Uniqcli

Cisco FirePOWER 8350 (FP8350-K9) to Firepower 9300 Migration

The FirePOWER 8000 Series hit Last Day of Support on 2024-06-30 — here is how to migrate the FP8350-K9 to Cisco's Firepower 9300 Series cleanly and compliantly.

UT
Uniqcli Team
November 24, 2025 · 8 min read
Share
Cisco FirePOWER 8350 (FP8350-K9) to Firepower 9300 Migration

The Cisco FirePOWER 8350 (PID FP8350-K9) and its 8000 Series siblings — the 8360, 8370, and 8390, along with the AMP8350 through AMP8390 variants — were the high-water mark of Sourcefire-derived, dedicated next-generation IPS hardware. Built as modular, stackable chassis that could be ganged together for tens of gigabits of inspected throughput, the 8000 Series anchored data-center and high-throughput perimeter inspection for a generation of federal, healthcare, and large-enterprise networks. That generation is now over. Cisco bulletin c51-741685 retired the entire 8000 Series, and the Last Day of Support has passed. If an 8350 is still inline in your environment, it is now an unsupported, unpatchable inspection device sitting in the traffic path — which is precisely the place you cannot afford one.

Why the 8350 end-of-life matters right now

An IPS that no longer receives signatures and software fixes is worse than no IPS, because it manufactures false assurance. Three concrete exposures follow from the lifecycle status of the FP8350-K9, and all three are already in effect rather than looming.

  • No PSIRT remediation: Cisco will not issue security fixes for the 8000 Series. Any vulnerability disclosed against the platform, the FireSIGHT/FMC-managed software train it runs, or the underlying OS is permanent. There is no First Fixed Release to upgrade to.
  • No TAC or RMA: past the Last Day of Support you cannot open a support case or get a hardware replacement. A failed power supply, NetMod, or chassis on an 8350 is now a self-sourced spare or an outage — not a next-business-day part.
  • Audit and compliance exposure: FedRAMP, CMMC, HIPAA, PCI DSS, and STIG-driven assessments all flag end-of-support security appliances. An unsupported inline inspection device is a documented, repeatable finding that auditors will hold against you until it is removed.

What each milestone date actually means

  • End of Sale (2019-06-10): the last day Cisco accepted new orders for the FP8350-K9. After this point the platform existed only as installed base and secondary-market hardware.
  • Last Day of Support / LDoS (2024-06-30): the final day of any Cisco service and support — TAC, RMA, bug fixes, and PSIRT remediation. This is the date that converts the appliance from supported to liability. There is no software maintenance phase remaining beyond it.

You can confirm the exact entry for your hardware on our FirePOWER 8350 end-of-life detail page, and check the rest of your fleet against the full Cisco End-of-Life hub so the 8350 is not the only surprise hiding in a rack.

Cisco's named successor for the 8000 Series is the Firepower 9300 Series — its carrier-grade, data-center security platform. The 9300 is the right inheritor not just because it is faster, but because it collapses the dedicated-IPS model of the 8350 into a consolidated, software-defined Secure Firewall platform that does NGIPS, NGFW, and more on the same silicon.

From fixed-function NGIPS to a modular, multi-service chassis

The 8350 was a fixed NGIPS engine: you bought inspection horsepower and added NetMods for copper/fiber interfaces and hardware bypass. The Firepower 9300 is a 3-slot modular chassis driven by an FXOS supervisor. Each slot accepts a security module (the SM-series, spanning roughly SM-24 through SM-56 across generations), and a network module bay handles the data interfaces. The practical differences that matter on a migration:

  • Software-defined role: each security module runs as a logical device — Cisco Secure Firewall Threat Defense (FTD) or ASA — so the same hardware that replaces your 8350's IPS function can also terminate VPN, do application control, URL filtering, and TLS decryption. The standalone IPS box becomes one feature of a consolidated NGFW.
  • Throughput class: a single 8350 inspected in the low-double-digit Gbps range and you stacked up to four chassis (the 8390) to scale. A populated 9300 delivers multi-tens to well over 100 Gbps of inspected throughput per chassis depending on module, with hardware flow offload and crypto acceleration via on-board SmartNIC/crypto engines that the 8000 Series never had.
  • Interfaces and optics: the 9300 network modules support 10G, 25G, 40G, and 100G optics — a generational jump from the 1G/10G NetMod world of the 8350 — which is usually the difference between fitting into a modern spine/leaf data center and not.
  • Clustering and multi-instance: instead of the 8000 Series' fault-tolerant stacking, the 9300 scales with native clustering (intra- and inter-chassis) and multi-instance, letting you carve a chassis into separate FTD container instances with isolated resources for different tenants, enclaves, or mission systems.

Licensing and management: the real change to plan for

This is where teams underestimate the project. The 8000 Series ran the classic FireSIGHT/Defense Center model with perpetual, hardware-tied feature entitlements. The Firepower 9300 with FTD runs on Cisco Smart Licensing: term-based subscriptions (Threat, Malware/Secure Endpoint integration, URL Filtering, and the Carrier license for SP features) tracked in a Smart Account rather than baked into the box. Management likewise moves forward. Where the 8350 reported to FireSIGHT, the 9300 is driven by the modern Secure Firewall Management Center (FMC) — on-prem appliance or virtual — or cloud-delivered FMC via Cisco Defense Orchestrator. Budget for the Smart Account setup, the subscription term decision, and an FMC platform as first-class line items, not afterthoughts.

A practical migration plan

1. Assessment and inventory

Enumerate every 8000 Series chassis by serial: which are standalone 8350s, which are stacked into an 8390, and which carry AMP variants. Capture the inline interface map, the bypass NetMod placement, the throughput you actually inspect at peak (not the rated number), and every IPS policy, intrusion rule set, custom rule, and network/port object in the managing FireSIGHT/FMC. This inventory is what sizes the 9300 module and licenses correctly.

2. License transition

Stand up or confirm a Cisco Smart Account and Virtual Account, then map your old perpetual entitlements to 9300 subscription SKUs (Threat, Malware, URL, plus the base FTD/ASA software). Decide term length against your refresh horizon, not the lowest sticker — a 9300 is a 7-plus-year asset and the term should match.

3. Config and feature parity

Translate, do not lift-and-shift. Sourcefire-era IPS policies, variable sets, and access control rules carry over conceptually to FTD but should be rebuilt and tuned in FMC, taking the opportunity to retire dead rules and consolidate. If the 9300 will also absorb firewall, VPN, or decryption duties that previously lived on separate ASA or other devices, design that converged policy now while you have a parallel environment to validate against.

4. Physical: rack, power, optics, interfaces

The 9300 is typically a 3RU chassis with dual high-wattage AC or DC supplies — confirm rack PDU capacity and cooling before delivery, as it draws more than an 8350. Re-spec optics: 8000 Series NetMod transceivers will not move forward, so the 9300 network module needs new 10/25/40/100G optics matched to your switching. Plan inline pairs and any hardware bypass requirements (FTD inline sets with fail-to-wire) to preserve the fail-open behavior your 8350 NetMods provided.

5. Phased cutover

Run the 9300 in a passive or monitor-only posture first (or inline in tap/monitor) alongside the live 8350 to validate that inspection results and false-positive rates match expectations under real traffic. Cut over one inline segment at a time during a change window, keep the 8350 physically cabled but bypassed as an immediate rollback for the first window, then decommission once stable.

6. Secure decommission

An end-of-life IPS holds sensitive configuration: object names that map your topology, custom rules that reveal what you watch for, and potentially captured event data. Wipe storage to your data-sanitization standard (NIST SP 800-88), pull the units from any asset and license records, and use a certified disposal path. For federal and DoD environments, follow your media-destruction policy rather than reselling intact appliances.

Procurement notes for government and enterprise buyers

Because the 8350 is long past End of Sale, replacement is a new-build purchase, and for regulated buyers the sourcing details decide whether the order is clean. Confirm TAA compliance and country of origin on every 9300 SKU and optic before the PO is cut; verify each line is a current, orderable part rather than another platform drifting toward its own EoL. Government Purchase Card (GPC) thresholds, NASA SEWP or GSA vehicle alignment, and lead times all matter — high-end security chassis and 100G optics can carry multi-week lead times, so order against your cutover window with margin. Sourcing from an authorized Cisco partner is what guarantees genuine hardware, valid Smart Licensing entitlement, and warranty standing — none of which a gray-market 9300 can promise.

You can browse the Firepower 9300 and the broader Secure Firewall line in our catalog or catalog. When you are ready to size the right security modules, subscriptions, and optics against your actual 8350 inventory, request a refresh quote and our team will scope a TAA-compliant, audit-ready migration before your unsupported appliances become an incident.

Frequently asked questions

Is the Cisco FirePOWER 8350 (FP8350-K9) still supported?

No. The 8000 Series reached End of Sale on 2019-06-10 and its Last Day of Support was 2024-06-30. Both dates have passed, so there is no TAC, no RMA, and no PSIRT security maintenance. Any 8350/8360/8370/8390 still inline is running unsupported and unpatchable, and will be flagged in HIPAA, PCI, CMMC, FedRAMP, and STIG audits until it is removed.

What replaces the FirePOWER 8350 / 8000 Series?

Cisco's named successor is the Firepower 9300 Series, its data-center-grade Secure Firewall platform. It is a 3-slot modular chassis driven by an FXOS supervisor that runs security modules as logical FTD or ASA devices, so it absorbs the 8350's NGIPS role while also doing NGFW, VPN, URL filtering, and TLS decryption on the same hardware.

How much more throughput does the Firepower 9300 deliver than an 8350?

A single 8350 inspected in the low-double-digit Gbps range and scaled by stacking up to four chassis (the 8390). A populated 9300 delivers multi-tens to well over 100 Gbps of inspected throughput per chassis depending on the security module, aided by hardware flow offload and crypto acceleration the 8000 Series lacked, and it scales further through native clustering instead of stacking.

What changes with licensing when moving from the 8350 to the 9300?

The 8000 Series used the classic FireSIGHT model with perpetual, hardware-tied feature entitlements. The Firepower 9300 with FTD uses Smart Licensing — term-based Threat, Malware, URL Filtering, and base software subscriptions tracked in a Smart Account. You will need to stand up a Smart Account and Virtual Account and choose a subscription term aligned to the platform's service life.

Can I reuse my 8350's optics, NetMods, and IPS policies on a Firepower 9300?

Optics and NetMods do not carry forward — the 9300 uses network modules with new 10/25/40/100G optics that must match your switching. IPS policies, variable sets, and rules translate conceptually to Secure Firewall Threat Defense but should be rebuilt and tuned in the Secure Firewall Management Center (FMC) or cloud-delivered FMC rather than lifted-and-shifted, which is a good moment to retire dead rules.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote