
If you still run Cisco ISR 4351 routers (PID ISR4351/K9) at branch sites, federal facilities, or clinical buildings, the clock has already started. Cisco closed End-of-Sale on November 7, 2023, software maintenance ended August 31, 2025, and the Last Day of Support (LDoS) is November 30, 2028. After that final date the platform is fully retired by Cisco. This guide walks through what each milestone means in operational and compliance terms, why the recommended successor — the Catalyst C8300-2N2S-6T Edge Platform — is a genuine generational jump rather than a like-for-like swap, and how to plan a clean, auditable migration.
Where the ISR 4351 stands in its lifecycle
The ISR 4351 was the high-density member of the ISR 4000 branch family — three onboard Gigabit Ethernet ports (RJ-45/SFP combos), three NIM slots, two service-module (SM-X) slots, and a modular power supply that could carry PoE for inline-powered modules. It shipped with 200 Mbps of aggregate throughput by default, unlockable to roughly 400 Mbps through a performance (boost) license, and supported IOS XE with PAK/RTU feature licensing (IP Base, AppX, SEC) that later moved to Smart Licensing. It was the workhorse that replaced the 2951 and 3900-series in mid-to-large branches. That role is exactly why letting it drift past LDoS is risky: these boxes usually terminate WAN, VPN, and voice for an entire site.
Why software maintenance ending already hurts
The most under-appreciated milestone is the August 2025 software maintenance date, which is already behind us. From that point Cisco no longer publishes fixed IOS XE images for the 4351. When a new IOS XE vulnerability lands in a Cisco Security Advisory, ISR 4000 branches typically appear in the affected list — but there is no patched build for this PID to deploy. For any environment under a continuous-monitoring or vulnerability-remediation mandate (FedRAMP, FISMA/RMF, CMMC, HIPAA Security Rule, PCI DSS), an unpatchable WAN router is a finding waiting to happen. You can compensate with ACLs and segmentation, but you cannot close the underlying CVE.
After LDoS in November 2028, the second shoe drops: no TAC case can be opened and no advance hardware replacement is available. A power-supply or board failure becomes a procurement scramble on the secondary market rather than a next-business-day RMA. Acting in the 2026 window — well ahead of LDoS — lets you budget, stage, and cut over on your schedule instead of an outage's.
The replacement: Catalyst C8300-2N2S-6T
Cisco maps the ISR 4351 to the Catalyst C8300-2N2S-6T, part of the Catalyst 8300 Edge Platform line. The naming decodes directly: 2 NIM slots, 2 SM-X slots, and 6 onboard ports. It is a 1RU fixed/modular router built for the SD-WAN and SASE era, and it keeps the modular DNA of the ISR while moving the silicon and software generations forward.
What is concretely better
- Throughput: the 8300 is built on a modern multi-core x86 data plane and delivers multi-gigabit aggregate forwarding and far higher IPsec/crypto throughput than the 4351's 200–400 Mbps boost ceiling — headroom for full-tunnel VPN, encrypted SD-WAN overlays, and rising branch bandwidth without a performance license bottleneck.
- Interfaces: 6x onboard 1GbE plus 2x 10GbE (SFP+) on this model, versus three GE combo ports on the 4351 — real 10G uplinks for internet-as-WAN and dual-circuit designs, no SM consumed for speed.
- Software: native Cisco IOS XE SD-WAN (Catalyst SD-WAN, formerly Viptela) with on-box application hosting (containers/Cisco DNA app hosting) on an x86 core, enabling edge security and observability workloads the 4351 could not run.
- Module reuse: the 8300 accepts current NIM and SM-X modules, so many serial, T1/E1, LTE/5G, and switching modules can carry forward — confirm each module's compatibility before assuming reuse.
- Licensing: moves from PAK/RTU + early Smart Licensing to Smart Licensing Using Policy with Cisco DNA / Catalyst subscription tiers (Network Essentials, Advantage, or Premier, plus a DNA term), aligning the branch with controller-based management and SD-WAN entitlement.
A practical migration plan
1. Assessment and inventory
Pull every ISR4351/K9 serial, its installed NIM/SM-X modules, DRAM/flash, current IOS XE version, and active license set (use 'show license' and 'show inventory'). Record each site's WAN circuits, throughput utilization, VPN/SD-WAN role, voice/SRST functions, and uplink media. Map which existing modules are 8300-compatible and which must be replaced. This inventory becomes both your bill of materials and your config-parity checklist. Our team can validate the install base against current EoL milestones — see the live detail page for this PID at ISR 4351 end-of-life details.
