Uniqcli

Nexus 5672UP-16G EoL: Migration to Nexus 9300 93180YC-FX

The Nexus 5672UP-16G reaches Last Day of Support on May 31, 2026 — here's why it has to come out and how to migrate cleanly to the 25G/100G Nexus 9300 (N9K-C93180YC-FX).

UT
Uniqcli Team
February 5, 2026 · 10 min read
Share
Nexus 5672UP-16G EoL: Migration to Nexus 9300 93180YC-FX

If you still have Cisco Nexus 5672UP-16G switches (PID N5K-C5672UP-16G) carrying production traffic in a data center, top-of-rack, or SAN-attached row, the lifecycle clock on this platform is nearly out. End of Sale passed on May 5, 2021, software maintenance ended on May 5, 2022, and the Last Day of Support (LDoS) lands on May 31, 2026. After that final date Cisco provides no software fixes, no PSIRT security patches, and no TAC or RMA hardware replacement for this model. The switch will keep forwarding frames, which is exactly why these units quietly stay racked long past the point where they should have been replaced. This guide explains what each milestone means for a live fabric, why the recommended Nexus 9300 (N9K-C93180YC-FX) is a genuine generational upgrade rather than a like-for-like swap, and how to plan a clean migration off NX-OS 7.x onto the Nexus 9000 line.

What the Nexus 5672UP-16G actually was

The 5672UP-16G is a 1RU fixed Nexus 5600-series leaf switch built around unified ports. It provides 48 SFP+ ports running 1/10 Gigabit Ethernet, of which a block of 16 are true unified ports capable of 16G Fibre Channel as well as Ethernet/FCoE — that 16G-FC capability is what the '16G' in the name denotes and what made this switch attractive for converged SAN-attached racks. Above the 48 access ports sit 6 QSFP+ uplinks at 40GbE. The platform runs NX-OS (the 7.x train), supports FCoE and native Fibre Channel, vPC, FEX aggregation (it was a common parent switch for Nexus 2000 fabric extenders), and line-rate Layer 2/Layer 3 forwarding with cut-through switching and a hardware buffer architecture tuned for low latency. For a 2015-era 10G/16G-FC converged top-of-rack design it was an excellent fit. Against 25G/100G server connectivity and modern leaf-spine fabrics, its 10G access and 40G uplinks are the ceiling, not the floor.

Why acting now matters

The danger of an end-of-life data center switch is not that it fails — it is that it keeps running while the support floor disappears underneath it. For a switch that sits in the forwarding path of every server in a rack, three exposures compound after LDoS:

  • No PSIRT security patches. When a new NX-OS vulnerability is disclosed — and the Nexus line gets regular PSIRT advisories covering everything from BGP and management-plane bugs to FCoE and image-signing issues — the 5672UP-16G will not receive a fixed image. Its software is already frozen at the 2022 maintenance cutoff, so any CVE touching that code on this hardware is permanent and unremediable.
  • No TAC or RMA. After May 31, 2026 a failed unit cannot be opened as a support case or swapped under a service contract. In a data center that often means a single hardware failure takes down a whole rack's worth of dual-homed servers with no vendor recovery path — your only fallback is a cold spare bought before LDoS or a gray-market unit of the same dead-end model.
  • Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under (FedRAMP, CMMC, the HIPAA Security Rule, PCI DSS, and CISA directives) expect supported, patchable infrastructure. An unsupported switch that cannot receive patches is a standing audit finding, and 'the vendor no longer ships fixes for this device' is not a defensible remediation plan.

There is also a software dead-end specific to this platform. The Nexus 5600 line tops out on the NX-OS 7.3 maintenance train; it never moved to the NX-OS 9.x / 10.x code that the Nexus 9000 family runs. As you modernize automation, telemetry, and security tooling around current NX-OS, the 5672UP-16G is stranded on a code base that no longer gets features or fixes. The hardware and its software age out together.

What each milestone means in practice

  • End of Sale (2021-05-05): the last day Cisco accepted new orders for the N5K-C5672UP-16G. Everything since has been consuming the support tail.
  • End of Software Maintenance (2022-05-05): the last day Cisco released maintenance and bug-fix images. Since then even non-security defects go unfixed, and the NX-OS build on these switches is effectively static.
  • Last Day of Support / LDoS (2026-05-31): the hard wall. No TAC, no RMA, no patches of any kind. After this date the switch is entirely on its own.

Cisco's EoL bulletin maps the 5672UP-16G directly to the Nexus 9300 (N9K-C93180YC-FX). This is a 1RU fixed Nexus 9000 leaf with 48 ports of 1/10/25 Gigabit Ethernet plus 6 ports of 40/100 Gigabit Ethernet QSFP28 uplinks. Across every axis that matters for this switch's role, it is a clear step up:

  • Access speed: 25G to the server, not 10G. Each of the 48 SFP28 access ports runs 1/10/25G, so the same rack footprint that gave you 10G NIC connectivity now supports 25G server attach without re-cabling the port count. That is a 2.5x per-port ceiling for modern NICs and converged/hyperconverged nodes.
  • Uplinks: 100G, not 40G. The 6 QSFP28 uplinks run 40 or 100GbE, so leaf-to-spine bandwidth more than doubles per uplink versus the 5672's 40G QSFP+. The switch delivers roughly 3.6 Tbps of forwarding throughput at line rate.
  • MACsec line-rate encryption. The -FX supports IEEE 802.1AE MACsec on its ports — wire-speed Layer 2 encryption that the 5672UP-16G does not offer. For DoD, federal, and healthcare data-in-transit requirements this is often the single feature that justifies the refresh on its own.
  • Cloud Scale ASIC and telemetry. The 93180YC-FX is built on Cisco's Cloud Scale silicon with hardware streaming telemetry, flow analytics (FT/NetFlow-class visibility), and far deeper, smarter buffering than the 5600 generation — directly relevant to bursty storage and east-west data center traffic.
  • NX-OS or ACI mode. The same hardware can run standalone NX-OS (with NX-OS 9.x/10.x feature parity, model-driven programmability, and gNMI/gRPC telemetry) or operate as an ACI leaf if you are moving toward an application-centric fabric. The 5600 line could do neither.

Licensing: the model has changed

The 5672UP-16G used the older Nexus per-feature licensing model (LAN Enterprise, Storage/FC, FEX, and similar PAK-based licenses installed on the switch). The Nexus 9300 uses Cisco Smart Licensing with the NX-OS tiered model — Essentials and Advantage subscriptions plus optional add-ons such as the Day-2 Operations / telemetry tier — all tracked through your Smart Account and a Smart Licensing Using Policy (SLP) workflow. Budget for the subscription term, not just the hardware, confirm your Smart Account is provisioned before deployment, and map each legacy feature license to its Smart Licensing equivalent so nothing you rely on (L3 routing, FCoE, telemetry) lands unlicensed. This is the line item teams most often forget.

A practical migration plan

1. Assessment and inventory

Pull an exact count of N5K-C5672UP-16G units and document each one's role: standalone leaf, vPC pair member, or FEX parent. Capture per-switch port usage (10G Ethernet vs. 16G-FC unified ports vs. FCoE), attached FEX models, vPC peer relationships, uplink optics (40G QSFP+ types), VLAN/VRF and routing config, and the current NX-OS 7.x version. Flag every native Fibre Channel port — that inventory drives the SAN decision above.

2. License transition

Provision or confirm your Smart Account, then map legacy per-feature licenses to NX-OS Smart Licensing tiers (Essentials/Advantage and any telemetry add-on). Stage licensing before the first switch ships so the 93180YC-FX comes up entitled rather than in evaluation mode.

3. Config and feature parity

Rebuild the configuration on the target NX-OS 9.x/10.x release: vPC domains and peer-links, port-channels, VLAN/VRF/SVI layout, L3 routing (OSPF/BGP), QoS, and FCoE or FEX where used. NX-OS 9.x changes some defaults and syntax versus 7.x, so do not assume a copy-paste config will apply cleanly — diff it. Decide upfront whether to enable MACsec on uplinks or access ports, and validate it end to end before cutover since it is new behavior the 5600 never carried.

The 93180YC-FX is 1RU like the 5672, so rack space is a wash, but check power and optics carefully. Uplinks move from 40G QSFP+ to 40/100G QSFP28 — existing 40G optics may carry over, but 100G uplinks need new QSFP28 optics and the right fiber. Access ports move from SFP+ to SFP28; 10G SFP+ optics generally work in 25G-capable ports, but plan optics for any new 25G server attach. Confirm PSU type and data-center power/cooling, and remember Nexus 9300 leaf switches form leaf-spine fabrics rather than a stack — there is no StackWise here, so the redundancy model is vPC pairs and ECMP uplinks, which you design rather than cable into a ring.

