
If you still have a Cisco ASR 1001 (PID ASR1001) terminating an internet edge, an MPLS handoff, or aggregating WAN and SP services, it is now running well past every support boundary Cisco published for the platform. The fixed single-RP ASR 1001 went End of Sale on April 29, 2016, and crossed its Last Day of Support (LDoS) on April 30, 2021. As of 2026 it has been more than five years since Cisco was contractually obligated to do anything for that chassis. The recommended successor in Cisco's own bulletin was the ASR1001-X, and that is the like-for-like, single-RU upgrade most operators should standardize on for this exact box.
This guide is written for federal, DoD, SLED, healthcare, and enterprise teams who need a concrete migration path rather than a vendor slogan. We cover what each milestone date actually means operationally, why the ASR1001-X is materially better hardware for an ASR 1001 role, and a step-by-step refresh plan from inventory through secure decommission. For the dated record on this specific PID, see the ASR1001 EoL detail page; for adjacent platforms, the broader Cisco end-of-life hub tracks the rest of your fleet.
Why running an ASR 1001 today is a real exposure, not a paperwork problem
The ASR 1001 is not merely "old." Past LDoS, three things stop simultaneously and they compound. First, Cisco PSIRT no longer produces fixed software for the platform, so any new IOS-XE vulnerability that touches the ASR 1000 code base on an affected train will never get a patched image for this chassis. You are frozen on whatever release you last loaded, with no remediation path other than a workaround or a forklift. Second, TAC will not open a software or hardware case, and RMA is gone, so a failed Route Processor or power supply means you are sourcing a used spare and self-installing with no Cisco backstop. Third, and most relevant to regulated buyers, an unsupported router fails the basic control language in FedRAMP, FISMA, CMMC, HIPAA, and most cyber-insurance questionnaires that require vendor-supported, patchable infrastructure on the network boundary.
What each milestone date means in practice
- End of Sale (2016-04-29): Cisco stopped taking new orders for the ASR1001 PID. Anything you buy now is used or new-old-stock, with no factory warranty.
- End of Software Maintenance: not separately published for this chassis, which in practice means maintenance rebuilds ended on the standard ASR 1000 cadence well before LDoS. No new IOS-XE images, bug fixes, or security rebuilds target this RP.
- Last Day of Support (2021-04-30): the hard line. After this date there is no TAC, no RMA, and no PSIRT remediation for the ASR1001. SmartNet cannot be purchased or renewed against it.
The replacement: Cisco ASR1001-X and why it is genuinely better here
The ASR1001-X (PID ASR1001-X) is the direct successor and keeps the form factor you already rack: a fixed, single-RU ASR 1000 with an integrated Route Processor, Embedded Services Processor (ESP), and SPA Interface Processor in one chassis. It is not a different operating model to learn, it is the same IOS-XE platform with more headroom and a modern licensing story.
Throughput and forwarding
The original ASR 1001's onboard ESP was rated around 2.5 Gbps of forwarding (license-upgradeable to roughly 5 Gbps on later steps). The ASR1001-X ships with an integrated 20 Gbps ESP and is software-licensable up in tiers to 36 Gbps, so a single box now covers WAN aggregation loads that previously demanded an ASR 1002-X or a stacked design. That is real consolidation: more services (NAT, NetFlow, IPsec, QoS) running concurrently without exhausting the data plane.
Interfaces, optics, and crypto
- Built-in interfaces: the ASR1001-X carries 6 fixed Gigabit Ethernet ports (SFP) plus 2 Ten Gigabit Ethernet (SFP+) ports onboard, versus the ASR 1001's smaller fixed-port count, and it still accepts a SPA for additional or higher-speed interfaces.
- Memory: this configuration ships with 8 GB DRAM (expandable), comfortably above the ASR 1001's typical 4 GB, which matters for larger BGP tables and richer feature sets on current IOS-XE.
- Hardware crypto: the ASR1001-X includes onboard hardware-accelerated IPsec, so site-to-site VPN and encrypted transport scale without a separate crypto module.
- Dual power supplies: this build is dual P/S, giving the power redundancy an edge device should have and that the base ASR 1001 often lacked.
Licensing: from PAK/RTU to Smart Licensing
This is the change that surprises teams most. The ASR 1001 era used node-locked PAK license files and right-to-use throughput/feature unlocks tied to the chassis. The ASR1001-X runs current IOS-XE with Cisco Smart Licensing: entitlements live in your Smart Account and Virtual Account and are consumed by the device, rather than being a paper PAK in a drawer. Throughput tiers (up to 36 Gbps) and feature sets (IP Base, Advanced IP Services / Advanced Enterprise equivalents, plus crypto) are activated as license entitlements. Plan the Smart Account setup before cutover; do not treat licensing as a day-of task.
