Meraki

I spend a lot of time pouring over vendor solutions. A lot. Unfortunately, I don’t specialize in one area like wireless, security, storage, voice, etc. I am more of a network generalist. Because of that, I tend to focus on the big companies or those who fill a certain niche. There are just too many vendors to keep track of. Because of that, I seem to have missed Meraki. Thank goodness for Wireless Field Day 2! For an in depth recap of the WFD2 visit to Meraki, read Tom Hollingsworth’s post here.

It’s not that I was completely ignorant of them. I’d seen some of their advertisements. I knew that they sold wireless gear. I knew that they had some switches and firewalls. Everything was managed by the “cloud”. I took all that into consideration and thought: “Yay. Another vendor shilling for the “cloud”. As if we didn’t have enough already.” That was my thoughts on Meraki coming into Wireless Field Day 2. I work for a VAR that sells Cisco, HP, Aerohive, Brocade, Juniper, and a ton of other vendors. We have a variety of wireless choices at our disposal. I can sell a product for almost any environment. In short, I can work with all sorts of “it depends” scenarios. That should help explain some of my skepticism.

That doesn’t mean I was opposed to hearing Meraki’s pitch. I LOVE talking to vendors no matter the size of the company or the particular area they focus on. I firmly believe that every vendor has something to offer. They ALL employ smart people.

So that’s where I was at on Thursday, January26th when we pulled up to the Meraki headquarters in San Francisco. I was a skeptical non-believer. We walked through their offices and it felt 100% like a tech startup. Lots of young people typing away on large screen Macs. Plenty of flair attached to desks of varying heights. A few dogs wandering around. Snacks galore in their break area(which also included a few kegs of beer). All the things that scream: “You want to come to work.” Nothing like the usual corporate environments where cubical walls run high, dress codes are enforced, and the only semblance of a corporate perk is free coffee or a meager selection of carbonated beverages. Still, I was skeptical. I’ve seen this before. It is replayed “ad nauseum” across the entire Silicon Valley landscape.

The more I listened to the people from Meraki talk, the more I began to change my mind about them. We all asked a fair amount of questions. They answered them with a fair amount of candor. They also did a demonstration of their management platform. During this demonstration, I couldn’t help but think how polished the management interface looked. It was full of features, yet didn’t seem cluttered. It wasn’t a canned demo either. Below is a video of Pablo Estrada from Meraki walking us through the wireless product. He also took a little time showing us the switch and firewall management piece as well.

Live demonstrations of Meraki Wi-Fi gear with Pablo Estrada from Stephen Foskett on Vimeo.

In addition to the extensive demonstration that Pablo did, one of the delegates from WFD2, Daniel Cybulskie, put together an article and video on Meraki’s Device Manager product. You can access it here.

 

 

 

 

Wireless

Their wireless product set is very easy to understand. A few AP models for indoor and a few for outside. They have all the major features other vendors have. WIPS, RTLS, spectrum analysis, RRM, 802.1x, device fingerprinting, etc. Everything is managed through the MCC(Meraki Cloud Controller). After our initial discussions at the Meraki headquarters, it seemed as if their controller wasn’t very controller-like at all. If you lost your connection to the MCC(ie the Internet), you could still authenticate new users provided your RADIUS box was local. Your captive portal would also continue working for guest access provided you hosted that locally. With a lot of the other solutions out there, this wasn’t the case. If you lost your link to the controller, you could still function, but no new client connections could happen.

Could this be another controller-less solution? After all, the MCC seemed to be more management plane oriented and less control plane oriented. Then, the mystery was solved. RRM didn’t work 100% without the connection to the MCC. In effect, layer 3 roaming was dead without the MCC link. However, we were informed that Meraki is working on making that functionality available locally(read the “Comments” section in this link). At some point in the future, you can lose the MCC link and still be able to roam via layer 3. I suspect this isn’t a big deal in some of the areas Meraki is prevalent in(ie retail), but can be an issue in the larger networks like educational institutions, hospitality, etc. Once the layer 3 roaming piece is worked out, Meraki will be a lot closer to the controller-less solution that Aerohive has been alone in for the past couple of years. Ideally, most decent sized networks will have redundant Internet connections. You could even buy a cheap DSL or cable modem circuit and only use it for backup connectivity to the MCC should your primary circuit fail. DSL and cable are cheap compared to a full blown redundant Internet circuit for a medium to large network. I am not entirely sure of the bandwidth requirements, but I can’t imagine they are huge given the fact that all data plane traffic stays local and quite a few of the control plane functions can stay local as well.

 

 

 

 

 

But Wait……..There’s More!

If one were to simply look at the wireless portion of Meraki, you would miss out. As of today, they are selling their own wired switches and firewalls. This is where I think they start to differentiate themselves from other companies even more. These devices are also managed over the Internet. The switches are basically 24 or 48 x 1Gbps interfaces. All wire speed/non-blocking. You can get them with or without PoE and they support 802.3af and 802.3at for your devices requiring a bit more power. Oh, and all ports can provide power at once if need be, but the limitation on the switch(24 and 48 port) is 380W in total.

There are some additional limitations on the switching side. They do provide 10Gbps uplinks from the switches, but it appears they are only doing so with short-haul multi-mode optics. I suspect this is because most of their customers are going to use short haul optics if any optics at all. In my opinion, these switches are not going to be dropped into a network to run as a core or distribution switch unless it is a rather small environment.

 

 

 

 

 

Yes. There’s Still More!

Not to be content with basic wired/wireless products, Meraki also has a decent firewall/UTM/router/call-it-what-you-will offering. Ranging from 100Mbps to 2Gbps stateful firewall throughput, they have a box that can meet most organization’s needs at least from a throughput perspective. As with any other vendor, when you spin up VPN connectivity, throughput drops like a rock. I suspect other features cause a performance hit as well, but those numbers aren’t displayed. That isn’t unique to Meraki. No other vendor that I know of will openly tell you how poorly their box runs when you turn all the features on. Why would they? Marketing isn’t in the business of highlighting the negatives. 🙂

A firewall is a firewall right? Not these days. If you want to differentiate yourself from the others, you need to have some serious application intelligence. A big part of what makes PaloAlto Networks a good firewall vendor is their ability to understand a ton of applications and affect throughput based on that understanding instead of the usual IP address and port access rules. Barracuda Networks can do this too with their Next Generation firewall as does Check Point with their latest and greatest offering. The Meraki firewall is able to do substantial application recognition and when paired with device fingerprinting, you can give users an experience that they will either love you for, or hate you for. In short, you have some serious options. Allow iPads to access Facebook, but prohibit laptops. Those kinds of things.

Apparently, that wasn’t enough for Meraki, so they took their firewalls to the next level. They included content filtering, routing, WAN optimization, link bonding, and automatic VPN creation.

The VPN portion looks to be pretty straightforward. They can create IPsec tunnels between your remote sites with a single click. I’ve built massive numbers of VPN connections over the years. However, I have never built one with a single click. Obviously, since all these devices are managed over the Internet, it can send down the appropriate phase1/2 parameters that you normally enter manually on each end of the connection. Very quick and efficient provided you are using Meraki gear on both sides.

The link bonding is really just a way of aggregating dissimilar connections so that you can perform basic load balancing and also have failover without having to employ a large amount of devices to support it all. Barracuda Networks has a similar product. This isn’t a service that a large enterprise customer would necessarily employ as they are going to use redundant hardware and other mechanisms to control the flow of traffic. I can see the benefit of this for the medium to smaller customers. Especially considering it doesn’t cost you any more money. In fact, the only increased licensing charge appears to be for content filtering, client VPN connectivity, and anti-virus.

I saw a bit of the content filtering during the product demo at the Meraki headquarters. It appears to be fairly in depth like most decent content filters are. You can filter by category, end user, etc. Nothing too exciting there, but a nice feature to have considering other vendors have separate appliances you have to install for this type of service.

The one thing out of all of these features that caught my eye was the WAN optimization piece. The low end MX60 has 100MB of cache. The other models all have 1TB of cache on a SATA drive with the exception of the large MX600. It has 4TB in a RAID configuration. That’s a lot of space for WAN optimization cache. If you look at Riverbed Steelheads, you have to get the 5050H to even get 800GB of cache storage. To get 4TB or more with Riverbed, you have to buy the largest box they sell, the 7050M. I can assure you that box costs 4 times or more of the price of the MX600. I would be willing to bet the Riverbed Steelheads will outperform the Meraki MX boxes from a WAN optimization perspective, but considering you get the WAN optimization for no additional fee, it would be worthwhile to use it even if the gain was minimal. Meraki states you can get up to 99% intersite bandwidth reduction using their WAN optimization and that you can accelerate CIFS, FTP, HTTP, and TCP traffic by up to 209 times the non-accelerated rate. Of course, that all depends on a variety of factors. I wouldn’t count on seeing those kinds of performance numbers outside of pristine lab scenarios, but again, it’s WAN optimization without the price tag of the larger vendors.

