Cisco Aironet 3702i (AIR-CAP3702I-A-K9) Refresh Guide
The Aironet 3702i hit Last Day of Support on April 30, 2024 — here is how to migrate this Wave 1 flagship AP to the Wave 2 3802i or Wi-Fi 6 Catalyst 9130AX without breaking your WLC or your compliance posture.

If you still have Cisco Aironet 3702i access points (PID AIR-CAP3702I-A-K9) hanging from your ceilings, they are now running on borrowed time. As of April 30, 2024, the entire Aironet 3700 series reached its Last Day of Support. There is no longer a Cisco safety net behind these radios — no security fixes, no software, no replacement hardware. This guide walks through exactly what that means for the 3702i specifically, what you gain by moving to the Wave 2 Aironet 3802i or the Wi-Fi 6 Catalyst 9130AX, and how to run the refresh cleanly on a controller-based network.
What the 3702i actually was
The 3702i was Cisco's flagship indoor enterprise AP for the 802.11ac Wave 1 era. It ran a 4x4:3 radio design — four antennas, three spatial streams — topping out at 1.3 Gbps PHY on 5 GHz. It carried Cisco CleanAir for spectrum analysis, ClientLink 3.0 beamforming, and a modular expansion slot for the 802.11ac wireless security/monitoring or hyperlocation modules. It was powered by 802.3at PoE+ and connected over a single 1 GbE uplink. For 2014, it was top of the line. For 2026, every one of those headline numbers is a bottleneck.
Why the dates matter, and why now
Cisco publishes three milestones for every product. Read them as a countdown, because that is how they behave in practice.
- End of Sale (2019-04-30): Cisco stopped selling new 3702i units. Any unit bought after this came from channel stock or the secondary market.
- End of Software Maintenance (2020-04-29): The last maintenance and bug-fix releases shipped. After this date, no new AireOS or IOS-XE images carry fixes for 3702i-specific defects.
- Last Day of Support / LDoS (2024-04-30): The hard wall. Cisco TAC will not open cases, RMA replacement is gone, and — critically — PSIRT will not issue patches for new vulnerabilities affecting these APs.
That last point is the one auditors care about. Once an AP is past LDoS, any future CVE in its driver, supplicant, or management stack is permanent and unpatchable. For FedRAMP, CMMC, HIPAA, PCI-DSS, and most DoD ATO frameworks, running gear that can no longer receive security updates is a finding waiting to happen. You can compensate with segmentation, but you cannot make the underlying exposure go away. You can see the full milestone record for this PID on its 3702i end-of-life detail page, and check your other models against the EoL hub.
The recommended replacement, and what you actually gain
Cisco's bulletin names the Aironet 3802i (AIR-AP3802I-A-K9) as the direct successor. It is the like-for-like flagship swap and the simplest migration. Buyers planning for the next decade, however, are generally jumping straight to the Catalyst 9130AX (Wi-Fi 6). Both are real, defensible choices — here is the difference.
Option A: Aironet 3802i (802.11ac Wave 2)
- 4x4:4 radio design — a fourth spatial stream over the 3702i's three, plus downlink MU-MIMO so the AP talks to multiple clients simultaneously instead of round-robin.
- Up to ~5.2 Gbps aggregate data rate versus the 3702i's 1.3 Gbps on 5 GHz — roughly triple the air-side capacity.
- Flexible Radio Assignment (FRA): the AP can split into dual 5 GHz radios in high-density zones, something the single-5 GHz 3702i physically cannot do.
- Cisco mGig / Smart Rate uplink (2.5/5 Gbps over existing Cat5e/Cat6), removing the 1 GbE wired ceiling that the 3702i could hit.
- Retains CleanAir and the modular slot; 802.3at PoE+. Same mounting footprint and AireOS familiarity for a near drop-in swap.
Option B: Catalyst 9130AX (Wi-Fi 6 / 802.11ax)
- 802.11ax adds OFDMA and uplink + downlink MU-MIMO — the single biggest efficiency gain for rooms full of small, chatty IoT and mobile clients, where the 3702i wastes airtime.
- 8x8 (or 4x4 dual-band) radio architecture with Target Wake Time for battery-powered endpoints.
- mGig 5 Gbps uplink, 802.3bt-capable, and an integrated IoT radio for BLE.
- Runs natively on the Catalyst 9800 controller and Cisco DNA Center / Catalyst Center, putting wireless under the same assurance and analytics umbrella as your switching.
- Far longer support runway — you are buying years of headroom rather than refreshing into another platform that is itself mid-lifecycle.
A practical migration plan
1. Assess and inventory
Export your AP list from the WLC (show ap summary) and capture each 3702i's name, MAC, AP group, RF profile, mounting location, switchport, and PoE class. Note which units carry expansion modules. Pull a heatmap or AP-on-a-stick survey if your density requirements have changed since the original install — Wave 2 and Wi-Fi 6 cells behave differently and you may be able to thin out APs or, conversely, need more for capacity.
2. License and controller transition
Stand up or confirm a Catalyst 9800 controller (physical, virtual, or embedded) if you go the 9130AX route — the 3702i cannot share a controller with 9130AX on modern code, so plan a parallel WLC during cutover. Create the Smart Account, order the matching DNA/Networking subscriptions, and pre-stage AP join profiles and country/regulatory domain settings (note the -A regulatory domain on your existing PID — order the replacements in the correct domain).
3. Config and feature parity
Map every 3702i policy forward: SSIDs, WPA2/WPA3 modes, RADIUS/ISE integration, FlexConnect vs local mode, mDNS, RF profiles, and CleanAir thresholds. WPA3 and Enhanced Open are genuinely new capabilities on the replacements — decide now whether to adopt them during the refresh or after. Validate that any module-dependent feature (e.g. hyperlocation) has an equivalent on the new platform before you decommission.
4. Physical: power, uplinks, optics
- PoE budget: confirm switches deliver 802.3at (and ideally 802.3bt for the 9130AX at full power). An older switch capping at 802.3af will brown-out a Wave 2 / Wi-Fi 6 AP into reduced-power mode.
- Uplink speed: the 3702i's 1 GbE ports leave mGig on the table. To realize the 2.5/5 Gbps uplink, you may need mGig access switches (Catalyst 9300 with mGig ports). Plan that as part of the wireless refresh, not after.
- Cabling: existing Cat5e generally carries 2.5 Gbps fine; verify runs for 5 Gbps. Mounting brackets differ — order the AIR-AP-BRACKET equivalents if you are not reusing existing mounts.
5. Phased cutover
Do not big-bang a building. Convert one floor or wing at a time: join the new APs to the new controller/AP group, let RRM settle, validate client roaming and authentication against ISE, then decommission the matching 3702i units. Run both old and new in overlapping coverage for a few days so you can fall back instantly if an SSID or policy behaves unexpectedly.
6. Secure decommission
Reset each retired 3702i to factory defaults to clear stored controller info, PSKs, and certificates before the unit leaves your control. For DoD/federal environments, follow your media-sanitization SOP and document chain of custody. Past LDoS hardware has effectively zero trade-in value but real disposal obligations — track it through your property-disposal process.
Procurement notes for government and enterprise buyers
- TAA compliance: confirm country of origin on the replacement APs for GSA Schedule, DoD, and SLED contracts — an authorized partner can document this per shipment.
- GPC / purchase-card payments and quotes structured to your contract vehicle are standard for a refresh of this size.
- Lead times: enterprise APs and matching DNA subscriptions can carry multi-week lead times; order ahead of any audit deadline rather than after a finding.
- Buy from an authorized Cisco partner so warranty, Smart Licensing entitlement, and TAC eligibility attach cleanly to your Smart Account — secondary-market APs frequently arrive without transferable support.
You can browse the 3802i and Catalyst 9130AX alongside matching switches and licensing in our catalog, or have us scope the swap directly. When you are ready to size the refresh, get a quote with your AP count and controller details and we will return a TAA-compliant, GPC-payable bill of materials with the right regulatory domain and subscription tier.
Frequently asked questions
Is the Cisco Aironet 3702i (AIR-CAP3702I-A-K9) still supported?
No. The 3702i reached Last Day of Support on April 30, 2024. Cisco TAC will not open cases, there is no RMA replacement, and PSIRT will not patch new vulnerabilities affecting it. Software maintenance ended back on April 29, 2020.
What is the direct replacement for the 3702i?
Cisco's bulletin names the Aironet 3802i (AIR-AP3802I-A-K9), the Wave 2 flagship, as the direct successor. It adds a fourth spatial stream, downlink MU-MIMO, Flexible Radio Assignment, and an mGig uplink. Buyers refreshing for the long term typically move to the Wi-Fi 6 Catalyst 9130AX instead.
Can I keep my existing controller when I upgrade?
It depends. The 3802i can run on AireOS controllers similar to the 3702i, making it the simpler swap. The Catalyst 9130AX requires a Catalyst 9800 controller and Catalyst/DNA Center, so plan a parallel WLC during cutover — the 3702i and 9130AX cannot share a controller on current code.
Do the replacements need new switches or cabling?
Possibly. The 3702i used a 1 GbE uplink and 802.3at PoE+. To use the 3802i or 9130AX mGig uplink (2.5/5 Gbps) you may need mGig access switches, and the 9130AX prefers 802.3bt power. Existing Cat5e usually carries 2.5 Gbps; verify runs for 5 Gbps.
How much more capacity do I actually get?
The 3702i tops out at 1.3 Gbps on 5 GHz with no MU-MIMO. The 3802i reaches roughly 5.2 Gbps aggregate with downlink MU-MIMO and dual-5 GHz FRA — about triple the air capacity. The 9130AX adds OFDMA on top, which is the bigger real-world win in dense, mixed-client environments.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read