Is 36 Hours of Labor Reasonable for Replacing an ASA-5516 with a Meraki MX95 HA Pair?

0
0
Asked By MellowCedar47 On

We're a single-site organization with about 50 users, and we've been quoted roughly $6,000 in labor to retire our Cisco ASA-5516 and deploy a pair of Meraki MX95 appliances in high availability. The estimate includes about 12 hours for setup and deployment, 2 hours to configure VPN, and 6 hours to install or update VPN software on workstations. Another 16 hours is allocated for planning, design, meetings, documentation, project management, and related work.

That puts the total estimate at 36 hours, not including the hardware and licensing. I understand there may not be a direct migration tool and that the ASA configuration has to be reviewed and recreated manually, but I expected this to be closer to an 8–10 hour project. The actual complexity depends on our firewall rules, routing, NAT, site-to-site VPNs, authentication, and what is behind the firewall. Does this estimate seem reasonable, or is it excessive?

4 Answers

Answered By QuietHarbor82 On

For a straightforward configuration, 36 hours sounds high. Meraki is largely managed through the dashboard, and the basic VPN and HA setup should not take eight hours by itself. A consultant who understands the existing ASA configuration could probably complete the technical migration in roughly 5–15 hours, depending on the number of rules, NAT entries, VLANs, routes, and VPN peers.

That said, the quote may be covering discovery, testing, rollback planning, documentation, and project coordination rather than just clicking through the Meraki setup. Ask for a detailed task list and a clear breakdown of what is included.

BrightMango6 -

The workstation estimate may be a separate issue. If the VPN client can be packaged as an installer or deployed through existing endpoint-management tools, installing it on each machine should usually take much less than a full 15-minute billing block per computer.

Answered By NorthstarQuill29 On

The answer depends almost entirely on the current ASA design. Recreating a small, simple edge firewall with a few VLANs, basic NAT, and one or two VPNs could be a one-day job. A more complicated environment with internal NAT, multiple site-to-site tunnels, dynamic routing, authentication integrations, complex firewall policies, or a large Layer 2 domain could reasonably take several days.

The planning and documentation time is not automatically unreasonable, especially if the provider is responsible for validating the old configuration, testing failover, documenting the new design, and providing a rollback plan. But 36 hours should come with a very specific scope and deliverables.

Answered By SilverPebble73 On

Some people can complete this kind of replacement in a few hours, but that usually assumes they already know the environment and are comfortable troubleshooting it themselves. A professional quote also includes time spent discovering undocumented behavior in the ASA and making sure the migration does not interrupt business operations.

I would not judge the estimate from the appliance configuration alone. Have them identify the number of firewall rules, VLANs, NAT policies, VPN connections, routing protocols, authentication methods, and endpoints involved. If those counts are all modest, the quote deserves closer scrutiny; if the design is complicated or poorly documented, the extra time may be justified.

Answered By CopperWren51 On

I would separate the estimate into migration work and optional project-management work. The MX pair can often be staged in advance, with most configuration completed before the cutover. Ask whether the provider can supply a detailed plan, preconfigure the appliances, automate the VPN-client installation, and let your team handle straightforward workstation changes.

Also request a fixed-fee proposal or an hours-not-to-exceed amount. That makes it easier to compare the quote with another provider without arguing over whether every individual task should take 15 minutes or two hours.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.