
If you still run Cisco Nexus 93120TX switches (PID N9K-C93120TX) as copper top-of-rack or leaf nodes, the lifecycle clock has fully run out. This 2RU access switch reached its Last Day of Support (LDoS) on February 28, 2025. From that date forward Cisco issues no software fixes, no PSIRT security patches, and provides no TAC case handling or RMA hardware replacement for this platform. The switch keeps forwarding frames at line rate, which is precisely why these units linger in racks long after the support floor has vanished. This guide explains what each end-of-life milestone means for a production fabric, why Cisco names the Nexus 93216TC-FX2 as the migration target, and how to plan a clean cutover without stranding your spine or your server cabling.
What the Nexus 93120TX actually was
The 93120TX (N9K-C93120TX) is a first-generation Nexus 9300 fixed switch: 96 ports of 1/10GBASE-T copper for server access, plus 6 uplinks of 40G via QSFP+. It carries roughly 2.4 Tbps of switching capacity and is built on a Broadcom T2-class ASIC. It runs NX-OS in standalone (NX-OS) mode only; it predates the Cloud Scale ASIC line, so it never supported Cisco ACI leaf operation, line-rate MACsec, or model-driven streaming telemetry. For 2015-era 10GBASE-T server farms it was a workhorse. In a 2026 data center being asked to feed 25G/100G spines, run encryption in the fabric, and stream telemetry to an analytics platform, it is a generation behind on every one of those axes.
Why acting now matters
The hazard of an end-of-life leaf switch is not that it fails; it is that it keeps working while the support model collapses underneath it. After LDoS three exposures stack up:
- No PSIRT security patches. When a new NX-OS vulnerability is disclosed, the 93120TX will not receive a fixed image. Its software is frozen at the 2021 maintenance cutoff, so any CVE touching that code path on this hardware is permanent and unremediable on-box.
- No TAC or RMA. A failed switch cannot be opened as a support case or swapped under a service contract. Your only recovery is a spare you bought before LDoS or a gray-market unit of the same dead-end model — neither of which is a defensible operational posture for a production fabric.
- Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under — FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS, and CISA directives — expect supported, patchable infrastructure. An unsupported switch that cannot receive fixes is an audit finding waiting to happen, and 'the vendor no longer ships patches' is not an acceptable remediation.
There is also a fabric-design trap. As you modernize spines to 100G and adopt VXLAN EVPN or ACI, the 40G-uplink, T2-class 93120TX becomes the bottleneck and the odd node out. It cannot encrypt with MACsec, cannot run as an ACI leaf, and cannot feed the telemetry pipeline the rest of your fabric depends on. The leaf ages out alongside the operating model it was built for.
What each milestone means in practice
- End of Sale (2020-02-29): the last day Cisco accepted new orders for the 93120TX. Everything after this date is consuming the support tail.
- End of SW Maintenance (2021-02-28): the last day Cisco released maintenance and bug-fix NX-OS images for the platform. After this, even non-security defects go unfixed.
- Last Day of Support / LDoS (2025-02-28): the hard wall. No TAC, no RMA, no patches of any kind. The hardware is fully on its own.
The recommended replacement: Nexus 93216TC-FX2
Cisco's bulletin names the Nexus 93216TC-FX2 (N9K-C93216TC-FX2) as the migration product, and it is a clean generational successor rather than a like-for-like reissue. It preserves the thing that made the 93120TX attractive — high-density 10GBASE-T copper in a compact 2RU chassis — while replacing everything underneath. It keeps the same 96 ports of 1/10GBASE-T for your existing copper-attached servers, so the access-side cabling story is largely unchanged.
- Doubled fabric and faster uplinks: ~4.32 Tbps of switching capacity versus 2.4 Tbps, with 12 uplinks of 40/100G QSFP28 versus the 93120TX's 6x 40G QSFP+. That moves your spine connectivity from a 40G ceiling to 100G and gives you twice the uplink port count for non-blocking leaf-spine designs.
- Cloud Scale ASIC: the FX2 drops the legacy T2-class silicon for Cisco's Cloud Scale ASIC, unlocking deeper buffers, larger forwarding tables, and the feature set modern fabrics require.
- Line-rate MACsec: the FX2 can encrypt links at wire speed — something the 93120TX simply cannot do — which is a frequent requirement for DoD and healthcare segments that need data-in-transit protection inside the data center.
- NX-OS or ACI: the same hardware boots as a standalone NX-OS switch or operates as a Cisco ACI leaf, so the FX2 fits whether you stay on NX-OS with VXLAN EVPN or adopt ACI later. The 93120TX was NX-OS standalone only.
- Model-driven streaming telemetry: gRPC/gNMI streaming telemetry feeds Nexus Dashboard Insights and third-party analytics in near-real-time, replacing the 93120TX's SNMP-poll and legacy NX-API model.
