Is 36 Hours of Labor Reasonable for Replacing an ASA-5516 with a Meraki MX95 HA Pair?

0
0
Asked By MellowPine47 On

We're a single-site organization with about 50 users, and we've been quoted roughly $6,000 in labor to retire an ASA-5516 and deploy a pair of Meraki MX95 appliances in high availability. The quote includes about 12 hours for setup and deployment, 2 hours to configure the VPN, and 6 hours to install or update VPN software on workstations at 15 minutes per device. Another 16 hours is allocated to planning, design, meetings, documentation, project management, and related work. That puts the total at about 36 hours, excluding hardware and licensing. I understand there may not be a direct migration tool and that the existing configuration has to be reviewed and recreated manually, but I expected this to be closer to an 8–10 hour project. Does this estimate sound reasonable, or is it excessive?

5 Answers

Answered By CedarViolet3 On

The estimate isn’t automatically unreasonable if the consultant is carefully auditing the existing ASA configuration and rebuilding a complicated design. Internal NAT, multiple WANs, dynamic routing, large Layer 2 domains, unusual firewall rules, and several VPN authentication methods can add significant time. The planning, testing, documentation, and change-management work can also be legitimate, especially if this is a fixed-price project. Ask for a detailed list of deliverables and assumptions rather than judging only by the appliance count.

Answered By SilverKite29 On

For two MX95s configured as a warm-spare or HA pair, the basic appliance setup itself should not take very long. The real question is how much complexity is behind the ASA. If the provider cannot explain exactly what the 12 deployment hours and 8 VPN-related hours cover, I’d push back. A fixed-fee quote can be fair, but it should include clear acceptance criteria and not charge enterprise-level migration effort for a simple configuration.

Answered By BriskLantern6 On

The workstation portion is worth questioning. Installing a VPN client on each computer is often a simple MSI or scripted deployment, so you may be able to handle that internally or have the provider supply an installer. Fifteen minutes per machine may simply be the provider’s minimum billing increment, not the actual technical effort.

Answered By NorthPebble52 On

I’ve done similar firewall replacements in a day when the existing configuration was well understood and there were only a few rules and VPNs. Other migrations have taken several days because discovery, testing, documentation, and troubleshooting were included. The best way to evaluate this quote is to request a breakdown of the current ASA objects, routing, NAT, VPNs, failover testing, workstation deployment, rollback plan, and documentation. If those items are simple, get a second quote; if they’re complex, 36 hours may be defensible.

Answered By QuartzHarbor8 On

It depends heavily on what the ASA is actually doing. A basic Meraki deployment with straightforward NAT, firewall rules, routing, and a site-to-site VPN could probably be completed in a day. Meraki is largely configured through the dashboard, and much of the work can be scripted through the API. For a simple environment, 20 hours for the technical work sounds high, and eight hours just to configure the VPN would be difficult to justify.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.