Virtual MX Question

Hello. I have a client who is looking at replacing an MX-450 for a Virtual MX that can handle a heavier load specifically when using Malware detection and Intrusion detection. They have a 2Gig fiber up and down that they regularly use 80% of. When the malware and intrusion detection is enabled it chokes the connection. My feeling is the MX-450 can physically handle the 2800 devices, they just need a bigger pipe to the net to handle the usage.

Does anyone have any experience with the virtual MX or have an MX-450 with a 3-10Gig pipe and about 3000 active devices that can give me some good feedback?

Firstly the vMX is mostly just a VPN concentrator, there is no “through” on it.

As for the MX450 cutting the mustard: I would reference the sizing guide here:

Edit: Thanks for the gold!

vMX are not for on prem.

https://meraki.cisco.com/en-uk/product/security-sd-wan/virtual-appliances/vmx-small/

“Supported in AWS, Azure, Google Cloud Platform, Alibaba Cloud, Cisco NFVIS”

The MX450

https://meraki.cisco.com/en-uk/product/security-sd-wan/large-branch-campus-concentrator/mx450/

Large-branch, campus, or DC security and SD-WAN appliance for up to 10,000 users.

It is unlikely that 2800 client devices would be too much for the MX450 to handle. Not impossible, but unlikely.

Max throughput

https://meraki.cisco.com/product-collateral/mx-sizing-guide/?file

If the connection is “choking”, then probably need to investigate what that actually is (Wireshark etc) and where it’s coming from as it may well not be the MX450

I agree with you, a 450 can handle double that with all features enabled. And I agree with /u/ivantsp as well, it doesn’t sound quite like it’s the MX but something else. It sounds to me like the MX is sending lots of malware scanning data out to another site and that increase in traffic is the problem. What is your scanning tool, Unbrella?

If you want bells and whistles on a security appliance at a high throughput, you should look to Palo or Fortigate. We have a MX450 ha pair. It cannot keep up with 2 1gig wans. For example, uploading to a S3 bucket on wan1 slowed down when I ran a Speedtest from wan2. Different clients obviously. Circuits are geo diverse. Or high rates of cross vlan traffic. Our no amp group policy is used quite a bit.

Perfect. Thank you.

I will look at that. I miss the ASA with the Fireppwer added on that was there,