A practical migration plan
1. Assessment and inventory
Capture the running config, show version, show inventory, show platform, and show license (or license summary) from every ASR 1001. Record the IOS-XE train, the licensed throughput tier, installed SPAs, and the exact optics in each port. Note BGP/OSPF adjacencies, NAT pools, IPsec peers, QoS policies, and any ROMmon dependencies. This inventory becomes your parity checklist and your decommission record.
2. License transition
Stand up (or confirm) your Cisco Smart Account and the right Virtual Account, then order the ASR1001-X with the throughput tier and feature/crypto entitlements that match or exceed today's PAK unlocks. Map old right-to-use throughput to the new licensed tier deliberately so you do not under-provision the data plane on day one.
3. Config and feature parity
IOS-XE configs port over with high fidelity, but validate the deltas: interface naming may shift with the new port layout and any new SPA; confirm crypto maps or IKEv2 profiles use the onboard hardware crypto; revalidate QoS hierarchical policies against the larger ESP; and re-test NetFlow/Flexible NetFlow and any NBAR features on the current release. Build the candidate config in a lab or on the bench and diff it against production before you touch the live edge.
4. Physical: rack, power, uplinks, optics
- Both chassis are 1RU, so rack space and cabling layout are largely unchanged.
- Confirm power: the ASR1001-X dual-P/S build wants two feeds; verify PDU capacity and matching AC or DC supplies for your facility.
- Reuse SFP/SFP+ optics where the coding and speed match, but inventory them first; the X model's 10GE SFP+ ports may let you upgrade selected uplinks from 1G to 10G during the swap.
- No PoE or stacking applies to this platform class; the consolidation win is throughput per RU, not stack scale.
5. Phased cutover
For edge and aggregation routers, stage the new ASR1001-X alongside the old one and migrate one path at a time where topology allows. Use routing-protocol cost/metric manipulation, BGP local-preference and AS-path prepending, or HSRP/VRRP priority to drain traffic gracefully onto the new box, verify the control plane and data plane, then fail back fast if anything regresses. Keep the ASR 1001 powered and cabled as a fallback through at least one maintenance window before you reclaim it.
6. Secure decommission
Once the ASR1001-X owns production, sanitize the retired chassis: erase startup and running configs, wipe the bootflash and any storage, and clear stored credentials and keys. For DoD and regulated environments follow your NIST SP 800-88 media sanitization process and document chain of custody. Record serials against your asset register so the decommissioned PID is closed out for the next audit.
Procurement notes for government and enterprise buyers
Because the ASR 1001 is unsupported and the ASR1001-X is itself end-of-sale, sourcing matters. Buy from an authorized Cisco partner so the hardware provenance, software entitlement, and any available support coverage are legitimate. For federal buyers, confirm TAA compliance and country-of-origin documentation up front, plan for GPC/purchase-card thresholds and contract vehicles, and ask about lead times early since end-of-sale optics, SPAs, and chassis can carry longer or variable availability. Bundling the chassis, the right Smart Licensing throughput tier, optics, and a support contract in one quote avoids the classic gap where a router arrives without the entitlement to forward at rate.
You can browse the replacement and compatible optics in our catalog, and when you are ready to scope the refresh against your exact port, throughput, and license requirements, request a refresh quote and we will return a TAA-documented, partner-sourced configuration with lead times.
Frequently asked questions
When did the Cisco ASR 1001 reach end of life?
The ASR1001 went End of Sale on April 29, 2016, and reached its Last Day of Support (LDoS) on April 30, 2021. Since that date there is no TAC support, no RMA, and no PSIRT security patching for the chassis, and SmartNet cannot be renewed against it.
What is the recommended replacement for the ASR 1001?
Cisco's bulletin names the ASR1001-X as the direct successor. It keeps the same 1RU single-RP ASR 1000 form factor but adds a 20 Gbps integrated ESP (licensable to 36 Gbps), 6 fixed GE plus 2 SFP+ 10GE ports, 8 GB DRAM, onboard hardware crypto, and dual power supplies.
How much faster is the ASR1001-X than the ASR 1001?
The original ASR 1001 forwarded roughly 2.5 Gbps (up to about 5 Gbps with license steps). The ASR1001-X starts at 20 Gbps and licenses up to 36 Gbps, so one box can absorb aggregation loads that previously needed an ASR 1002-X or a second chassis.
Does migrating change the licensing model?
Yes. The ASR 1001 used node-locked PAK / right-to-use license files. The ASR1001-X runs current IOS-XE with Smart Licensing, where throughput tiers and feature/crypto entitlements live in your Cisco Smart Account and are consumed by the device. Set up the Smart Account before cutover.
Should I buy the ASR1001-X or jump to the Catalyst 8500?
For a straight, budget-conscious one-for-one ASR 1001 refresh, the ASR1001-X is the proven drop-in on the same IOS-XE platform. The ASR1001-X is itself now end-of-sale, with the Catalyst 8500 as Cisco's strategic SD-WAN edge platform, so if you are designing a multi-year Cisco SD-WAN edge, evaluate the Catalyst 8500 in parallel before you commit.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read