Uniqcli

Cisco 5508 WLC EoL: Migrate to 5520 / Catalyst 9800-40

The AIR-CT5508-K9 passed Last Day of Support on July 31, 2023. Here's what each milestone means, why an unpatchable AireOS controller is a compliance liability, and how to refresh cleanly to the Catalyst 9800-40.

UT
Uniqcli Team
February 18, 2026 · 10 min read
Share
Cisco 5508 WLC EoL: Migrate to 5520 / Catalyst 9800-40

If a Cisco 5508 Wireless Controller (PID AIR-CT5508-K9) is still anchoring your wireless network, it is now past every lifecycle milestone Cisco tracks. The 5508 reached Last Day of Support on July 31, 2023. From that date forward there are no software fixes, no PSIRT security patches, and no TAC or RMA hardware coverage for this chassis. It keeps terminating CAPWAP tunnels and handing out IPs, which is precisely why so many 5508s quietly survive in production years after they should have been retired. This guide explains what the end-of-life dates actually mean for a live controller, why the path now runs to the Catalyst 9800-40 rather than the originally-named 5520, and how to plan a refresh that preserves feature parity without a forklift weekend.

What the 5508 actually was

The 5508 was, for the better part of a decade, the default enterprise AireOS controller. It is a 1RU appliance built around eight 1-Gigabit SFP ports (typically aggregated as an 8 Gbps LAG to the distribution layer) and a license-tiered AP count that scaled from 12 up to 500 access points and up to 7,000 clients on a single box. It runs AireOS — Cisco's purpose-built wireless OS, not IOS — and was licensed with right-to-use AP-count licenses (for example LIC-CT5508-25 for 25 APs) layered onto the base chassis. In its day it was the workhorse for campuses, hospitals, and government sites: N+1 and SSO high availability, FlexConnect for branch survivability, and broad support for the Aironet 802.11n and 802.11ac access-point generations that dominated that era.

Two facts now define it. First, the hardware is a 2010-era platform with eight 1G uplinks — a hard ceiling in a world where a single Wi-Fi 6 AP can saturate a gigabit link on its own. Second, and more urgent, AireOS itself is a dead-end software train. Cisco's wireless future is IOS-XE on the Catalyst 9800 family, and the last AireOS releases will not run the newest access points or receive the security maintenance that current code does.

Why acting now matters

The danger of an end-of-life controller is not that it fails — it is that it succeeds at passing traffic while the support floor disappears underneath it. After LDoS, three exposures compound on a 5508:

  • No PSIRT security patches. AireOS controllers have a long history of serious advisories — remote code execution and denial-of-service issues in the web management interface and CAPWAP among them. When the next wireless or AireOS CVE lands, the 5508 will not receive a fixed image. Its software is frozen at the 2019 maintenance cutoff, so any vulnerability in that code path is permanent on this box.
  • No TAC or RMA. A failed controller cannot be opened as a support case or swapped under a contract. For a device that is a single point of failure for every AP it manages, your only recovery is a cold spare you bought before LDoS or a gray-market unit of the same dead-end model.
  • Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under — FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS, and CISA Binding Operational Directives — all assume supported, patchable infrastructure carrying production data. An unpatchable controller that touches every wireless client is a finding waiting to be written, and "the vendor no longer ships fixes" is not a defensible remediation plan.

There is also a hardware-software trap. As you adopt Wi-Fi 6/6E access points, the 5508 simply cannot manage them — newer APs require IOS-XE controllers, and AireOS support for the latest radios was never added. The controller and the AP fleet age out together, so deferring the controller refresh quietly caps the access layer at last-decade radios too.

What each milestone means in practice

  • End of Sale (2018-05-04): the last day Cisco accepted new 5508 orders. Everything after this date is consuming the support tail you already paid for.
  • End of Software Maintenance (2019-08-01): the last day Cisco released maintenance and bug-fix AireOS images for the platform. After this, even non-security defects go unfixed.
  • Last Day of Support / LDoS (2023-07-31): the hard wall. No TAC, no RMA, no patches of any kind. The chassis is entirely on its own.

The replacement path: 5520, then Catalyst 9800-40

Cisco's original EoL bulletin named the 5520 Wireless Controller (AIR-CT5520-K9) as the direct successor to the 5508, and on paper it is a clean step up: two 10-Gigabit SFP+ uplinks instead of eight 1G ports, scale to 1,500 APs and 20,000 clients, and Smart Licensing instead of node-locked RTU AP licenses. The catch is that the 5520 is itself now end-of-life. Buying one today simply moves you to the back of the same support queue. For any refresh in 2025 and beyond, the real target is the Catalyst 9800 family — specifically the Catalyst 9800-40 (C9800-40-K9) as the modern equivalent for a 5508-class deployment.

The Catalyst 9800-40 is not an AireOS box with a new label — it is a different platform built on IOS-XE, and the differences are the whole point of the migration:

  • Modern OS and AP support. IOS-XE 17.x is the only train that supports Wi-Fi 6 (Catalyst 9100) and Wi-Fi 6E (Catalyst 9136) access points. Moving the controller to the 9800-40 is what unlocks OFDMA, downlink and uplink MU-MIMO, and the 6 GHz band for the AP refresh that follows.
  • Throughput and uplinks. The 9800-40 delivers roughly 40 Gbps of aggregate data-plane throughput with four 10G SFP+ uplinks, versus the 5508's 8 Gbps over 1G ports — headroom that matches what high-density Wi-Fi 6 cells actually generate.
  • Scale. The 9800-40 supports up to 2,000 access points and 32,000 clients per controller, comfortably above the 5508's 500-AP / 7,000-client ceiling, so consolidation ratios improve.
  • Smart Licensing and Catalyst Center. AP licensing moves from per-PID RTU licenses to Cisco Smart Licensing (Network Advantage / DNA tiers) managed in a Smart Account, with assurance and analytics through Catalyst Center (formerly DNA Center). License entitlement becomes portable across controllers instead of locked to a chassis.
  • Hot/standby SSO and patchability. The 9800 supports stateful switchover HA pairs and — critically — IOS-XE In-Service Software Upgrade and hot patching, so you can apply security fixes without the long maintenance outages AireOS upgrades demanded.

A practical migration plan

1. Assessment and inventory

Start with what the 5508 is actually carrying. Export the running config and pull the AP inventory (model, count, regulatory domain, and current AireOS code) so you know how many of the existing APs the 9800 will support and how many must be replaced — older Aironet models that the 9800 cannot adopt force a parallel AP refresh. Capture WLAN/SSID definitions, RF profiles, AP groups, FlexConnect groups, RADIUS/ISE integration, and any guest-anchor relationships. Record current AP-license counts so you can size the Smart Licensing entitlement correctly.

2. License transition

This is the step most teams underestimate. AireOS RTU AP licenses on the 5508 do not transfer to IOS-XE — the 9800 uses Smart Licensing tied to a Smart Account. Plan to acquire Network Advantage (or DNA Advantage) AP entitlements sized to your AP count, set up the Smart Account and a Catalyst Center instance if you want assurance, and decide between connected and on-prem (Smart Software Manager satellite) licensing models, which matters for air-gapped and DoD environments.

3. Config and feature parity

There is no in-place AireOS-to-IOS-XE config conversion you can fully trust to a script. Cisco's Wireless Config Analyzer/Conversion tooling translates much of the WLAN, RF, and policy structure, but treat its output as a draft. Rebuild and validate the security-sensitive pieces by hand: 802.1X/RADIUS to ISE, WPA3 and PMF settings, FlexConnect-to-local-switching policies, mDNS/Bonjour, mobility groups, and ACLs. The 9800 uses a policy-tag / site-tag / RF-tag model that is conceptually different from AireOS AP groups, so map your design to tags deliberately rather than transliterating.

The 9800-40 is a 1RU appliance like the 5508, so rack space is a non-issue, but the uplinks change: budget for 10G SFP+ optics or DACs into your distribution switches rather than the 5508's 1G SFPs, and provision the switch ports to match. Confirm dual power supplies for the HA story and verify your management VLAN, out-of-band, and NTP/syslog reachability before cutover. Controllers do not carry PoE — the access points do — so PoE budget planning belongs to the AP refresh, where Wi-Fi 6E radios may need 802.3at/bt depending on model and feature set.

5. Phased cutover

Avoid a big-bang swap. Stand up the 9800-40 alongside the live 5508, build and validate the configuration, then migrate APs in controlled waves by changing the primary controller assignment (or DHCP option 43 / DNS discovery) so a batch of APs join the 9800 while the rest stay on the 5508. Validate roaming, RADIUS auth, and guest flows on the first wave before widening. Mixed-controller operation during the transition is normal; keep mobility groups consistent so clients roam cleanly across the boundary. Once all supportable APs are on the 9800 and any unsupported APs are replaced, decommission the 5508.

6. Secure decommission

Before the 5508 leaves the rack, erase it. Wipe the configuration and any stored RADIUS shared secrets, certificates, and admin credentials, then record the chassis serial for asset and contract closure. For federal, DoD, and healthcare environments, follow your media-sanitization standard (NIST SP 800-88) and capture a certificate of data destruction. Do not resell or donate a controller that held production keys without a verified wipe.

Procurement notes for regulated buyers

Wireless controllers and the AP refresh that rides along carry the same acquisition constraints as the rest of your Cisco fleet. A few specifics for this swap:

  • TAA compliance. For federal and DoD purchases, confirm the Catalyst 9800-40 and the replacement APs ship from TAA-designated countries of origin and request documentation up front; this is a hard contract requirement, not a preference.
  • GPC and contract vehicles. Right-sized controller-plus-license bundles fit micro-purchase and card thresholds for smaller sites, while larger refreshes typically run through GSA or SEWP-style vehicles — sequence the license and Smart Account setup so entitlement is ready when hardware lands.
  • Lead times and Smart Account setup. Plan for current Cisco lead times on the 9800 platform and Wi-Fi 6E APs, and start the Smart Account / licensing paperwork early — it is often the long pole, not the hardware.
  • Buy through an authorized partner. Sourcing the controller, optics, licenses, and APs through an authorized Cisco partner keeps warranty, Smart Licensing entitlement, and support contracts clean — gray-market controllers routinely arrive without valid entitlement or coverage.

If you are mapping a wider fleet, the full end-of-life catalog at /cisco-eol shows which of your other platforms share this deadline, and live availability for the Catalyst 9800-40, 10G optics, and Wi-Fi 6E access points is on /catalog. When you are ready to scope the refresh, our team can size the controller, license tier, and AP count against your current 5508 inventory and return a TAA-compliant quote: get a quote at /get-a-quote.

Frequently asked questions

Is the Cisco 5508 Wireless Controller still supported?

No. The AIR-CT5508-K9 reached Last Day of Support on July 31, 2023. After that date Cisco provides no TAC support, no RMA hardware replacement, and no software or security (PSIRT) patches. It will keep running, but any new AireOS vulnerability affecting it will never be fixed, which is a significant compliance and security exposure for regulated environments.

Should I replace my 5508 with the 5520 that Cisco's bulletin recommended?

Not anymore. The 5520 (AIR-CT5520-K9) was the named successor, but it has since reached end-of-life itself, and it still runs AireOS — so it cannot support Wi-Fi 6E access points and offers only a short support runway. For any refresh today the right target is the Catalyst 9800-40 (C9800-40-K9) on IOS-XE, which supports current and next-generation APs.

Will my existing access points and AireOS licenses work on the Catalyst 9800-40?

Partially. The 9800-40 can adopt many Wi-Fi 5 and Wi-Fi 6 Aironet/Catalyst APs but not the oldest models the 5508 supported, so inventory your APs first — some will need replacement. AireOS right-to-use AP licenses do NOT transfer; the 9800 uses Cisco Smart Licensing (Network/DNA Advantage) in a Smart Account, so plan a fresh license entitlement sized to your AP count.

How much better is the Catalyst 9800-40 than the 5508?

Substantially. The 9800-40 scales to about 2,000 APs and 32,000 clients with roughly 40 Gbps of throughput over 10G SFP+ uplinks, versus the 5508's 500 APs, 7,000 clients, and eight 1G ports. It runs IOS-XE with hot patching and ISSU for low-downtime upgrades, supports Wi-Fi 6/6E radios with OFDMA and MU-MIMO, and integrates with Catalyst Center for assurance — none of which AireOS on the 5508 can deliver.

Can I migrate from the 5508 to the 9800 without a full outage?

Yes. Stand up the Catalyst 9800-40 alongside the live 5508, build and validate the configuration, then migrate access points in controlled waves by reassigning their primary controller (or via DHCP option 43 / DNS discovery). Keep mobility groups consistent so clients roam across both controllers during the transition, validate each wave, then decommission and securely wipe the 5508 once all supportable APs have moved.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote