Nexus 3064 EoL: Migration to Nexus 9300 (93180YC-FX3)
The Nexus 3064 (N3K-C3064PQ-10GE) passed Last Day of Support on June 30, 2021. Here's why it must come out and how to migrate cleanly to the Nexus 9300 (N9K-C93180YC-FX3) — 25G access, 100G uplinks, VXLAN/EVPN, and MACsec.

If a pair of Cisco Nexus 3064 switches (PID N3K-C3064PQ-10GE) are still humming away in a trading rack or a top-of-rack server row, they are well past the point where Cisco will help you if something goes wrong. The 3064 reached its Last Day of Support on June 30, 2021. Every milestone on this platform's lifecycle has expired, and the only thing keeping it in production is inertia: low-latency switches that still forward packets tend to stay racked long after the support contract underneath them has gone dark. This guide explains what the end-of-life dates mean for a live data center fabric, why Cisco's recommended Nexus 9300 (N9K-C93180YC-FX3) is a genuine generational jump rather than a like-for-like swap, and how to plan a clean migration that holds up under a federal, DoD, or healthcare audit.
Nexus 3064 (N3K-C3064PQ-10GE) lifecycle at a glance: End of Sale: June 30, 2016. Last Day of Support (LDoS): June 30, 2021. Both dates have passed. After LDoS, Cisco provides no software fixes, no PSIRT security patches, and no TAC support or RMA hardware replacement for this PID. The full milestone record lives on the EoL detail page for this switch.
What the Nexus 3064 actually was
The N3K-C3064PQ-10GE is a 1RU, fixed-configuration switch with 48 SFP+ ports (1/10 Gigabit) and 4 QSFP+ ports (40 Gigabit, breakable into 16 additional 10G interfaces), for 64 total 10G-equivalent ports. It delivers 1.28 Tbps of switching capacity and roughly 950 million packets per second of wire-rate Layer 2/3 forwarding. Its claim to fame was latency: built on a Broadcom Trident+ ASIC running in cut-through mode, it pushed packets in roughly a microsecond, which is why it landed in high-frequency trading floors and latency-sensitive HPC and storage fabrics. It runs NX-OS from the 3000-series train, with a single-core control-plane CPU and a small shared packet buffer. For 2012, it was an excellent low-latency leaf. In 2026 it is a frozen, unpatchable ASIC with no VXLAN/EVPN data-plane support, no MACsec, no 25G, and no path forward on modern NX-OS.
Why acting now matters
The risk of an end-of-life switch is not that it fails. It is that it keeps forwarding traffic flawlessly while the safety net underneath it disappears. After LDoS, three exposures compound:
- No PSIRT security patches. When a new NX-OS vulnerability is disclosed, the 3064 will not receive a fixed image. Its software is frozen on a train that stopped getting maintenance years ago, so any CVE touching that code on this hardware is permanent and unremediable. For a switch that often sits in the data path of sensitive workloads, that is a standing, unfixable hole.
- No TAC or RMA. A failed unit cannot be opened as a support case or swapped under SmartNet. Your only recovery is a cold spare you bought before LDoS or a gray-market unit of the same dead-end model — and in a low-latency pair, losing one half quietly halves your redundancy.
- Audit and compliance exposure. FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS, and CISA directives all expect supported, patchable infrastructure. An unsupported switch that cannot receive a fix is a finding, and 'the vendor no longer ships patches for this model' is not a defensible remediation plan in front of an assessor.
What each milestone means in practice
- End of Sale (2016-06-30): the last day Cisco accepted new orders for this PID. Everything after this date has been drawing down the support tail.
- Last Day of Support / LDoS (2021-06-30): the hard wall. No TAC, no RMA, no software or security fixes of any kind. From this date the hardware is entirely on its own, and any unit still in service is running on borrowed time.
The recommended replacement: Nexus 9300 (N9K-C93180YC-FX3)
Cisco directs Nexus 3064 deployments to the Nexus 9300 fixed family, and the N9K-C93180YC-FX3 is the modern representative. It is also a 1RU switch, so the rack footprint and operating model feel familiar — but the silicon, the speeds, and the feature set are a full generation ahead. Where it improves on the 3064:
- Port speeds and density: 48 downlink ports at 1/10/25G (SFP28) plus 6 uplinks at 40/100G (QSFP28). The 25G access tier is the headline — server NICs have moved from 10G to 25G, and the 93180YC-FX3 gives you a clean 25G leaf where the 3064 topped out at 10G.
- Capacity: 3.6 Tbps of switching and roughly 1.2 billion packets per second of forwarding, versus the 3064's 1.28 Tbps. Roughly triple the throughput in the same 1RU.
- Cloud Scale ASIC: the FX3 runs Cisco's Cloud Scale silicon (versus the 3064's Broadcom Trident+). That brings hardware VXLAN/EVPN bridging and routing, flexible forwarding tables, larger and smarter buffering (~40 MB shared), and sub-microsecond cut-through latency that meets or beats the 3064 on the metric it was bought for.
- Line-rate MACsec encryption on every port — relevant for any agency or healthcare buyer that needs data-in-motion encryption between racks or across a data center interconnect. The 3064 had no MACsec at all.
- Native hardware PTP (IEEE 1588) and rich telemetry (streaming model-driven telemetry, hardware flow tables). For HFT and timestamping use cases this is a material upgrade over the 3064's limited timing support.
- Deployment flexibility: the FX3 runs in NX-OS standalone mode (with VXLAN/EVPN for modern spine-leaf fabrics) or in ACI mode as a leaf, so the same hardware fits a CLI-managed fabric today and an ACI fabric later.
Licensing: the model has changed
The 3064 predated subscription licensing — you bought the switch, you ran NX-OS, done. The 93180YC-FX3 uses Cisco Smart Licensing Using Policy, with feature tiers (NX-OS Essentials and Advantage, plus the Day-2 Operations / Nexus Dashboard add-ons) tracked through your Smart Account. Essentials covers core L2/L3 switching; Advantage unlocks VXLAN/EVPN, segmentation, and the richer automation and assurance features most fabric buyers actually want. Budget for the subscription term alongside the hardware, and confirm your Smart Account is provisioned before deployment so the switches register and license cleanly. This is a procurement line item that simply did not exist on the 3064, and it is the most common thing teams forget to scope.
A practical migration plan
1. Assessment and inventory
Pull an exact count of N3K-C3064PQ-10GE units, their roles (ToR leaf, HFT edge, storage fabric), and their pairings for redundancy. Capture per-switch: rack and RU position, every connected port with its optic type (SFP+ SR/LR, DAC, or 40G QSFP+), uplink topology (vPC peer-link, port-channels, spanning-tree or routed uplinks), VLAN/VRF inventory, and the running NX-OS version and feature set. Flag any features the 3064 used that the FX3 implements differently, and note where 40G uplinks will move to 100G.
2. Optics, cabling, and feature parity
This is where a Nexus refresh quietly gets expensive. The 3064's SFP+ and QSFP+ optics and DACs do not all carry forward: the FX3's access ports are SFP28 (which accept 10G SFP+ optics but enable 25G with SFP28), and the uplinks are QSFP28 (which accept 40G QSFP+ but enable 100G with QSFP28). Decide per link whether you stay at the old speed or step up, then build an optics bill of materials — it is frequently a large fraction of the project cost. On the config side, NX-OS 9.x/10.x on the FX3 is close enough that most L2/L3, vPC, and routing syntax ports cleanly, but validate it in a lab: confirm vPC peer-keepalive and consistency, re-verify any QoS and buffer tuning against Cloud Scale's different buffer model, and if you are introducing VXLAN/EVPN, design the underlay and overlay deliberately rather than porting a flat L2 design.
3. Rack, power, and phased cutover
Both switches are 1RU with front-to-back or back-to-front airflow options — match the new units to your hot/cold aisle and confirm the FX3's higher power draw against your PDU and circuit budget before install. Stage the FX3 pair in parallel in adjacent RUs where possible, build and validate the config, then cut over rack by rack (or by redundant half of a vPC pair) during a maintenance window so one path always stays up. For latency-sensitive trading workloads, baseline the FX3's measured latency against the 3064 in your own traffic profile before you commit the production cutover.
4. Secure decommission
Once a 3064 is out of the path, do not just unrack it. Wipe the configuration and any stored credentials, certificates, and SNMP/TACACS secrets, then follow a documented sanitization and disposal process. For federal and DoD environments, retire the asset against your inventory system and capture a certificate of data destruction — the decommission record is part of the audit story, not an afterthought.
Procurement notes for regulated buyers
For US federal, DoD, and SLED buyers, confirm TAA compliance and country of origin on the new Nexus 9300 units, and order through an authorized Cisco partner so the hardware, Smart Licensing entitlements, and SmartNet/Solution Support all land in your contract correctly — gray-market Nexus gear routinely fails to license or register and carries no valid support. Data center optics and Cloud Scale switches can carry meaningful lead times, so place orders early and ask about GSA/GPC purchasing paths where applicable. As an authorized partner, uniqcli can scope the switch, the optics BOM, the license tier, and the support term as one quote. Browse current Nexus 9300 options on our catalog, review the full milestone record on the Nexus 3064 EoL detail page, or see every affected platform on our Cisco end-of-life hub.
Ready to scope the swap?: Send us your 3064 inventory and uplink topology and we will return a TAA-compliant Nexus 9300 (N9K-C93180YC-FX3) configuration with the optics, licensing tier, and support term priced in. Start at /get-a-quote.
The Nexus 3064 earned its place on the trading floor, but it has been unsupported and unpatchable since 2021. The 93180YC-FX3 keeps the low-latency, 1RU character you bought the 3064 for while adding 25G access, 100G uplinks, VXLAN/EVPN, MACsec, and a support runway that will outlast your next hardware cycle. Get a tailored migration quote and move the refresh from a standing audit risk to a scheduled, low-drama project.
Frequently asked questions
Is the Cisco Nexus 3064 (N3K-C3064PQ-10GE) still supported?
No. The Nexus 3064 reached End of Sale on June 30, 2016 and its Last Day of Support (LDoS) on June 30, 2021. After LDoS, Cisco provides no software updates, no PSIRT security patches, and no TAC support or RMA hardware replacement. Any unit still in production is unpatchable and unsupportable, which is both an operational risk and an audit finding for FedRAMP, CMMC, HIPAA, and PCI-regulated environments.
What replaces the Nexus 3064?
Cisco directs Nexus 3064 deployments to the Nexus 9300 fixed family. The representative replacement is the N9K-C93180YC-FX3, a 1RU switch with 48 ports at 1/10/25G (SFP28) and 6 uplinks at 40/100G (QSFP28). It delivers about 3.6 Tbps versus the 3064's 1.28 Tbps, runs the Cloud Scale ASIC with hardware VXLAN/EVPN, line-rate MACsec, and PTP, and still hits sub-microsecond cut-through latency for trading and HPC workloads.
Can I reuse my 3064's optics and DACs on the Nexus 9300?
Partially. The FX3's access ports are SFP28 and accept your existing 10G SFP+ optics, but you need SFP28 modules to reach 25G. The uplinks are QSFP28 and accept 40G QSFP+ optics, with QSFP28 required for 100G. Build a per-link optics bill of materials early, because optics are often a large share of the total refresh cost and can carry long lead times.
How does licensing change moving from the 3064 to the 93180YC-FX3?
The 3064 had no subscription licensing. The 93180YC-FX3 uses Cisco Smart Licensing Using Policy, with NX-OS Essentials and Advantage tiers (plus optional Day-2 Operations add-ons) tracked through a Smart Account. Essentials covers core L2/L3; Advantage unlocks VXLAN/EVPN and richer automation. Provision your Smart Account before deployment and budget the subscription term alongside the hardware.
Does the Nexus 9300 keep the low latency the 3064 was known for?
Yes. The 93180YC-FX3's Cloud Scale ASIC supports cut-through forwarding with sub-microsecond port-to-port latency that meets or beats the 3064 on the metric it was bought for, while adding hardware PTP timing and streaming telemetry. For latency-sensitive trading deployments, baseline the FX3 against the 3064 in your own traffic profile during staging before the production cutover.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read