2. License transition
Establish or confirm your Smart Account and Virtual Account, then size Catalyst 8300 subscriptions per site. Decide the management model now: Catalyst SD-WAN (controller-based) versus traditional IOS XE autonomous mode, because it dictates onboarding (PnP/plug-and-play vs. manual) and the DNA tier you need.
3. Config and feature parity
IOS XE configs port over with high fidelity, but validate the deltas: SD-WAN overlay templates if you are adopting Catalyst SD-WAN, crypto map vs. route-based VPN choices, QoS policy re-tuning for the higher throughput, and any voice/SRST or analog module behavior. Build a per-site golden config and test it on a bench 8300 before touching production.
4. Physical: rack, power, uplinks, optics
Both platforms are 1RU, so rack space is rarely an issue. Confirm power: the 8300 has its own PSU options (AC/DC, optional redundancy) — do not assume the 4351's PSU or PoE module carries over. Plan optics: the new 10G SFP+ uplinks need 10G transceivers/cabling that branches running 1G combo ports today may not have. Stage modules into the 8300 chassis and label everything before the maintenance window.
5. Phased cutover
Pilot one representative branch, soak it for one to two weeks, then roll out in waves grouped by circuit type and criticality. Pre-stage and pre-license each 8300 (PnP shines here for SD-WAN), keep the 4351 cabled as a fallback during the first window, and verify routing, VPN/overlay, QoS, and voice before decommissioning the old unit.
6. Secure decommission
Wipe configuration and credentials from each retired 4351 (erase NVRAM/startup-config and any stored keys/certificates), record serials for asset and contract removal, and for federal/DoD use a media-sanitization process aligned to NIST SP 800-88. Then deregister the units from your Smart Account and SmartNet contracts so you stop paying support on dead hardware.
Procurement notes for government and enterprise
- TAA compliance: order Catalyst 8300 units and optics through channels that guarantee Trade Agreements Act-compliant country of origin — essential for GSA/DoD and most SLED contracts.
- GPC and purchasing vehicles: the refresh can be structured as Government Purchase Card-payable for in-threshold buys, or routed through your standing contract vehicle for larger rollouts.
- Lead times: Catalyst 8300 hardware, specific NIM/SM-X modules, and 10G optics can carry multi-week lead times — order ahead of your cutover windows, not during them.
- Authorized sourcing: buy from an authorized Cisco partner so units arrive with valid warranty, eligible support contracts, and clean Smart Account licensing — avoid gray-market 8300s that cannot be registered.
Browse the Catalyst 8300 and related edge platforms in our catalog, review the broader retirement schedule on the Cisco EoL hub, and when you are ready to scope a site-by-site refresh, get a quote for a TAA-compliant, GPC-payable ISR 4351-to-Catalyst 8300 migration.
Frequently asked questions
When does the Cisco ISR4351/K9 reach end of life?
Cisco set End-of-Sale on November 7, 2023, and end of software maintenance on August 31, 2025 — so the 4351 no longer receives IOS XE bug fixes or PSIRT security patches. The Last Day of Support (LDoS) is November 30, 2028, after which Cisco TAC support and hardware RMA end entirely.
What is the recommended replacement for the ISR 4351?
Cisco migrates the ISR 4351 to the Catalyst C8300-2N2S-6T Edge Platform. It keeps a modular design (2 NIM + 2 SM-X slots) but adds a modern x86 data plane, multi-gigabit and much higher crypto throughput, 6x 1GbE plus 2x 10GbE uplinks, native Catalyst SD-WAN, and app hosting — a true generational upgrade over the 4351's 200–400 Mbps ceiling.
Can I reuse my ISR 4351 NIM and SM-X modules in the Catalyst 8300?
Often yes — the Catalyst 8300 accepts many current NIM and SM-X modules, so serial, T1/E1, LTE/5G, and switching modules can frequently carry forward. Verify each module against the 8300 compatibility matrix before assuming reuse, and note that the 4351's power supply and PoE module do not transfer.
Do my ISR 4351 software licenses transfer to the Catalyst 8300?
No. The 4351's perpetual IP Base/AppX/SEC (PAK/RTU) licenses do not move to the 8300. The Catalyst 8300 uses Smart Licensing Using Policy with term-based Cisco DNA/Catalyst subscriptions (Network Essentials, Advantage, or Premier) tied to your Smart Account, so you size and purchase new subscriptions as part of the refresh.
Is it a compliance problem to keep running the ISR 4351 after 2025?
Yes, for regulated environments. Because software maintenance ended August 31, 2025, the 4351 gets no patches for newly disclosed CVEs. Under FISMA/RMF, FedRAMP, CMMC, HIPAA, or PCI DSS, an unpatchable WAN router is a likely audit finding. Segmentation and ACLs can mitigate but cannot remediate the underlying vulnerability — migration is the durable fix.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read