Licensing: Smart Licensing, not feature locks
The FX2 lives in the modern NX-OS Smart Licensing Using Policy model, with tiered entitlements (Essentials/Advantage, plus optional ACI tiers) managed in Cisco Smart Software Manager rather than the older per-feature PAK licenses common in the 93120TX era. Plan the license conversion as its own workstream: confirm which feature set each leaf needs (VXLAN EVPN and advanced telemetry typically require the Advantage tier), set up or reuse a Smart Account and Virtual Account, and decide between direct connect, an on-prem Smart Software Manager satellite, or offline reservation for air-gapped and classified environments. For TAA-regulated buyers, the offline reservation path is usually the right fit.
A practical migration plan
1. Assess and inventory
Pull a definitive inventory of every 93120TX: rack and unit position, NX-OS version, uplink count and speed, attached server ports, VLAN/VRF footprint, and the spine each one homes to. Capture running configs and the show inventory / show module output so you have an authoritative source for feature parity. If you are reconciling units you inherited, confirm each PID and serial before you order anything.
2. Establish config and feature parity
Map the 93120TX's NX-OS configuration onto the FX2. Most Layer 2/Layer 3, vPC, OSPF/BGP, and QoS constructs port directly, but validate the deltas: Cloud Scale TCAM carving, ACL scale, and any features the FX2 adds (MACsec, advanced telemetry) that you will want to enable as part of the refresh. Decide up front whether the FX2 leaves stay in NX-OS standalone or join an ACI fabric, because that choice shapes the rest of the cutover.
3. Physical: rack, power, uplinks, optics
Both switches are 2RU, so rack space is a wash. Confirm power and airflow direction (port-side intake vs exhaust) matches your hot/cold aisle. The big physical change is uplinks: stage QSFP28 optics or breakout cables for the 100G spine connections before the maintenance window. Pre-label and pre-route uplinks so the cutover is a swap, not a scavenger hunt.
4. Phased cutover
Migrate leaf by leaf rather than all at once. In a vPC pair, bring up one FX2, build the vPC peer-link and keepalive to its mate, move server ports in waves, validate forwarding and telemetry, then repeat for the second member. This keeps redundancy intact throughout and gives you a clean rollback per leaf if anything looks wrong.
5. Secure decommission
Once a 93120TX is drained, wipe NX-OS configuration and any stored credentials before the unit leaves the rack. For federal and healthcare environments, follow your media-sanitization standard (NIST SP 800-88) and obtain a certificate of data destruction. Browse current FX2 stock and optics on our catalog or the full catalog to line up replacements before you pull anything.
Procurement notes for regulated buyers
Buy the FX2 and its optics through an authorized Cisco partner so warranties, Smart Licensing entitlements, and Cisco SmartNet/Solution Support attach cleanly to your Smart Account. For US federal and DoD, confirm Trade Agreements Act (TAA) compliance and country of origin on each line, and plan for GPC/contract-vehicle purchasing where applicable. Cloud Scale switches and 100G optics can carry real lead times, so order ahead of your cutover window rather than at it. As an authorized partner, uniqcli can validate the bill of materials, confirm TAA status, and stage optics and licenses to match your migration schedule.
Compare every milestone date and the recommended successor on the Nexus 93120TX EoL detail page, browse other affected platforms in our Cisco end-of-life index, and when you are ready to scope the refresh, request a quote for a TAA-compliant 93216TC-FX2 build with optics and licensing matched to your fabric.
Frequently asked questions
Is the Cisco Nexus 93120TX still supported?
No. The 93120TX reached Last Day of Support on February 28, 2025. Cisco no longer provides software fixes, PSIRT security patches, TAC case handling, or RMA hardware replacement for this platform. Any switch still in production is running unsupported and unpatchable.
What is the recommended replacement for the Nexus 93120TX?
Cisco's bulletin names the Nexus 93216TC-FX2 (N9K-C93216TC-FX2) as the migration product. It keeps the same 96 ports of 1/10GBASE-T copper in 2RU but adds 12x 40/100G QSFP28 uplinks, ~4.32 Tbps of capacity, a Cloud Scale ASIC, line-rate MACsec, and NX-OS or ACI leaf operation.
Can I reuse my 40G optics and cabling when migrating to the 93216TC-FX2?
Only partially. The 93120TX uses 40G QSFP+ uplinks while the FX2 uses 40/100G QSFP28 cages. Existing 40G optics may seat, but to reach 100G you will need new QSFP28 transceivers or 100G-to-4x25G breakout cabling, so budget optics as a separate line item. The 96-port 10GBASE-T copper server cabling carries over unchanged.
Does the Nexus 93216TC-FX2 support Cisco ACI?
Yes. The FX2 is a Cloud Scale switch that boots as standalone NX-OS or operates as an ACI leaf with model-driven streaming telemetry. The 93120TX was NX-OS standalone only and could never run as an ACI leaf.
How does licensing change when moving to the 93216TC-FX2?
The FX2 uses NX-OS Smart Licensing Using Policy with tiered entitlements (Essentials/Advantage and optional ACI tiers) managed in Cisco Smart Software Manager, rather than the per-feature PAK licenses of the 93120TX era. Plan a Smart Account, choose direct/satellite/offline reservation, and use offline reservation for air-gapped or classified environments.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read