5. Phased cutover

Migrate rack by rack, not all at once. Stand up the new 93180YC-FX (or vPC pair) alongside the existing 5672s, migrate one rack's server uplinks and storage paths, validate forwarding, vPC consistency, FCoE/FC reachability, and any MACsec sessions, then proceed. Keeping dual-homed servers split across old and new during the transition lets you fall back with a cable move rather than a rebuild.

6. Secure decommission

Decommissioned 5672UP-16G switches still hold running and startup configs, credentials, SNMP/AAA secrets, and certificates. Erase the configuration and wipe each unit before it leaves the rack, remove it from NMS, CMDB, and Smart Licensing records, and for federal and healthcare environments follow your media-sanitization and asset-disposal policy (NIST SP 800-88-style handling) with documented chain of custody.

Procurement notes for government and enterprise buyers

Source the Nexus 9300 replacements through an authorized Cisco partner. For US federal, DoD, and SLED buyers, confirm TAA compliance and country-of-origin documentation up front, validate genuine Cisco serials and clean Smart Licensing entitlement, and plan for current data-center switching lead times rather than assuming stock — Nexus 9000 lead times and optics availability both fluctuate. Government Purchase Card (GPC) orders, contract vehicles, and quote-to-PO timelines all benefit from engaging the partner early so licensing, TAA paperwork, optics, and delivery line up with your fiscal calendar. Buying used or gray-market 5672UP-16G units to extend a dead platform only deepens the audit and support problem.

Ready to scope the swap? Review the full milestone detail for this model on the N5K-C5672UP-16G EoL page, browse current Nexus 9000 switching and optics in our catalog, and see the broader migration picture on the Cisco EoL hub. When you are ready, get a refresh quote and we will size the 93180YC-FX fabric, MACsec licensing, any MDS SAN move, and optics to your racks.

Frequently asked questions

Is the Cisco Nexus 5672UP-16G (N5K-C5672UP-16G) still supported?

Only until May 31, 2026, its Last Day of Support. Software maintenance already ended on May 5, 2022, so the switch gets no new bug fixes today. After LDoS, Cisco provides no security patches, no software fixes, no TAC support, and no RMA hardware replacement. The switch still forwards traffic, but it becomes unpatchable and unsupported, which creates real audit and compliance exposure.

What is the direct replacement for the Nexus 5672UP-16G?

Cisco's EoL bulletin maps it to the Nexus 9300 (N9K-C93180YC-FX), a 1RU fixed leaf with 48 ports of 1/10/25G plus 6 ports of 40/100G uplinks, built on Cloud Scale silicon with line-rate MACsec encryption and streaming telemetry. It runs standalone NX-OS or in ACI mode, both of which the 5600 line could not do.

What does the Nexus 9300 (93180YC-FX) gain over the 5672UP-16G?

Server access moves from 10G to 25G across the same 48 ports, uplinks move from 40G QSFP+ to 40/100G QSFP28, and total throughput rises to roughly 3.6 Tbps. It adds IEEE 802.1AE MACsec line-rate encryption, hardware streaming telemetry and flow analytics on Cloud Scale ASICs, and a current NX-OS 9.x/10.x code base versus the frozen NX-OS 7.3 train on the 5600.

What happens to my 16G Fibre Channel ports when I migrate?

That is the one capability that does not carry straight across. The 5672UP-16G had unified ports that could run native 16G Fibre Channel, but the 93180YC-FX is an Ethernet/FCoE leaf, not an FC switch. Inventory your native FC ports first, then decide to either keep storage on FCoE or move native Fibre Channel onto a Cisco MDS 9000 fabric (for example MDS 9148T/9396T 32G FC).

Does migrating off the 5672UP-16G change Cisco licensing?

Yes. The 5672UP-16G used the older Nexus per-feature (PAK-based) license model — LAN Enterprise, Storage/FC, FEX, and so on. The Nexus 9300 uses Cisco Smart Licensing with NX-OS Essentials/Advantage tiers plus optional telemetry add-ons, tracked in a Smart Account via Smart Licensing Using Policy. Provision the Smart Account and map every legacy feature license to its Smart Licensing equivalent before deployment.

Can I just buy more 5672UP-16G units to extend the deployment?

It's strongly discouraged. The switch passes its Last Day of Support on May 31, 2026, so any units you buy are unsupported and unpatchable, and they're typically gray-market. For government and healthcare buyers this deepens the audit problem rather than solving it. Refresh to the supported Nexus 9300 from an authorized Cisco partner instead.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote