Home / Partners / Cisco Meraki vMX on AWS
AWS Partner Network · Service Offering

Deploy Cisco Meraki vMX on Amazon Web Services with confidence.

ExecConcepts is an AWS Partner specializing in the architecture, deployment, and managed support of Cisco Meraki vMX virtual security appliances on AWS. We extend the Cisco Meraki SD-WAN fabric into Amazon Virtual Private Cloud environments for healthcare, dental, state and local government, and mid-market organizations — with a repeatable, audit-ready engagement model.

AWS Partner Network member Service Offering delivered on Amazon Web Services. AWS Marketplace listed (BYOL).
Practice
Cisco Meraki vMX on AWS
Our partnership

An AWS-aligned practice, purpose-built for regulated and operationally sensitive workloads.

ExecConcepts has invested in the AWS Partner Network to give our customers a single accountable partner for the full lifecycle of a Cisco Meraki vMX deployment on AWS — from initial assessment and AWS account preparation, to AWS Marketplace procurement, to active-active high-availability deployment across multiple Availability Zones, to long-term managed support.

Our team builds every engagement to the AWS Well-Architected Framework. We deliver in writing, with named engineers, fixed scope, and a documented project plan — the same standard required of AWS Service Delivery Partners.

  • 5 AWS-certified engineers across Solutions Architect, Networking, and Security tracks
  • 10 Business-day standard deployment timeline, kickoff to handover
  • 2-AZ Active-active high availability is the default, not an upgrade
  • 24×7 Post-deployment managed support tiers available
What we deliver

A complete Cisco Meraki vMX on AWS service offering.

We deploy the Cisco Meraki vMX virtual appliance — available as vMX-S, vMX-M, and vMX-L on AWS Marketplace (Bring Your Own License) — into a customer-owned AWS account, integrated with the customer’s existing Meraki Dashboard and on-premises Meraki MX fabric. Every engagement includes the four components below.

AWS landing-zone preparation

Account governance review aligned to the AWS Startup Security Baseline — root-account MFA, AWS CloudTrail across all Regions, AWS IAM Identity Center federation, and an Amazon Simple Storage Service log destination with MFA Delete.

Active-active vMX deployment

Two Cisco Meraki vMX instances launched from the AWS Marketplace BYOL listing across two Availability Zones, fronted by AWS Transit Gateway and integrated with the customer’s existing Amazon Virtual Private Cloud topology.

Meraki AutoVPN fabric extension

Existing on-premises Meraki MX sites are joined to the AWS deployment via Meraki AutoVPN with no additional tunnel configuration — the Meraki Dashboard remains the single pane of management for all sites.

HA failover automation

AWS Lambda functions monitor vMX health and reroute traffic through AWS Transit Gateway in seconds, with Meraki API credentials held in AWS Secrets Manager and runtime telemetry in Amazon CloudWatch.

Documented handover

Customers receive an as-built runbook, the network diagram, an AWS Identity and Access Management role map, the AWS Secrets Manager rotation schedule, and a user-acceptance-testing checklist signed off by both teams.

Managed support & tuning

Optional tiers covering 24×7 incident response, quarterly Amazon CloudWatch metric reviews, vMX firmware lifecycle, and AWS Marketplace license renewal — with named engineers and a defined escalation path.

Reference architecture

Active-active across two Availability Zones, with AWS Transit Gateway at the core.

The reference design below is what every ExecConcepts Cisco Meraki vMX on AWS engagement starts from. Customer-specific designs may add additional Amazon Virtual Private Cloud workload accounts, Amazon Route 53 Resolver endpoints, or AWS Network Firewall integration depending on the environment.

ExecConcepts reference architecture for Cisco Meraki vMX on AWS Reference architecture diagram showing on-premises Cisco Meraki MX appliances connecting via Auto VPN to two vMX-M instances deployed across two Availability Zones in an AWS Region. AWS Transit Gateway routes traffic to Production, Development, and Shared Services VPCs. Management services include AWS Lambda, AWS Secrets Manager, Amazon CloudWatch, AWS CloudTrail, AWS Identity and Access Management, and Amazon Simple Storage Service. The Meraki Dashboard remains the single management plane. Aligned to the AWS Well-Architected Framework. ExecConcepts — Cisco Meraki vMX on AWS: Reference Architecture Highly available 3rd-party virtual firewall & SD-WAN landing on AWS (Active-Active across two Availability Zones) Customer On-Premises Branch / HQ / Data Center Cisco Meraki MX Physical Security Appliance (MX75 / MX85 / MX95 etc.) LAN, IDS/IPS, AMP, NGFW Users & Endpoints LAN VLANs / Wi-Fi / IoT Servers, printers, PoS Internet Meraki Dashboard Cloud Mgmt (TCP/7734) Customer Admin • SAML SSO to AWS • MFA on root • Cross-account IAM role • Least-privilege policies AutoVPN tunnel (IPsec/UDP 500/4500) over Internet AutoVPN IPsec ESP AWS Region (us-east-1) Customer-owned AWS Account · Managed under ExecConcepts service offering Transit / Security VPC (10.0.0.0/16) Internet Gateway Availability Zone A Public Subnet (10.0.1.0/24) vMX-M (Active) Private Subnet (10.0.11.0/24) Workload ENIs (optional) Route → vMX-A Availability Zone B Public Subnet (10.0.2.0/24) vMX-M (Active) Private Subnet (10.0.12.0/24) Workload ENIs (optional) Route → vMX-B AWS Transit Gateway Route propagation · Inter-VPC · Cross-region peering Workload VPCs (attached via TGW) Production VPC 10.1.0.0/16 • EC2 / EKS / RDS • Egress via vMX • Default route → TGW • AutoVPN to on-prem Dev / Staging VPC 10.2.0.0/16 • EC2 / Lambda • Same L7 policy • Inspected via vMX Shared Services VPC 10.3.0.0/16 • Active Directory • DNS, NTP • Centralized logs Management & Security AWS Lambda vMX health checks · route failover AWS Secrets Manager Meraki API key (encrypted) Amazon CloudWatch Metrics · alarms · failover events AWS CloudTrail API audit logs → protected S3 AWS IAM Cross-acct role · SAML · STS Amazon S3 Logs & backup config (KMS) AWS Marketplace (BYOL AMI) Key Design Choices • Active-Active vMX across 2 AZs • Lambda-driven HA route updates • AutoVPN to on-prem MX fleet • Centralized egress via TGW • L7 firewall, IDS/IPS, content filter • Encrypted at rest (KMS) & in transit • Least-privilege IAM + MFA on root • CloudTrail in all regions → S3 • Quick Start ref: aws-quickstart/ quickstart-cisco-meraki-sd-wan-vmx Aligned to AWS Well-Architected Framework
ExecConcepts · Cisco Meraki vMX on AWS · Reference Architecture v1.0 Aligned to the AWS Well-Architected Framework
AWS services leveraged

Built on the AWS services we use every day — named correctly.

ExecConcepts deploys the following AWS services in every Cisco Meraki vMX on AWS engagement. Service names follow the AWS product catalog at aws.amazon.com/products.

Compute Amazon Elastic Compute Cloud (Amazon EC2)

Hosts the Cisco Meraki vMX virtual appliance instances across two Availability Zones.

Networking Amazon Virtual Private Cloud (Amazon VPC)

Provides isolated network environments for the Meraki vMX deployment and customer workloads.

Networking AWS Transit Gateway

Centralizes routing between the vMX security VPC, workload VPCs, and on-premises sites.

Procurement AWS Marketplace

Source of the vMX-S, vMX-M, and vMX-L appliance AMIs licensed BYOL through Cisco.

Security AWS Secrets Manager

Stores and rotates the Meraki Dashboard API credentials used by failover automation.

Compute AWS Lambda

Runs the vMX health-check and Amazon EC2 route-table update functions for HA failover.

Observability Amazon CloudWatch

Collects vMX metrics, Lambda logs, and alarm signals for the managed support tier.

Audit AWS CloudTrail

Provides a multi-Region audit log of every API call made in the customer’s AWS account.

Identity AWS Identity and Access Management (IAM)

Enforces least-privilege access for ExecConcepts engineers via cross-account roles with MFA.

Storage Amazon Simple Storage Service (Amazon S3)

Destination for AWS CloudTrail logs, configuration backups, and as-built documentation.

Use cases by vertical

Built for the customers we know best.

We focus the Cisco Meraki vMX on AWS practice on the three customer segments where our existing industry expertise — particularly through our Total Dental Solutions vertical — translates directly into faster, lower-risk engagements.

Primary · Healthcare & Dental

HIPAA-aware multi-site connectivity

Group dental practices and small-to-mid hospital systems with 5–50 sites needing secure, consistently-policied access to cloud-hosted practice management, imaging, and EHR platforms.

  • Practice-management SaaS on AWS
  • PACS & imaging archive offload
  • Site-to-cloud AutoVPN over Meraki
Secondary · SLED

State & local migration on-ramps

State, local, and education customers using Meraki on-premises today and migrating workloads into AWS. AWS Marketplace procurement aligns with cooperative-purchasing vehicles already familiar to public-sector buyers.

  • School districts & libraries
  • County and municipal IT
  • Marketplace cooperative purchasing
Tertiary · SMB / Mid-Market

Cloud landing-zone accelerator

Distributed mid-market organizations adopting AWS for the first time and needing a secure, consistently-managed network plane before migrating their first production workload.

  • Multi-branch retail & professional services
  • Hybrid-cloud network plane
  • Foundation for future AWS adoption
HIPAA  aware design patterns CJIS  considerations available FERPA  for K-12 deployments AWS Well-Architected  reviewed
Engagement model

Ten business days, named engineers, fixed scope.

Every ExecConcepts Cisco Meraki vMX on AWS engagement follows the same four-phase plan, with the same deliverables and the same roles assigned. Customers know what they’re getting before they sign.

1

Discovery

AWS account review, Meraki Dashboard audit, target topology workshop. Days 1–2.

2

Design

Sized reference design, AWS Marketplace SKU selection, signed scope & runbook. Days 3–5.

3

Deploy

Active-active vMX launch, AWS Transit Gateway integration, AutoVPN cutover. Days 6–9.

4

Handover

User-acceptance testing, runbook walkthrough, post-engagement support handoff. Day 10.

Get started

Ready to talk through a Cisco Meraki vMX deployment on AWS?

We’ll scope a fixed-price engagement and provide a written project plan with named engineers before you commit. Most discovery calls run 30 minutes.

ExecConcepts

ExecConcepts provides a range of cost-effective technology solutions delivered in excellence nationwide. We make technology work more efficient and reliable while driving down risk and reducing overall costs for your organization.

Contact