
The Cisco Aironet 3802i (AIR-AP3802I-A-K9) was a workhorse. As the flagship indoor model of the Aironet 3800 series, it delivered 802.11ac Wave 2 with a 4x4:3 spatial-stream radio design, integrated mGig (Multigigabit) uplink to break the 1 Gbps barrier on existing cabling, CleanAir spectrum intelligence, and a modular slot for the Hyperlocation or third-radio modules. For a generation of enterprise, campus, and federal deployments it was the default high-density AP. But its lifecycle is now firmly in the past tense, and if you still have these radios on your ceilings, the clock is running down toward a hard support cliff.
This guide lays out exactly where the 3802i sits in its end-of-life timeline, what each milestone means for an operations and compliance team, and why the Catalyst 9130AX (C9130AXI-A) is the correct refresh target rather than a like-for-like spare hunt. You can see the full milestone table on the AIR-AP3802I-A-K9 EoL detail page.
Where the Aironet 3802i sits in its lifecycle
Cisco published the end-of-life bulletin for the Aironet 3800 series years ago, and the key dates for the 3802i are no longer theoretical. End-of-Sale passed on October 31, 2022, so the product can no longer be ordered new through Cisco. End of software maintenance hit on May 1, 2024, which is the milestone most teams underestimate. The final hard stop, Last Date of Support (LDoS), is October 31, 2027.
What each milestone actually means in practice
- End-of-Sale (2022-10-31): Cisco stopped taking new orders. Any 3802i you buy today is refurbished, gray-market, or new-old-stock — none of which extends the support timeline. Whatever you buy still dies on the LDoS date.
- End of SW Maintenance (2024-05-01): This is the security milestone that matters most. After this date Cisco no longer ships maintenance releases or, critically, PSIRT security patches for the 3802i image. A new CVE against the AireOS/IOS-XE code path this AP runs will not be fixed on this hardware. You are frozen on whatever release you last installed.
- Last Date of Support (2027-10-31): The final cliff. After LDoS there is no Cisco TAC, no RMA/hardware replacement, no software downloads, and no entitlement under SmartNet/Cisco Support. A failed AP becomes e-waste with no replacement path, and an open ticket has nowhere to go.
That compliance angle is why "it still works, leave it" is the most expensive option. An auditor does not care that the radio still passes traffic; they care that the device is past software maintenance and cannot be remediated. Unpatchable infrastructure on a regulated network is a finding, and findings carry remediation deadlines that are far less forgiving than a planned refresh.
The recommended replacement: Catalyst 9130AX (C9130AXI-A)
Cisco directs 3802i migrations to the Catalyst 9130AX, and it is a genuine generational jump, not a rebadge. The 9130AX moves from 802.11ac Wave 2 to Wi-Fi 6 (802.11ax), and the difference is architectural, not incremental.
What is concretely better
- Wi-Fi generation: 802.11ax (Wi-Fi 6) versus Wave 2 802.11ac. You gain OFDMA, which subdivides channels so the AP can service many small-packet clients simultaneously instead of serially — the single biggest win for dense IoT, classroom, clinic, and barracks-style deployments where the 3802i choked on client count, not raw throughput.
- Radio design: The 9130AX runs an 8x8:8 / dual 4x4:4 flexible radio architecture with the Cisco RF ASIC, versus the 3802i's 4x4:3SS. Combined with 1024-QAM, BSS coloring, and Target Wake Time, real-world capacity and battery-device efficiency climb sharply.
- Uplink: Both have mGig, but the 9130AX's Multigigabit port (up to 5 Gbps) is matched to Wi-Fi 6 aggregate throughput so the wired side is no longer the bottleneck. Reuse your existing Cat5e/Cat6 — no recabling required.
- Power: The 9130AX wants 802.3at (PoE+) for full functionality and can take advantage of 802.3bt on capable switches. Confirm your switch PoE budget; this is the most common refresh gotcha (see migration plan below).
- Licensing model: This is the operational shift. The 3802i lived in the AireOS controller world. The 9130AX runs on the Catalyst 9800 controller (physical, virtual, or embedded) or Meraki cloud management, and is licensed under Cisco DNA / Smart Licensing (Cisco Networking Subscription) with DNA Essentials or Advantage tiers rather than perpetual right-to-use. Budget for the subscription term, not just the hardware.
- Management: You move from a legacy WLC/Prime model to Catalyst 9800 + Cisco Catalyst Center (formerly DNA Center) or to Meraki dashboard. Either path gives you assurance, AI-driven RRM, and application visibility the 3802i era never had.
A practical migration plan
1. Assessment and inventory
Pull an accurate count of 3802i units and their locations, then capture the current WLC platform and code train, SSID/WLAN profiles, RF profiles, AP groups, and any FlexConnect or office-extend configs. A predictive or validated RF survey is worth doing because Wi-Fi 6 channel planning (especially 80/160 MHz width decisions and BSS coloring) differs from how you tuned the Wave 2 fleet.