That covers the 3 main Meraki lines. Wireless, wired, and security. A product set that is easy to remember. Now how about pricing? What does a Meraki network cost? Thankfully, you can find that out before you even pick up the phone or send out an e-mail to their sales staff. They actually have a fairly decent pricing tool right on their web site. The cost for each AP, switch, and MX firewall is shown along with licensing, maintenance, etc. This is something I wish more vendors would do as it shows the customer right up front what their costs are going to be. If they get it cheaper, then even better, but at least they know how much they should budget for initially. What makes the pricing tool even more interesting is that they compare it to the cost of comparable Cisco products. They actually give the corresponding Cisco part number and the associated cost.

 

 

 

 

 

 

 

The prices are all list, but you can add the appropriate discount into the calculation to get more realistic numbers, because who pays list? 😉

Closing Thoughts

Like a lot of companies out in the Silicon Valley and Bay Area, Meraki employs a fair amount of smart and talented people. Using commodity hardware and some decent software, they appear to have built a nice product set with a management model that is appealing to your small to medium environments. The questions that I find myself asking are where they fit and don’t fit. What environments would they thrive in? Certainly the heavily distributed environments that survive off a single Internet connection are applicable. Retail immediately comes to mind. I don’t doubt their wireless can scale, but until they can handle layer 3 roaming without a link to the MCC, I will remain cautious. This isn’t a controller/controller-less argument on my part. It’s just that any time you rely on something off site to serve a critical function, you better make sure you have more than one way to connect to it.  As for the wired switches, I think they would be fine on the edge. Will they build more capable switching platforms in the future? I am guessing that they will. Hard-wired switches don’t have the same dependency on the dedicated link to a management platform like the wireless solution does. As for the security solutions, they appear to be able to scale up to the large network size. Perhaps some in depth testing of the MX platforms would paint a different picture.

As of today, I have a much different opinion of Meraki compared to just a month ago. I like what they are doing with the concept of “cloud” based management of their hardware. It makes it easier to sell to certain organizations that want to run lean IT shops. The Meraki product is easy to install and easy to use, based on my own testing of one of their wireless AP’s and the corresponding management console. Their products are not for everyone. Certain organizations are not going to want to go the route of “cloud” managed hardware. They also don’t have a ton of different hardware options that some organizations will want. That’s the risk you take when running with a model such as theirs. I do think that we’ll see more and more interest in companies like Meraki as IT resources become scarce in the years to come. By resources, I mean people. I look forward to seeing what they will come up with in the future.

Disclaimer: As a delegate for Wireless Field Day 2, my travel, lodging, and meals were paid for by a number of vendors including Meraki. I also received some items from Meraki with their logo on it along with an MR16 access point to keep for testing or personal use. None of this was done with the expectation that I would write or say anything about them.

 

This entry was posted in cloud, security, switching, vendors, wireless and tagged , , , . Bookmark the permalink.

8 Responses to Meraki

  1. Pingback: Wireless Field Day 2: The Links

  2. Devin Akin says:

    Hi Matthew,

    This was a great write-up. You got skillz brotha. Comments:

    1) Might I ask how Meraki does L3 roaming even with the MCC link up?
    * Did you accidentally reach a conclusion, and they let you keep going with it without correcting you? To me, that looks like what happened on the Meraki blog in the comments section. 🙁 Boo Meraki.
    * I wonder how many other bad conclusions they led you to or allowed you to arrive at without correction. :-/ Time for the Spanish Inquisition methinks. You obviously caught that 209% crap on the WAN-opt. 🙂 I’ve found that with Meraki’s marketing, you have to “read between the lines” alot more than with other vendors. I’m told the same by my friends at other vendors who compete with Meraki. 🙁 Boo Meraki.

    2) “Commodity hardware” is right. Commodity hardware isn’t the answer to the BYOD nightmare though…ask Aerohive, Ruckus, Cisco, Xirrus, and the rest. High throughput at high density with iDevices takes superior hardware.

    3) Meraki seems to be doing “a little of alot”. In cases like this, a company becomes a jack-of-all-trades/master-of-none. Would you agree? This seems to be their strategy. Hey, I’m not knocking it – it’s a valid and reasonable strategy by any account. It’s important to note however that if the customer is looking for best-of-breed, they won’t get it with Meraki (unless we’re talking about the GUI perhaps). They seem to specialize on the GUI, and it shows. Kudos to their GUI guy(s).
    * An engineer I used to work with once asked me what I wanted to be. I said, “the best engineer in the world.” He said, “At what?” I said, “At everything I do.” He said, “You’re going to fail.” I said, “Why?” He said, “Because there’s not enough time. You should specialize.” He was right. I did specialize: Wi-Fi…and look what it’s done for me…alot. Morale of the story: If you want to be the best at any one thing, you must specialize. Look at Aerohive, look at Ruckus, look at MetaGeek. Am I wrong?

    …and again, like you asked on Twitter, they do have a nice interface. Meraki isn’t all bad. In the words of my friend Scott Daniel, “I loves me a nice GUI” (so do I), but if the system can’t deliver on its intended purpose of providing highly-reliable infrastructure for the intended purposes….oy. Meraki is an appropriate solution for some vertical markets and some customer types. If that were not true, they would’ve been gone already. I think it’s silly of them to be trying to take their lack-o-technology into places where it doesn’t fit via vague-yet-polished marketing spin. They should be true to who they are and what they have in their marketing.

    Again, this was a spectacular write-up. Excellent work.

    Yea Matthew! 🙂

    Devinator

    Devin Akin
    Chief Wi-Fi Architect
    Aerohive Networks
    blogs.aerohive.com

    • Devin,

      I have to take some things at face value. With regards to L3 roaming, I would have to test this out in order to be sure. I only have 1 of their AP’s, so unless several of us from WFD2 pool our AP’s together to test, I guess we’ll have to trust Meraki. Hey, now that Andrew works for Aerohive, maybe he won’t need his Meraki AP anymore. 🙂

      I will also point out that I was one of the dumber people in the room with Meraki as it relates to WiFi. There isn’t much that gets past the group of people I was with, and I know you know this. 🙂 If something regarding roaming seemed off, I would imagine someone would have brought it up. Is it your contention that they are unable to do L3 roaming at all?

      With Meraki deployed across several college campuses, I have to imagine L3 roaming is something that has come up. Those are high density environments. Of course, if no real time traffic(ie voice/video) is in use, you might not even notice a move from one subnet to another. Again, I will have to take their word on it. They have publicly stated on their site that they support it. It wouldn’t look too good if they were being untruthful.

      I met the guy who wrote that post. I even rode in his nice new Subaru. I didn’t get the impression that he was one of those bad marketing types that sits around the office cranking out FUD all day long and blasting it to the far corners of the Internet. They were all very nice and genuine people just trying to advance their technology. Not unlike your company. 🙂

      Matthew

  3. Hi Matthew,

    Thanks for writing this thoughtful and considered blog post. You clearly took the time to document what you saw and learned, and it’s great that you shared it with the rest of us. Thanks for keeping an open mind when you were here visiting, even as a self-described “skeptical non-believer” 🙂

    By the way, I think what Kiren wrote in his Meraki blog comment was pretty clear.

    I’m also glad you found the cost calculator useful. We aim to make the whole solution easy to understand, including down to the pricing and SKUs.

    Pablo
    pablo@meraki.com

    • Pablo,

      The cost calculator is a GREAT idea. I especially like the idea that you allow people to account for a discount instead of trying to pass off everything as if we all pay list pricing with Cisco as some will do in cost comparisons. Thanks for the comments and especially for spending time with myself and everyone else during Wireless Field Day 2!

      Matthew

  4. Jack J Silvera says:

    Have anybody tried Tanaza (http://www.tanaza.com). I recently found them on-line and it looks like they do something similar to Meraki but at a much lower price point, and they also support multiple Wi-Fi AP vendors, like Netgear, D-link, TP link and Ubiquiti. I plan to use them shortly at a client site. I was wondering if you had any experience with them.

    • Jack,

      That’s an interesting company. I had never heard of them prior to seeing your comment. Although they are “cloud based” like Meraki, the fact that they manage several different vendors tells me they are going to be a niche player in very small sites. I would be interested in the features they will be able to provide when compared to the larger Enterprise vendors out there. The cost is really reasonable, and until May of 2012, it’s free to use! Couldn’t hurt to try them out I suppose.

      Matthew

  5. Pingback: Wireless Field Day 2 Wrap Up | Meraki Blog

Comments are closed.