Meraki MS390 4x10GE Module EoL: Refresh to C9300-NM-8X
The MA-MOD-4X10G uplink module hits Last Day of Support on November 1, 2026. Here is what that means for an MS390 stack and how to refresh cleanly to the Catalyst 9300 with the native C9300-NM-8X 10G network module.

If you still have Cisco Meraki MA-MOD-4X10G uplink modules seated in MS390 switches, the clock on them is short. This four-port 10GbE SFP+ module went End of Sale on November 1, 2021, and it reaches its Last Day of Support (LDoS) on November 1, 2026. After that date Cisco provides no software fixes, no PSIRT security remediation, and no TAC or RMA hardware replacement for the module or the MS390 platform it plugs into. The uplinks keep passing traffic, which is precisely why these modules tend to outlive their support window unnoticed in the back of a wiring closet. This guide explains what the milestone dates actually mean for a running MS390 stack, why the native Catalyst 9300 8x10GE network module (C9300-NM-8X) is the right landing spot, and how to plan a refresh that preserves uplink capacity, stacking, and management without a fire drill.
What the MA-MOD-4X10G actually was
The MA-MOD-4X10G is a hot-swappable uplink module for the Meraki MS390 stackable access switch. It provides four SFP+ ports, each running 10 Gigabit Ethernet, for a total of 40 Gbps of uplink toward the distribution or core layer. The module accepts standard SFP+ optics and SFP+ direct-attach copper (Twinax) cables, and it also negotiates down to 1G SFP where you still terminate legacy fiber. It seats in the dedicated module bay on the rear of an MS390, separate from the front-panel access ports and from the StackPower and stacking connectors. Importantly, the MS390 is hardware that is functionally a Catalyst 9300 running Meraki cloud-managed firmware: the silicon is UADP-based and the module is mechanically a Meraki-branded variant of the Catalyst 9300 network module family. That lineage is exactly why the migration path is so clean.
In a typical deployment the MA-MOD-4X10G gave each MS390 access switch two to four 10G uplinks into an aggregation pair, often configured as a port-channel (LACP) for resiliency and 20-40 Gbps of effective bandwidth. For a 48-port multigigabit access switch that is the correct ratio. The constraint is not the module's performance; it is that the module and the MS390 chassis are aging out of support together.
Why acting now matters
The risk of an EoL uplink module is not that it stops forwarding packets. It is that the support floor disappears while the hardware keeps running. Three exposures stack up after LDoS:
- No PSIRT security patches. Once the MS390 platform passes LDoS, vulnerabilities affecting its firmware or the cloud-management plane on that hardware will not receive a fixed image. Any CVE in that code path becomes permanent for as long as the switch stays in service.
- No TAC or RMA. A failed module or switch cannot be opened as a support case or swapped under contract. Recovery depends on a spare you bought before LDoS or a secondary-market unit of the same dead-end model.
- Audit and compliance exposure. FedRAMP, CMMC, HIPAA Security Rule, PCI DSS, and CISA directives all expect supported, patchable infrastructure. An unsupported, unpatchable uplink module sitting in the data path is a finding waiting to happen, and 'the vendor no longer ships fixes' is not a defensible remediation plan for a federal, DoD, SLED, or healthcare assessor.
There is also a platform-convergence reason to move now. Cisco has unified the MS390 and the Catalyst 9300 onto a single hardware and management story under the cloud-managed Catalyst portfolio. As Meraki dashboard and Catalyst monitoring converge, staying on the MS390 leaves you on the trailing edge of a line Cisco is actively migrating customers off of. Refreshing the underlying switch to a current Catalyst 9300 puts you on supported silicon with a clear roadmap rather than a sunset platform.
What each milestone date means in practice
- End of Sale (2021-11-01): the last day Cisco accepted new orders for the module. Everything since has been consuming the support tail.
- End of Software Maintenance: not separately listed for this hardware module — firmware coverage tracks the MS390 platform's lifecycle rather than a discrete module date.
- Last Day of Support (2026-11-01): the hard cutoff. After this date there is no TAC, no RMA, no security fixes, and no entitlement, regardless of any active license. This is the date to plan the refresh around.
The recommended replacement: Catalyst 9300 with C9300-NM-8X
For 10G uplinks on the modern platform, the native module is the Catalyst 9300 8x10GE Network Module, PID C9300-NM-8X. Rather than a like-for-like swap, it is a capacity and flexibility upgrade, and because the MS390 already shares the Catalyst 9300 module form factor, it slots into the modular bay on a Catalyst 9300 (non-X) series switch the same way the MA-MOD-4X10G did on the MS390.
- Double the uplink port density. Eight SFP+ ports at 10G versus four, for up to 80 Gbps of uplink off a single module — room to build larger LACP bundles or dedicate ports to a redundant aggregation pair without contention.
- Native platform module. The C9300-NM-8X is engineered for the Catalyst 9300, so there is no Meraki-to-Catalyst module mismatch, no firmware quirk, and full Cisco support and RMA entitlement for the life of the platform.
- Modern UADP silicon and StackWise. A current Catalyst 9300 carries StackWise-480 (480 Gbps stack bandwidth) or StackWise-1T on the 9300X, plus StackPower for shared power resiliency across the stack — preserving the stack-as-one-switch model you ran on the MS390.
- mGig access plus UPOE/UPOE+. Catalyst 9300 access SKUs deliver multigigabit copper (up to 10G on -X mGig models) and up to 90W UPOE+ per port, future-proofing the edge for Wi-Fi 6E/7 APs, PTZ cameras, and high-draw endpoints.
- DNA / Cisco Networking Subscription licensing. The Catalyst 9300 moves you onto term-based Network Essentials or Network Advantage with DNA/Smart Licensing managed through Cisco Smart Account, with optional cloud management via Meraki dashboard so you keep a single-pane experience if that is your operating model.
A practical migration plan
1. Assess and inventory
Pull a full inventory of every MS390 and every MA-MOD-4X10G in the fleet, including serials, firmware, optic types per uplink, and current port-channel topology. Note PoE budget consumed at the access edge so the replacement Catalyst 9300 SKU (PoE+, UPOE, or UPOE+) is sized to actual draw, not guessed. The EoL detail page for this module is a useful anchor for the dates and the official replacement mapping.
2. Plan the license transition
Map current Meraki licensing to the Catalyst 9300 model. Decide between DNA Essentials and DNA Advantage based on the features you actually use (SD-Access, advanced telemetry, and policy segmentation push you to Advantage). Stand up or confirm a Cisco Smart Account and Smart Licensing Using Policy (SLUP) so entitlement is in place before hardware lands. If you want to retain cloud management, scope Meraki-managed Catalyst licensing in the same dashboard.
3. Establish config and feature parity
The MS390 and Catalyst 9300 share silicon, but the management model differs (Meraki dashboard versus IOS-XE / Catalyst Center, or cloud-managed Catalyst). Translate VLANs, access policies, ACLs, QoS, and uplink LACP groups into the target model. Build and validate the configuration in a lab or staging unit, and verify LACP negotiation and any 802.1X/MAB access policies against your authentication infrastructure before cutover.
4. Physical: rack, power, uplinks, optics, stacking
Plan rack units, StackPower and StackWise cabling, and PoE circuit capacity for the new stack. Seat the C9300-NM-8X in each Catalyst 9300's module bay, move the SFP+ optics over (or stage new ones where you are extending to eight uplinks), and pre-build the stack so it presents as a single logical switch the way the MS390 stack did.
5. Phased cutover
Cut over per stack or per closet during a maintenance window rather than fleet-wide at once. Bring up the new Catalyst 9300 uplinks alongside the live MS390 where the topology allows, validate forwarding and PoE on the new edge, then shift access ports and decommission the old switch. A phased approach keeps a rollback path open at every step.
6. Secure decommission
Wipe configuration and any stored credentials from retired MS390 switches and modules, remove them from the Meraki dashboard organization, and follow your data-sanitization and asset-disposal policy. For federal and DoD environments, document the chain of custody and sanitization to satisfy media-handling controls.
Procurement notes for regulated buyers
Source the Catalyst 9300 and C9300-NM-8X through an authorized Cisco partner to keep full warranty, Smart Licensing entitlement, and TAC eligibility intact. For federal, DoD, and SLED buyers, confirm TAA compliance and country of origin on every line, and align purchases to GSA/GPC vehicles where applicable. Modular network cards and switch SKUs can carry multi-week lead times, especially near a fiscal year close, so place orders well ahead of the November 1, 2026 LDoS rather than against it. Browse current Catalyst 9300 switches and modules in our catalog, and see related lifecycle guides on the Cisco EoL hub. When you are ready to scope quantities, optics, and licensing for your specific stack count, get a quote and we will build the bill of materials with you.
Frequently asked questions
When does the Meraki MS390 MA-MOD-4X10G reach end of support?
The MA-MOD-4X10G went End of Sale on November 1, 2021, and reaches Last Day of Support (LDoS) on November 1, 2026. After LDoS there are no security patches, no firmware fixes, and no TAC or RMA service for the module or the MS390 platform, regardless of any active license.
What replaces the MA-MOD-4X10G uplink module?
For 10G uplinks on the modern platform, Cisco's path is the Catalyst 9300 with the native C9300-NM-8X 8x10GE SFP+ network module. It doubles the uplink port count from four to eight, slots into the same Catalyst 9300 module form factor the MS390 already used, and carries full Cisco support and Smart Licensing entitlement.
Can I reuse my existing SFP+ optics and Twinax cables?
In most cases yes. The C9300-NM-8X uses standard SFP+ optics and direct-attach copper, so Cisco-supported transceivers like SFP-10G-SR, SFP-10G-LR, and SFP-H10GB-CU cables from the MA-MOD-4X10G generally carry over. Verify Cisco compatibility on each part number before assuming parity.
Do I keep cloud management after moving off the MS390?
Yes if you want it. The Catalyst 9300 can be managed in IOS-XE via Catalyst Center or run as a cloud-managed Catalyst switch in the Meraki dashboard, so you can preserve a single-pane operating model while moving onto current, fully supported silicon and term-based DNA/Cisco Networking Subscription licensing.
Why migrate before LDoS instead of running the MS390 until it fails?
Because the hardware keeps forwarding traffic while the support floor disappears. After LDoS there are no PSIRT security fixes, no RMA, and no TAC — and an unpatchable device in the data path is an audit finding under FedRAMP, CMMC, HIPAA, PCI DSS, and CISA directives. Refreshing ahead of November 1, 2026 keeps you supported and compliant.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read