2. License and controller transition
Stand up the Catalyst 9800 (the 9800-CL virtual controller is the low-friction path for most sites) and a Cisco Smart Account / Virtual Account for license assignment. Map your old perpetual AP entitlements to DNA Essentials or Advantage subscription seats. Decide term length up front — federal buyers often align this to the period of performance or a 3/5-year refresh cycle.
3. Config and feature parity
Recreate WLANs, policy profiles, RF profiles, and AAA/RADIUS integration on the 9800. The 9800 uses a policy-tag / site-tag / RF-tag model that does not map 1:1 from AireOS, so plan to rebuild rather than import. Validate 802.1X/WPA3 posture, mDNS/Bonjour gateway behavior, and any guest/web-auth flows before cutover.
4. Physical: power, uplinks, mounting
Confirm each access switch can deliver PoE+ (802.3at) to every 9130AX position and that the cumulative PoE budget covers a fully loaded switch — this is where refreshes stall. The 9130AX reuses the standard Cisco mounting bracket family and existing Ethernet drops in most cases, so cabling is rarely the constraint; power and switch capacity usually are. If you are also refreshing access switches, fold that into the same project.
5. Phased cutover
Run new and old in parallel where possible: deploy 9130AX APs on the 9800 in a pilot zone (one floor, one wing), validate client roaming and throughput, then sweep building by building. Keep the 3802i fleet live until each zone is proven, then decommission in batches rather than a single risky weekend cutover.
6. Secure decommission
Wipe AP and controller configurations, remove devices from the Smart Account and monitoring, update CMDB and cable records, and dispose through a certified ITAD or DoD-compliant sanitization process. Retain disposition records for your audit trail.
Procurement notes for government and enterprise buyers
Source the Catalyst 9130AX from an authorized Cisco partner so the hardware carries valid entitlement, a genuine warranty, and full TAA compliance for federal contracts. Buying gray-market or end-of-sale 3802i spares to limp along fails on both the support cliff and, often, TAA documentation. Uniqcli is an authorized partner: we provide TAA-compliant sourcing, accept the Government Purchase Card (GPC) for in-threshold orders, and can scope the 9800 controller and DNA subscription alongside the APs as a single quote. Plan for current Wi-Fi 6 AP lead times and order controllers and licenses in the same cycle so nothing arrives orphaned.
You can browse the replacement in our catalog, review related lifecycle notices on the Cisco EoL hub, and when you are ready to scope the refresh, get a quote and we will build a 3802i-to-9130AX migration package with controller, licensing, and TAA documentation included.
Frequently asked questions
When does the Cisco Aironet 3802i (AIR-AP3802I-A-K9) reach end of support?
End-of-Sale passed on October 31, 2022, software maintenance (including PSIRT security patches) ended May 1, 2024, and the final Last Date of Support is October 31, 2027. After LDoS there is no Cisco TAC, RMA, or software access for the 3802i.
What is the recommended replacement for the Aironet 3802i?
Cisco directs migration to the Catalyst 9130AX (C9130AXI-A), a Wi-Fi 6 (802.11ax) indoor AP. It upgrades from the 3802i's Wave 2 4x4:3SS design to an 8x8/dual-4x4 radio with OFDMA, 1024-QAM, BSS coloring, and a 5 Gbps mGig uplink, dramatically improving high-density client capacity.
Can a Catalyst 9130AX join my existing Aironet wireless controller?
No. The 9130AX cannot join a legacy AireOS WLC. It requires a Catalyst 9800 controller (9800-CL virtual, 9800-40/80, or embedded) or Meraki cloud management. If you are still on AireOS, the AP refresh must include a controller migration.
How does licensing change when moving from the 3802i to the 9130AX?
The 3802i used the AireOS perpetual right-to-use model. The 9130AX uses Cisco DNA / Smart Licensing (Cisco Networking Subscription) with DNA Essentials or Advantage tiers, managed through a Smart Account. Budget for the subscription term, not just the hardware.
Do I need to recable or upgrade switches to deploy the 9130AX?
Cabling is rarely the issue — the 9130AX reuses existing Cat5e/Cat6 drops via its mGig port and standard Cisco mounts. The common constraint is power: the 9130AX needs 802.3at (PoE+) for full function, so verify each access switch's per-port and total PoE budget before deployment.
Is buying a refurbished Aironet 3802i a viable way to extend our network?
No. Any 3802i, new or used, still hits the October 31, 2027 LDoS and is already past software maintenance, so it cannot receive security patches. Gray-market units also often lack TAA documentation, which fails federal procurement requirements. Refresh to the 9130AX instead.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read