Cisco 2504 WLC EoL: Migrate to 3504 or Catalyst 9800
The 2504 Wireless Controller passed Last Day of Support on April 30, 2023 — here's what each milestone means, why an unpatched AireOS controller is now a compliance liability, and how to migrate cleanly to a Catalyst 9800.

If a Cisco 2504 Wireless Controller (PID AIR-CT2504-K9) is still terminating CAPWAP tunnels in a branch closet, it is now past every Cisco lifecycle milestone that matters. The 2504 reached its Last Day of Support on April 30, 2023. From that date Cisco provides no software images, no PSIRT security fixes, and no TAC support or RMA hardware replacement for this platform. The box keeps brokering access points and passing client traffic, which is precisely why these small controllers persist in production long after they should have been retired. This guide explains what the end-of-life dates actually mean for a live wireless service, why the 3504 the bulletin named is itself a dead end in 2026, and how to plan a clean migration to a current Catalyst 9800 controller.
What the 2504 actually was
The 2504 (AIR-CT2504-K9) was Cisco's entry-level, branch-class AireOS Wireless LAN Controller. It is a small fanless appliance with four 1 Gigabit Ethernet ports (two of which can deliver 802.3af PoE to directly power a pair of access points), roughly 1 Gbps of aggregate throughput, and a hard ceiling of 75 access points and around 1,000 clients. AP capacity was sold in right-to-use increments — 5, 15, 25, 50, and 75 AP licenses — that you activated on the controller itself. Critically, the 2504 has no high-availability option: there is no AP SSO, no N+1 failover, no redundancy port. It is a single box, and when it dies, the wireless service in that building dies with it until someone restores a configuration onto replacement hardware.
For a 2014-era branch running a handful of 802.11n or early 802.11ac access points, the 2504 was correctly sized. The problem in 2026 is twofold: the hardware is unsupported, and the AireOS software train it runs cannot manage modern Wi-Fi 6/6E access points at all. The 2504 ages out the controller and strands the APs hanging off it in the same motion.
Why acting now matters
The dangerous thing about an end-of-life controller is not that it fails — it is that it keeps working while the support floor disappears beneath it. After LDoS, three exposures compound:
- No PSIRT security patches. When a new AireOS or CAPWAP vulnerability is disclosed, the 2504 will never receive a fixed image — its software train was frozen at the 2019 maintenance cutoff. A controller sees every client's authentication and sits inline on management traffic, so an unpatchable WLC is a high-value, permanently exposed target, not a peripheral device.
- No TAC or RMA. A failed 2504 cannot be opened as a support case or swapped under a contract. Because the platform has no HA, recovery means a cold rebuild onto a spare you bought before LDoS or a same-model unit from the secondary market — both of which put you right back on dead-end hardware.
- Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under — FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS, and CISA BOD directives — expect supported, patchable infrastructure carrying credentials. An unsupported controller that cannot be patched is an audit finding waiting to happen, and 'the vendor no longer ships fixes' is not a defensible remediation plan.
What each milestone means in practice
- End of Sale (2018-04-18): the last day Cisco accepted new 2504 orders. Everything since has been consuming the support tail.
- End of Software Maintenance (2019-04-18): the last day Cisco released maintenance and bug-fix images. After this, even non-security defects go unfixed and no newer AP models can be added to the supported matrix.
- Last Day of Support / LDoS (2023-04-30): the hard wall. No TAC, no RMA, no patches of any kind. The controller is entirely on its own.
The replacement path: 3504, and why you should look past it to Catalyst 9800
Cisco's EoL bulletin steered 2504 customers to one of two places: Cisco Mobility Express (a controller function embedded on a capable access point, which suits the smallest sites and removes the dedicated appliance entirely) or the Cisco 3504 Wireless Controller (AIR-CT3504-K9). The 3504 is a genuine step up from the 2504 — it roughly doubles AP scale to 150 APs and 3,000 clients, adds a 5 Gbps multigigabit (mGig) port alongside Gigabit uplinks for ~4 Gbps of real throughput, and crucially supports N+1 high availability so a branch is no longer one chassis failure away from an outage.
The right target for a 2504 refresh in 2026 is the Cisco Catalyst 9800 family on IOS-XE — specifically the Catalyst 9800-L (C9800-L-F-K9, fiber or copper mGig uplinks) for branch and midsize sites, the virtual 9800-CL for private cloud or data center hosting, or an Embedded Wireless Controller running directly on Catalyst 9100 access points for the smallest footprints. Compared with the 2504, the 9800-L scales far higher (on the order of 250 APs and 5,000 clients), supports stateful switchover (SSO) high availability so failover is sub-second rather than a cold rebuild, and is the only path that manages current Wi-Fi 6 (Catalyst 9115/9120/9130) and Wi-Fi 6E/7 access points. Moving to IOS-XE also unifies the controller onto the same operating system and Catalyst Center / Cisco DNA Center management plane as your switching, which the AireOS 2504 never touched.
Licensing: the model has changed completely
This is the single most-missed line item. The 2504 used AireOS right-to-use AP-count licenses activated on the box. The Catalyst 9800 uses Cisco Smart Licensing with Cisco DNA / Network subscriptions (Essentials or Advantage tiers) tracked through a Smart Account, typically reported via Smart Licensing Using Policy (SLUP) or an on-prem Smart Software Manager satellite for air-gapped and federal environments. You are now buying a subscription term, not a perpetual AP count. Provision the Smart Account and stage entitlements before any AP is migrated, or APs will join but fail to license cleanly.
A practical migration plan
1. Assessment and inventory
Pull an exact account of the 2504: current AireOS version, activated AP-license count, every associated access point with model and CAPWAP mode (local vs. FlexConnect), WLAN/SSID definitions, RF profiles, AAA/RADIUS servers, mobility groups, and the four physical port assignments. Flag any access points that are themselves EoL — many 2504-era APs (1600/2600/3600/1700-series) are also unsupported and should be refreshed in the same project rather than carried forward onto the new controller, which likely will not support them anyway.
2. Controller selection and license transition
Choose the target now: a hardware 9800-L for a branch that wants a local appliance, a 9800-CL virtual instance if you have hypervisor capacity, or an Embedded Wireless Controller on a Catalyst 9100 AP for a true small site. Stand the new controller up in parallel, create or attach the Smart Account, and load DNA/Network subscriptions before touching production. Do not attempt an in-place AireOS-to-IOS-XE upgrade — there is no such path; this is a parallel build and cutover.
3. Config and feature parity
Rebuild WLAN profiles, security policies (move WPA2 to WPA3 and Enhanced Open where posture allows — capability the AireOS 2504 lacked), 802.1X/RADIUS, AAA, FlexConnect groups, and RF profiles on the 9800. The IOS-XE configuration model differs structurally from AireOS, so treat this as a translation rather than a copy. Cisco's AireOS-to-9800 config conversion tooling can seed the build, but validate every policy by hand and run a documented parity diff against the 2504 before cutover so nothing silently drops.
4. Physical: power, uplinks, optics, and PoE
The 2504 powered two APs directly off its PoE ports; the 9800 does not power APs, so confirm your access switches have the PoE+/UPOE budget for the new AP fleet. Plan the controller's uplinks for mGig (the 9800-L offers copper or SFP fiber variants — order the right optics) and verify your access-layer cabling is Cat6/6A so you do not re-cap Wi-Fi 6 throughput at the wire. Rack power and space are trivial for the 9800-L, but a virtual 9800-CL needs allocated vCPU, memory, and a management VLAN reserved up front.
5. Phased cutover
Migrate by site or zone, never the whole estate at once. Repoint a small set of access points to the new controller (a primary-controller change or a DHCP Option 43 / DNS update), validate client onboarding across device types, run a post-cutover RF check, then proceed. Keep the 2504 live and reachable until each zone is confirmed so rollback is a controller-address change, not a rebuild.
6. Secure decommission
A retired 2504 still holds the wireless configuration, RADIUS shared secrets, certificates, and PSKs. Erase the configuration and factory-reset it before it leaves the rack, remove it from mobility groups, monitoring, and asset inventory, and for federal and healthcare environments follow your media-sanitization policy (NIST SP 800-88-style handling) with documented chain of custody.
Procurement notes for regulated buyers
For US federal, DoD, and SLED purchases, confirm Trade Agreements Act (TAA) compliance and country of origin on the controller, optics, and any new access points, and align to your GPC or contract vehicle thresholds. Catalyst 9800 hardware and Wi-Fi 6/6E access points carry real lead times that move with demand, and DNA subscriptions must be ordered and tied to your Smart Account in the same transaction — sourcing controller, APs, optics, and licensing together through an authorized Cisco partner avoids the most common delays and a mismatched-entitlement scramble at turn-up. As an authorized Cisco partner, we can validate the bill of materials, confirm TAA status, and quote the full refresh as one package.
Confirm the 2504's exact milestone dates on its EoL detail page, browse the full set of affected platforms on our Cisco end-of-life hub, and price current Catalyst 9800 controllers and Wi-Fi 6 access points in the catalog. When you are ready to scope the swap, get a quote and we will turn your 2504 inventory into a TAA-compliant, fully licensed migration plan.
Frequently asked questions
Is the Cisco 2504 Wireless Controller still supported?
No. The 2504 (AIR-CT2504-K9) passed its Last Day of Support on April 30, 2023. Cisco no longer provides software images, PSIRT security patches, TAC support, or RMA hardware replacement. End of Software Maintenance was April 18, 2019, so it has not received bug fixes since then either.
Can I just buy a 3504 to replace my 2504?
You can, but it is a poor long-term choice. The 3504 (AIR-CT3504-K9) was Cisco's named successor, but it went End of Sale on January 31, 2021 and runs the same AireOS platform with its own LDoS in January 2027. For any multi-year deployment, migrate directly to a Catalyst 9800 controller on IOS-XE instead, which has a long support runway and manages Wi-Fi 6/6E/7 access points.
What is the difference between the 2504 and the Catalyst 9800?
The 2504 is an AireOS appliance capped at 75 APs and ~1,000 clients with no high availability and four 1GbE ports. The Catalyst 9800-L runs IOS-XE, scales to roughly 250 APs and 5,000 clients, adds stateful (SSO) high availability, mGig uplinks, WPA3, and integrates with Catalyst Center / Cisco DNA Center. It also uses Smart Licensing with DNA subscriptions rather than AireOS right-to-use AP licenses.
Can I upgrade the 2504 directly to IOS-XE?
No. There is no in-place upgrade path from an AireOS 2504 to an IOS-XE Catalyst 9800. The migration is a parallel build: stand up the new controller, translate the configuration (Cisco's AireOS-to-9800 conversion tooling helps but must be validated), then cut access points over by zone and decommission the 2504.
Will my existing access points work on the new controller?
It depends on the AP model. Many 2504-era access points (Aironet 1600/2600/3600/1700 and similar) are themselves end-of-life and are not supported on current Catalyst 9800 code, so they should be refreshed to Catalyst 9100 Wi-Fi 6 (or later) APs in the same project. Inventory every AP during assessment and plan to replace the EoL ones rather than carry them forward.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read