Uniqcli

Cisco 891 (CISCO891-K9) EoL: Migrating to the C891F-K9

The Cisco 891 (CISCO891-K9) passed Last Day of Support in 2019, leaving it with no patches, TAC, or RMA — here's how to migrate cleanly to the supported C891F-K9.

UT
Uniqcli Team
December 3, 2025 · 7 min read
Share
Cisco 891 (CISCO891-K9) EoL: Migrating to the C891F-K9

If you still have a Cisco 891 Gigabit Ethernet Security Router (PID CISCO891-K9) carrying a branch office, a clinic, or a remote site, it is now operating entirely outside Cisco's support envelope. This first-generation ISR 800 desktop router went End-of-Sale on August 22, 2014, and reached its Last Day of Support (LDoS) on August 31, 2019. As of mid-2026 it has been almost seven years since Cisco's last obligation to fix, patch, or replace it expired. This guide explains exactly what that means in operational and compliance terms, why the Cisco 890 Series C891F-K9 is the right successor, and how to plan a clean migration that does not break your VPN, your WAN, or your audit posture.

What end-of-life actually means for the CISCO891-K9

Lifecycle milestones are not marketing labels; each one removes a concrete service you may be relying on without realizing it. For the 891, the calendar has fully run out, and that changes how you should treat the device today.

The milestone dates, in plain terms

  • End-of-Sale (Aug 22, 2014): Cisco stopped selling the CISCO891-K9 through normal channels. Any new unit after this date is refurbished, gray-market, or new-old-stock — none of which restores Cisco support.
  • End of Software Maintenance: Cisco's bulletin did not publish a confirmable software-maintenance date for this exact PID. In practice, IOS 15.x maintenance for the platform wound down years ago, and no current IOS release is built or qualified for it.
  • Last Day of Support (Aug 31, 2019): the hard wall. After this date there is no Cisco TAC support, no RMA hardware replacement, no bug fixes, and no security patches — period.

For regulated buyers this is where the cost lands. An unsupported edge router is a documented finding under FISMA/NIST 800-53 (SI-2, flaw remediation), CMMC, HIPAA Security Rule technical safeguards, and PCI DSS requirement 6 for unsupported software. You cannot compensate your way around a device that can never receive a patch. You can confirm the full milestone record on our CISCO891-K9 end-of-life detail page, and browse adjacent platforms on the Cisco EoL hub.

Cisco's bulletin names the Cisco 890 Series ISR, specifically the C891F-K9, as the direct migration path. This is deliberate: it is the same desktop form factor, the same eight-port managed Layer 2 switch (10/100/1000 on the 890 generation), the same console/AUX and USB layout, and the same classic IOS operating model — so your configuration concepts, CLI muscle memory, and rack/desk footprint carry straight over. The point of difference is in the WAN and in lifecycle longevity.

What you actually gain

  • WAN flexibility: the 'F' in C891F is the fiber SFP Gigabit Ethernet WAN port. Where the original 891 gave you a copper-only GE WAN, the C891F adds an SFP-based fiber GE uplink — directly useful for fiber-fed branches, metro-E hand-offs, or longer runs where copper will not reach.
  • A live support runway: the C891F-K9 has a far longer published lifecycle than the 891 it replaces, which is the whole reason Cisco swapped them. You move from a device years past LDoS to one that still receives maintenance and TAC.
  • Hardware VPN throughput and crypto: the 890 generation carries onboard hardware acceleration for IPsec/SSL VPN, sustaining encrypted site-to-site and teleworker tunnels at branch-class rates without collapsing the CPU the way a software-only edge would.
  • Integrated services parity: 8-port managed switch with optional 802.3af PoE on designated ports, dual WAN options for failover, and the same advanced security feature set (zone-based firewall, IPsec VPN, IOS IPS lineage).

Important licensing note: both the 891 and the C891F predate Cisco's Smart Licensing era. They run Universal IOS images gated by classic feature-set licenses (the IP Base / data / security / advanced PAK-and-RTU model), not the token-based Smart Licensing or DNA subscriptions you see on Catalyst 9000 and Catalyst 8000 edge platforms. So the C891F is a like-for-like licensing transition — you are not forced into a subscription. If, however, your branch needs SD-WAN, application visibility, or centralized cloud management, that is the moment to evaluate a Catalyst 8200/8300 running IOS-XE instead, where SD-WAN and Smart Licensing are native. For a straight refresh of an 891 that just needs to keep doing its job on a supported box, the C891F is the clean answer.

A practical migration plan

Treat this as a fixed-config edge swap, not a redesign. The work breaks into six stages.

1. Assessment and inventory

  • Pull the running config and 'show version' from each 891; record IOS train, feature licenses in use, and the exact interface roles (which of the 8 switch ports are PoE, which VLANs, WAN media).
  • Document every IPsec peer, crypto map / IKEv1-IKEv2 setting, DMVPN/EzVPN role, NAT pool, and ACL — these are the parity items that must survive the cutover.
  • Note WAN media per site: copper-fed sites map to the C891F copper WAN; fiber or metro-E sites are the ones that benefit most from the C891F SFP WAN port (and will need the correct SFP).

2. License and software transition

Confirm the feature set each site requires (security/VPN almost always) and order the C891F with the matching Universal image license. Because this stays in the classic licensing world, there is no token migration — but do standardize on a single, current, supported IOS 15.x maintenance release for the 890 family so your whole fleet is on one qualified train.

3. Config and feature parity

The 891 and C891F share IOS, so most of the config ports over with light edits. Expect to adjust interface names, re-map the WAN to the fiber SFP where applicable, and re-validate crypto. Build a per-site target config from the captured baseline, then diff it before deployment. Re-key VPNs as a security hygiene step rather than copying old pre-shared keys.

  • Same desktop footprint — wall/desk mount and the external power brick carry over conceptually; verify the C891F PSU and any rack-mount kit per site.
  • If a site uses the 891's PoE LAN ports for a phone or AP, confirm those same ports/budget on the C891F and that the 802.3af class is sufficient.
  • For fiber WAN sites, source the correct SFP (and patch/optic type) up front — this is the single most common day-of surprise.

5. Phased cutover

Stage the C891F off-line with the validated config, then cut over per site in a maintenance window: swap WAN/LAN, bring up the tunnels, verify routing and firewall policy, and confirm PoE endpoints register. Keep the old 891 on-site, powered off, until the new edge has run clean for a full business cycle so you have an instant fallback.

6. Secure decommission

Once confirmed, wipe the 891: erase the startup config and any VPN keys/certificates, clear the crypto store, and record the serial for asset retirement. For government and healthcare environments, dispose through a documented, sanitized chain so the device cannot resurface with credentials or topology intact.

Procurement notes for government and enterprise

  • TAA compliance: buy the C891F-K9 as genuine, TAA-compliant Cisco hardware through an authorized partner — not the gray market where 891 stock has lingered. Provenance is what survives an audit.
  • GPC / card payment: low-dollar branch refreshes often fit on a Government Purchase Card; we support GPC-payable orders so a single-site swap does not require a full procurement cycle.
  • Lead times: as an aging-but-active platform, the C891F can carry variable lead times — order early, especially when you also need specific SFPs or PoE configurations.
  • Authorized sourcing: working through an authorized Cisco partner secures warranty, support eligibility, and a clean compliance paper trail from day one.

Browse the 890 Series successor and matching optics in our catalog, and when you are ready to size the refresh, get a quote — tell us how many 891s you run and which sites are fiber-fed, and we will return a TAA-compliant, GPC-payable C891F migration plan with the right licenses and SFPs scoped in.

Frequently asked questions

Is the Cisco CISCO891-K9 still supported by Cisco?

No. The 891 reached End-of-Sale on August 22, 2014 and its Last Day of Support (LDoS) on August 31, 2019. Since then there is no Cisco TAC, no RMA hardware replacement, and no security patches or bug fixes. Any new CVE affecting its IOS train will never be fixed on this device, which makes it a permanent, unremediable finding for FISMA, CMMC, HIPAA, and PCI DSS audits.

What is the recommended replacement for the Cisco 891 router?

Cisco's bulletin names the Cisco 890 Series C891F-K9 as the direct successor. It keeps the same desktop form factor, the same 8-port managed switch, console/USB layout, and classic IOS operating model, while adding an SFP-based fiber Gigabit Ethernet WAN port (the 'F') and a much longer, still-active support lifecycle.

What is the difference between the CISCO891-K9 and the C891F-K9?

The headline difference is the WAN. The original 891 has a copper-only Gigabit Ethernet WAN port, while the C891F adds a fiber SFP GE WAN uplink for fiber-fed or metro-Ethernet sites. The C891F also has a far longer support runway. Both share the 8-port managed LAN switch, optional 802.3af PoE, hardware VPN crypto acceleration, and the classic Cisco IOS feature-set licensing model.

Does migrating from the 891 to the C891F require Smart Licensing or a DNA subscription?

No. Both the 891 and the C891F predate Smart Licensing. They run Universal IOS images gated by classic feature-set (PAK/RTU) licenses such as IP Base, data, and security. The C891F is a like-for-like licensing transition with no token migration. You would only move to Smart Licensing/DNA if you chose a newer IOS-XE platform like the Catalyst 8200/8300 for SD-WAN instead.

Will my existing 891 configuration and VPN tunnels transfer to the C891F?

Largely yes. Because both run classic Cisco IOS, most of the config ports over with light edits — interface name changes, re-mapping the WAN to the fiber SFP where used, and crypto validation. Best practice is to rebuild a per-site target config from the captured baseline, re-key VPNs rather than copying old pre-shared keys, and diff the result before cutover.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote