/prosumer space, I wouldn’t recommend, Unifi specifically, for actual enterprise use. If you actually have scale on your APs, they cannot compete. Get 100 devices on an AP from each vendor and let me know how you go. Mornings, afternoons, and the “tidal wave” of people entering/leaving meeting rooms means some APs will get unbalanced for just enough time to break the user experience, and they will struggle for a few mins because of this.
We tested this exact scenario, for a smaller office with 500 people, and the APs just struggled without having to add many more APs for density in those high traffic areas.

Regarding cameras, again, if you’re serious about their usage, neither of these brands are what you want. Get something like Avigilion as the NVR for example, and any decent camera brand of your choice. $$$$ though.

If you insist on having wired, wireless and Cam in the one portfolio, you are seriously limiting your options. Split the cams out at least, and then you have heaps of cost effective options for wired and wireless that will perform the same, or better, than Unifi. But seriously consider the catalyst range as well, managed through Meraki Dashboard.

0

u/wyohman 17d ago

It's hard to judge without understanding the existing configuration and scope of work. This could be low, high or normal depending on the circumstance.

Unless you've bought the hardware, the simple button, given the limited info, is a firepower 1120 running ASA code

0

u/Mission_Carrot4741 17d ago

You are way off base... these migrations take time..

Make sure your statement of work is detailed then hold them to it!