Content found in this wiki may not reflect official Church information. See Terms of Use for more information.
Meraki Installation Guide 2024
Printable instructions for replacing networking hardware in meetinghouses:
Meraki MX and Switch Installation Guide 2024 Meraki MX and Switch Installation Guide 202
Meraki Managed Firewall

- The Meraki MX67 is the recommended firewall for meetinghouses at this time.
- If your meetinghouse has a MX64, MX65, or MX68 firewall replace it with an MX67.
- We also support the following firewalls. If your location already has one of these, it does not need to be replaced: MX75, MX85, MX95, MX105, MX250, and MX450
- Port 2 on the MX67 should be connected to an SFP port on the Meraki Switch using an SFP Module. * Ports 3, 4, 5 will be disabled.
- NOTE: If you don’t have an SFP module then connect to one of the Switch Access Ports and configure that switch port to be “LINK” in Church Network Manager (CNM). (See [insert section form page 13])
Meraki Managed Switches
- For a successful install, please read the instructions before beginning the switch install or contacting the GSD for assistance. Reading and understanding this guide before you begin is imperative for success.
- Label cables before disconnecting them from any current switches.
- At least one Meraki managed switch must be installed in every meetinghouse worldwide
- All MS120 model Meraki switches will be removed as part of this install process. If a meetinghouse already has MS130 model switches, those can continue to be used
- Many meetinghouses use a combination of a Meraki switch and non-Meraki, unmanaged switches. After this network refresh, unmanaged switches will no longer be allowed. Any and all unmanaged switches must be removed and their connected devices connected to appropriately configured ports on Meraki managed switches (see page 13)
- The installer will need access to a mobile computer or an iPad with independent internet access in order to activate and configure the new switch(es) in CNM
- All wireless access points (APs) in the meetinghouse must connect directly to a Meraki managed switch. Do not connect old legacy Cisco APs into a Meraki Switch. Upgrade Cisco APs to Meraki APs.
- Order an SFP module when ordering a Meraki Switch.
- If a second Meraki switch is needed in the same meetinghouse then two additional SFP modules will be needed. Same goes for a third Meraki switch if needed
- You will need a screwdriver and wood screws if you are mounting a switch to a wall, cabinet, or rack
- You will need a pen or pencil, tape and paper to create a cable mapping sheet of the meetinghouse data drops
- The Switch installation will be much easier if you have 2 people to identify where each data cable connects. Especially for the Wireless Access Points.
- The Meraki switch(es) installed in a meetinghouse will be logically tied to the Meraki Firewall in the Meraki Cloud Management application.
- Use of the 48-port switch is an exception and should only be used when the number of in-use Ethernet network lines running to a single location exceeds 22. Any 48 port switches will have to be purchased by the FM group as none have been included in this 2025-2026 refresh project
SFP Modules
- Every switch will need a SFP module installed in port SFP 25 on the "24 Port switch" (port SFP 9 on the "8 Port switch" and port SFP 49 on the “48 port switch”)
- If a second Meraki switch is needed in the same meetinghouse then two additional SFP modules will be needed. Install the extra SFP module in Port 26 of the first Meraki 24 Port switch (or port SFP 10/SFP 50 on the first 8 or 48 port switch respectively) to connect the two Meraki Switches.
- To install the SFP module- open the lock, insert the module and close the lock. This will lock the SFP module into the switch.
- Connect the data cable to the SFP modules with the lock closed in the locked position.
- To remove an SFP module- open the lock and remove the module from the switch.
Steps before installing Meraki Managed Switches (MS130-8P,-24P,-48P)
- Using tags or tape, identify and label the following possible cables connecting to:
- Wireless Access Points (tag as AP)
- Clerk’s and unit Leader’s offices (tag as Clerk or BP or SP)
- The HVAC, Door locks, and other Facility devices (tag as HVAC or Locks or FAC)
- Webcast equipment, Audio/Video distribution systems (tag as AV)
- The Family History Center (if present) (tag as FHC)
- The Seminary and Institute Teacher Offices and student classrooms (if present) (tag as S&I)
- FM office, Mission office, etc... (if present) (tag as FM or Mission)
- All other rooms in the meetinghouse (all of these will be public zone)
- This is a great opportunity to determine if all classroom connections are used or needed. If they are no longer used, then leave the cables disconnected to reduce the number of needed switch ports. If you leave a room disconnected, then add a sticker to the data jack faceplate in that room stating that it is disconnected.
- After labeling, take photos of the current configuration to inform the troubleshooting process if problems occur during the new switch installation.
- It is recommended that you leave a sheet of paper with the cable and port mappings next to the switch. This will facilitate future changes to the network. (example: Port 7 on the switch goes to the Clerk’s office, etc. )
Replacing the current Meraki firewall with a Meraki MX67 firewall in CNM
**This procedure should only be performed if a meetinghouse is NOT currently operating with an MX67 firewall.
If there is already an MX67 firewall present, or if the site has been previously upgraded to an MX75, MX85, MX95 or MX105 firewall, skip forward to the switch activation procedure
1. Remove the new Meraki MX67 Firewall from the box and locate its Serial Number(SN) (Cloud ID). Then, log into
Church Network Manager (CNM)
- To access CNM enter http://cnm.churchofjesuschrist.ong into the browser's address bar
- Login to CNM using your Church Account Username and Password
2. Locate the Meetinghouse's page in CNM using the Search function and replace the current firewall with the new
MX67 firewall:
- Choose from the search dropdown which information item you want to use to find the meetinghouse you are working on (see screenshot 1 to the right)
- Once you have entered the search data, press the Search button
- From the results list, select the meetinghouse you are working on (if you search by firewall/device serial number, skip to step 7)
- In the Properties screen that appears, select the appropriate property
- In the next screen, which shows the property you selected, look in the Networks box and select the network which contains the serial number of the currently installed firewall (See Screenshot 2 to the right)
- Use CNM to replace the current firewall with the new MX67 firewall
- On the Network Details screen, press the Menu button at the top right of the screen and select the "Replace (RMA)" item (see screenshot 3 to the right)
- This will bring up a box asking for the serial number of the firewall you want to replace the current firewall with. Insert the serial number of the new MX67 firewall here and press the Save Changes button:
- Walt for the process to complete. Once completed, remove the ISP connection and the connection to the first switch from the old firewall. Connect the ISP connection to the new MX67 firewall's Internet port per the applicable diagram shown previously. Power up the new firewall. Wait for the firewall status light to turn solid white (See steps 1-2 in the "Steps after installing the Meraki Firewall and/or Meraki Switch on page 12 of these instructions)


