Networking · Concept · 10 min read

Cloud Managed Networking, and What Happens When You Stop Paying

The dashboard is the easy part. The clause that matters is what the hardware does when the license lapses, and on that the vendors differ completely: one shuts the network down, one keeps it running unmanaged, one has no license at all.

Written by Marko Ristic, Editor Updated Sep 17, 2026
30days of grace on Meraki before shutdown or disabled management
8 hrsbefore a Meraki MX on firmware 17 reboots without dashboard contact
90days after Mist expiry when Juniper can go read-only or end access
$0license cost of UniFi OS Server and UniFi Site Manager
Short answer

Cloud managed networking moves the management of switches, access points and firewalls into the vendor’s cloud, while traffic stays on the local network. The difference between platforms is the license.

On Meraki co-termination licensing the network is shut down after a 30-day grace period; on Meraki subscription licensing devices keep forwarding traffic but cannot be managed; Juniper Mist keeps operating without support; UniFi has no license.

  • The management plane is in the cloud; client traffic does not pass through it
  • Losing the internet link leaves devices running their last configuration
  • Meraki co-term: shut down after 30 days unlicensed; subscription: runs, unmanaged
  • Juniper Mist keeps the network operating after expiry, without support
  • UniFi and the self-hosted UniFi OS Server carry no license fee
On this page

The splitWhat moves to the cloud, and what stays on site

Cloud managed networking is easiest to understand as a split between two jobs every network does, which are easy to confuse. The data plane moves packets between users, servers and the internet.

The management plane is where someone configures the switches, sets the network security policies, sees which access point is overloaded, and pushes a firmware update. Cloud managed networking moves the second job into the vendor's cloud and leaves the first on site, which is why it is also called cloud-based network management.

Cisco Meraki's documentation states the design plainly: the Meraki cloud uses an out-of-band architecture, and no client data flows through the cloud. The devices hold their configuration locally and talk to the cloud for management. That has two practical consequences.

An internet outage does not take the office network down. When a device loses its connection to the Meraki cloud, whether because the site's WAN link failed, a Meraki data center is down or a routing problem sits in between, it keeps running with its last configuration.

Meraki also says its network fails over to another data center if one has an outage.

Management does go down with the link. While the cloud is unreachable nobody can change the configuration or see monitoring from the dashboard, and devices have to fall back on a local status page.

The details are specific: Meraki's MX security appliances on firmware 17 and later reboot after eight hours without dashboard connectivity to support self-healing, and an MX that loses the dashboard while its latest configuration is not yet "safe", meaning it has not run for 30 minutes without a reboot since the change, reverts to the previous safe configuration.

How it worksHow a cloud managed network works

The mechanics of cloud managed networking are the same across vendors, whatever the dashboard is called.

1. Claim. An administrator adds the device to the organization in the cloud dashboard, usually by serial number, and assigns it to a network and a configuration template. 2. Connect. On site, the device gets an address from DHCP and opens an encrypted outbound connection to the vendor's cloud.

Nothing has to be opened inbound on the firewall. 3. Configure. The device downloads its configuration and firmware. This is zero touch provisioning: whoever plugs it in needs no networking knowledge. 4. Report.

The device sends status, client and performance data to the cloud, which turns it into the monitoring views, alerts and reports. 5. Change. Every later change is made once in the dashboard and pulled down by the devices, at one site or at all of them.

The cloud holds the intended configuration and the devices hold a working copy. That is why cloud managed networks keep forwarding traffic when the link to the cloud is lost, and why a replacement device can take over the old one's configuration in minutes.

BenefitsBenefits of cloud managed networking, and who it suits

The benefits are about labor and control more than about network performance. The switches and access points forward traffic the same way under either model.

  • Centralized management. One dashboard for switches, WiFi, firewalls and every site, instead of one controller per location.
  • Remote troubleshooting. An engineer can see a client's connection history, check a switch port or restart a device without travel time.
  • Visibility. Usage, performance and client data for all networks in one place, with alerts when a device goes offline.
  • Scalability. Adding a site means adding devices to a template, not building another controller.
  • Automatic updates. Firmware and security fixes are scheduled centrally and applied in a maintenance window.
  • Predictable cost. Spending moves from a controller purchase to a subscription, for better and for worse, as the license section below explains.

Cloud-based management suits organizations with many small networks and few network staff: retail chains, schools, hotels, clinics, branch offices, and the MSPs that manage networks for them. It suits a single large campus with its own network team less, because that team already has the control the dashboard offers.

Against controllersCloud managed against controller-based networking

The alternative is a controller-based network: a controller you run yourself, either an appliance on site or software on a server in your own infrastructure, which pushes configuration to the access points and switches and collects their data.

What the cloud removes. There is no controller infrastructure to patch, back up or replace, and the centralized dashboard gives remote access to every site from anywhere, which is how small businesses with no IT staff on site end up with a network someone can actually manage.

New devices can be added to the dashboard and given a template configuration before anyone opens the box on site, which is the real advantage for a company with many small branches. Firmware updates are scheduled from one place.

What the cloud adds. A dependency on the vendor's service and on the site's internet connection for network management, a recurring license for every device, and configuration and monitoring data held by the vendor.

Organizations give up some direct control over the management infrastructure in exchange for not having to run it. For a single office with one IT person nearby, the controller-based model is not worse, just different. For a provider looking after forty small sites, cloud management usually wins on labor alone.

The line is blurring. Cisco now sells some next-generation hardware, including its C9350 and C9610 smart switches and CW9176 and CW9178 Wi-Fi 7 access points, with unified licenses that can be managed in cloud mode through the Meraki dashboard, on premises, or in a mixed mode.

That choice is available only on its subscription licensing, and term licenses for that hardware are cloud-only.

License expiryWhat happens when the license ends

This is the section to read before buying, because the license terms decide what an organization owns when it stops paying.

Cisco Meraki, co-termination and per-device licensing. Every active device in a network needs a license. When an organization is over its licensed device count or its licenses expire, it enters a 30-day grace period, and if it is not brought back into compliance it is shut down until proper licensing is applied.

Under the older per-device model, Meraki shuts down only the individual device whose license expired, again after 30 days. Meraki's documentation describes the co-termination outcome as a network shutdown, and its newer subscription documentation contrasts itself with the previous model's shutdown procedure.

Cisco Meraki, subscription licensing. The newer model follows a one-to-one device-to-license policy. After a subscription ends and its 30-day grace period passes, the networks bound to it enter a disabled management state.

Meraki lists what that means: devices keep their last license-compliant configuration and continue to function and forward data traffic, but administrators lose the ability to configure them through the dashboard or API, configuration and monitoring data are no longer displayed, customer-initiated firmware updates stop, and support ends. Meraki now offers subscription and co-termination to new customers; new conversions to per-device licensing are no longer accepted.

Juniper Mist. Mist's documentation answers the question directly: the Mist cloud does not disconnect access points when a subscription expires, and the network continues to operate. No support is provided for expired subscriptions, and Juniper reserves the right to disable access to the portal or terminate the organization dashboard; after 90 days it can give read-only access or terminate access.

Ubiquiti UniFi. There is no device license. UniFi's self-hosted UniFi OS Server is, in Ubiquiti's words, completely license-free, and its Site Manager for multi-site management is license-free too. Ubiquiti sells Official UniFi Hosting as a paid alternative to running the controller yourself.

TP-Link Omada. TP-Link describes a free cloud management tier, Essentials, alongside a licensed Standard tier with more features and support.

The practical reading is that "cloud managed" covers everything from a network that stops passing traffic when unpaid to one that has never had a license. None of these terms is hidden, and all of them are easy to miss when the quote shows the hardware price first.

CostWhat cloud managed networking costs over the life of the hardware

Because the license is annual or multi-year per device, the useful number is the total over the years you expect to keep the hardware, not the purchase price.

Count licenses per device, including spares in service. Meraki's documentation notes that only devices in a network need a license, so a spare switch kept in inventory does not consume one, while a warm spare pair of switches does need two. Its security appliances in a warm spare pair need only one.

Price the renewal, not just the first term. A three-year term bundled with new hardware is a different number from the renewal three years later, and it is the renewal that decides whether the hardware stays in service.

Put the end state in the budget. On a model that shuts down or loses management at expiry, the hardware has no useful life beyond the license. On a license-free platform, the cost after purchase is the time of whoever maintains it.

For an MSP the calculation includes one more line: the hours saved by managing every client network from one dashboard, which is often the reason cloud managed networks pay for themselves for the businesses that use them.

SecuritySecurity on a cloud managed network

Moving the management plane to the cloud changes where network security depends on the organization and where it depends on the vendor. Cloud network management does not make networks more or less secure by itself.

The dashboard is the new perimeter for management. One login controls the configuration of every switch, access point and firewall across every site. Protect it with multi-factor authentication, give administrators the narrowest role that works, and remove accounts when people leave. For businesses that use an MSP, the provider's technicians should have their own named accounts, not a shared login.

Firmware is easier to keep current. A central dashboard shows which devices run which firmware and schedules updates across sites, which removes the most common reason network infrastructure goes unpatched: nobody remembered it was there.

Policy is consistent by default. Firewall rules, VLAN segmentation and wireless security settings applied from templates are the same at every site, which is harder to achieve with a controller per location. The same consistency means one wrong change reaches every site at once, so review changes before pushing them.

The data held by the vendor. Configuration, device inventory and client monitoring data sit in the vendor's cloud. Organizations with data residency requirements should check where the vendor hosts it before signing.

ChoosingChoosing a cloud managed network

How many sites, and who is near them? Many small sites with nobody technical on hand favor cloud-based management and remote control of the network. One site with an IT person down the hall does not need it.

What does the contract say at expiry? Shutdown, unmanaged but running, or no license at all. Get the answer in writing from the vendor's own documentation, as quoted above, not from the reseller.

Who holds the dashboard, and who controls security? If an MSP runs the network, the organization and licenses should be in the client's name, with the provider as an administrator, so that changing providers does not mean re-licensing the hardware.

Does the site need management during an internet outage? If yes, find out what local access the devices offer when the cloud is unreachable.

How does it fit the rest of the stack? Firewalls, SD-WAN, switching and wireless from one dashboard is the strongest argument for a single vendor. Monitoring across mixed vendors is the job of network management software.

PitfallsWhere people go wrong

Letting licenses lapse on co-term hardware. Thirty days after expiry an out-of-compliance organization is shut down, and with it the network security and connectivity it provided. Put the expiry date in the same calendar as the domain renewals.

Adding one more device than the license covers. On Meraki co-termination, exceeding the licensed device count also starts the 30-day clock, for the whole organization.

Buying hardware from one reseller and licenses from another without checking the model. An organization can have only one licensing model, and moving from subscription back to co-termination is not supported.

Registering the dashboard to the MSP. The client pays for the hardware and licenses and then needs the old provider's cooperation to move them.

Assuming the cloud carries the traffic. It does not on Meraki's design, which is good news for outages and means bandwidth planning and on-site network security, such as the firewall rules on the appliance itself, still matter.

Ignoring the local fallback. Know how to reach a device's local status page before the WAN link fails, not after.

THE DAY THE LICENSE LAPSES, AND THE DAY THE GRACE ENDSDAY 0: LAPSESDAY 30: GRACE ENDSMERAKI CO-TERMRuns normallyNETWORK SHUT DOWNMERAKI SUBSCRIPTIONRuns normallyTRAFFIC FLOWS, NO MANAGEMENTJUNIPER MISTKeeps operatingRUNS, NO SUPPORT, PORTAL AT RISKUNIFINo licenseNOTHING CHANGESFrom each vendor’s own licensing documentation, read September 11, 2026.
Every platform runs normally the day its license lapses. They part ways when the 30-day grace period ends, and one of them never had a license to lapse.

ComparisonWhat each platform does when its license ends

CriterionMeraki co-termMeraki subscriptionJuniper MistUniFi
License per deviceYesYes, one to oneYesNo
Grace period30 days30 days30-day alertsNo license to lapse
Traffic after expiryNo, network shut downYesYesUnaffected
Configuration after expiryNoNoNo once the portal is disabledUnaffected
Monitoring after expiryNoNoNo once the portal is disabledUnaffected
Firmware updates after expiryNoNo, not customer-initiatedNot statedUnaffected
Vendor support after expiryNoNoNoNot tied to a license
Self-hosted optionNoNext-gen hardware, on-prem modeNot in the pages readYes, UniFi OS Server

The traffic row is the one most buyers never ask about. The configuration row is the one that matters six months after a lapse, when something needs to change.

FAQFrequently asked questions

What is cloud managed networking?

A network whose switches, access points and firewalls are configured, monitored and updated from the vendor's cloud dashboard instead of an on-site controller. The traffic stays on the local network; only management moves to the cloud.

Does traffic go through the cloud on a cloud managed network?

Not on Meraki's design, which Meraki describes as out of band, with no client data flowing through the cloud. Check each vendor, but management-only is the common architecture.

What happens if the internet goes down?

Devices keep running their last configuration, so the local network and any other WAN path keep working. Management and monitoring from the dashboard are unavailable until the link returns.

What happens when a Meraki license expires?

On co-termination licensing, the organization gets a 30-day grace period and is then shut down until licensing is restored. On subscription licensing, after 30 days the network enters disabled management: devices keep forwarding traffic, but configuration, monitoring, firmware updates and support stop.

Do Juniper Mist access points stop working when the subscription expires?

No. Mist's documentation says the network continues to operate. Support stops, and Juniper can disable portal access or terminate the dashboard; after 90 days it can give read-only access or terminate access.

Is UniFi cloud managed without a subscription?

Yes. Ubiquiti's UniFi OS Server for self-hosting and its Site Manager for multi-site management are license-free. Official UniFi Hosting is a paid option for those who do not want to run the server.

Is cloud managed networking more expensive?

The difference is the recurring per-device license. Compare the total over the years you will keep the hardware, including renewals, against the time a self-managed controller takes.

Can a cloud managed network be managed on premises instead?

Some can. Cisco's next-generation smart switches and Wi-Fi 7 access points with unified subscription licenses can run in cloud, on-premises or mixed mode. Most cloud-first platforms cannot.

Do spare devices need a license?

On Meraki, only devices in a network need one; a spare left in inventory does not. A warm spare pair of switches needs two licenses, a warm spare pair of security appliances one.

Who should own the dashboard when an MSP runs the network?

The client. The organization and licenses should be registered to the business, with the MSP added as an administrator, so the hardware stays usable if the provider changes.

Is cloud managed networking secure?

It can be more consistent than managing each site separately, because security policies and firmware updates come from one place. The dashboard login becomes a control point for every site on the network. Protect it with multi-factor authentication, limit administrators, and review the audit log.

What are cloud managed WiFi and cloud managed switches?

Cloud managed WiFi and cloud managed switches are access points and switches configured from a vendor's web dashboard instead of a local controller. Traffic still flows locally. Only management and monitoring go to the cloud, which is why a site keeps working when its internet connection drops.

Cloud vs on-premises controller: which is better?

A cloud controller suits organizations with many small sites and few network staff, because there is nothing to install or patch. An on-premises controller suits sites that cannot depend on a vendor's cloud or an ongoing subscription. The deciding factor in the cloud vs on-premises controller choice is usually licensing, not features.

What happens at Meraki license expiration?

Cloud managed network licensing is a subscription, so the hardware depends on it. With Meraki's co-termination licensing, license expiration starts a 30 day grace period, after which the organization is shut down until licenses are renewed. Other vendors keep forwarding traffic and only remove management. Read the licensing terms before you buy.

Read next · Tools Network Management Software, and the Three Questions It Has to Answer Monitoring across mixed vendors, which a single-vendor cloud dashboard does not do. Open this next11 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.