Nexus 93128TX EoL: Migration to the Nexus 93108TC-FX3
The Nexus 93128TX (N9K-C93128TX) passed Last Day of Support on October 31, 2022. Here is what each milestone means, why the 93108TC-FX3 is the right copper-leaf successor, and a concrete, low-risk migration plan for federal, healthcare, and enterprise data centers.

If you are still running Cisco Nexus 93128TX switches (PID N9K-C93128TX) in a data center access row, they are now past every Cisco lifecycle milestone that matters. The 93128TX went End-of-Sale on October 30, 2017, and reached its Last Day of Support on October 31, 2022. From that LDoS date forward Cisco provides no NX-OS maintenance images, no PSIRT security fixes, and no TAC or RMA hardware replacement for this platform. The switch keeps forwarding frames at line rate, which is exactly why these units quietly outlive their support window in copper-cabled racks. This guide explains what the EoL dates mean for a switch still carrying production traffic, why the Nexus 93108TC-FX3 is a genuine upgrade rather than a like-for-like swap, and how to refresh cleanly with minimal fabric disruption.
What the Nexus 93128TX actually was
The 93128TX was a 1RU, 96-port 1/10GBASE-T fixed leaf built for copper-cabled server access. Its 96 RJ-45 downlinks ran 1G or 10G over Cat6a/Cat7, and a single modular uplink slot (the M12PQ GEM) added up to 8x 40G QSFP+ — or 4x 40G plus 8x 10G — for spine connectivity. Forwarding was handled by a Broadcom Trident II-class ASIC, giving roughly 2.56 Tbps of switching with cut-through and VXLAN bridging/routing in hardware. It ran standalone NX-OS or operated as an ACI leaf under an APIC. For a 2014-era 10GBASE-T access row terminating dual-attached servers, it was a workhorse. The catch is structural: it is a Trident II design, so it predates the deep buffers, telemetry, and 100G uplink economics that current leaf switches assume, and the copper PHYs top out at 10G with no multigigabit steps below that.
Why acting now matters
The danger of an EoL leaf switch is not that it fails — it is that it succeeds at forwarding traffic while the support floor disappears beneath it. After LDoS, three exposures compound:
- No PSIRT security fixes. When a new NX-OS vulnerability is disclosed — an SNMP, LLDP, BGP, or management-plane CVE — the 93128TX will never receive a fixed image. Its last NX-OS build is frozen, and any affected code path on this hardware is a permanent exposure with no vendor remediation.
- No TAC or RMA. A failed unit cannot be opened as a support case or swapped under a SmartNet/Solution Support contract. Recovery depends entirely on a spare you bought before LDoS or a secondary-market unit of the same dead-end model — a fragile position for a switch that may be the only path to a rack of servers.
- Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under — FedRAMP, CMMC, the HIPAA Security Rule, PCI DSS, and CISA directives — expect supported, patchable infrastructure. An unsupported switch that cannot be patched is an audit finding waiting to happen, and "the vendor no longer ships fixes" is not a defensible remediation plan.
There is also a software-floor trap. Current NX-OS 10.x releases and the latest ACI versions have dropped the older first-generation Nexus 9300 platforms. As you upgrade the rest of the fabric to a modern NX-OS train or an ACI version that supports current features, the 93128TX is left stranded on a frozen image — it cannot ride the upgrade, so it forces the fabric to stall at an older release or leaves an unsupported island in an otherwise patched data center.
What each milestone means in practice
- End of Sale (2017-10-30): the last day Cisco accepted new orders. Everything after this date is consuming the support tail.
- End of Software Maintenance: the last day Cisco released NX-OS maintenance and bug-fix images for the platform. After this, even non-security defects go unfixed.
- Last Day of Support / LDoS (2022-10-31): the hard wall. No TAC, no RMA, no patches of any kind. The hardware is on its own from this date forward.
The recommended replacement: Nexus 93108TC-FX3
Cisco's copper-leaf successor for this slot is the Nexus 93108TC-FX3 (PID N9K-C93108TC-FX3), a 1RU Cloud Scale leaf built on the LS1800FX3 ASIC. It is not a like-for-like swap — it is a generational jump on every axis that matters for a data center access row:
- Multigigabit copper, not just 10G. The 93108TC-FX3 provides 48x 100M/1G/2.5G/5G/10GBASE-T downlinks. Where the 93128TX could only do 1G or 10G, the FX3 adds 2.5G and 5G NBASE-T steps, so it terminates Wi-Fi 6/6E uplinks, multigig server NICs, and mixed-speed endpoints on the same Cat6a plant without forcing everything to one rate.
- Fixed 100G uplinks instead of a 40G module. Six built-in 40/100G QSFP28 uplinks replace the 93128TX's single 40G GEM slot. That is a fixed, non-modular spine path at 100G — no uplink card to source, fail, or run out of, and a clean fit for a 100G or 400G-capable spine.
- Cloud Scale ASIC with real telemetry. The FX3 brings hardware streaming telemetry (model-driven telemetry, sFlow/NetFlow-class flow visibility), larger and smarter shared buffers, and line-rate VXLAN EVPN bridging and routing — capabilities the Trident II-based 93128TX simply did not have.
- Line-rate security and timing. Native MACsec on the uplinks, plus PTP (IEEE 1588) and Synchronous Ethernet, make the FX3 suitable for environments with encryption-in-transit mandates or precise time requirements — common in federal, financial, and broadcast/OT data centers.
- Same operational model, modern code. It runs current NX-OS 10.x as a standalone/VXLAN-EVPN leaf or as an ACI leaf under an APIC, so it slots into either fabric type and stays on a supported software train for years.
Licensing: from NX-OS feature licenses to Smart Licensing
The 93128TX lived in the older NX-OS world of node-locked feature licenses (LAN Enterprise/Base PAKs, plus ACI tier entitlements on the APIC). The 93108TC-FX3 uses Smart Licensing Using Policy with the current NX-OS tiers — Essentials and Advantage, plus add-ons such as the security/MACsec tier — all tracked through your Smart Account and (for offline data centers) an on-prem Smart Software Manager satellite. In ACI, entitlement is consumed per leaf at the fabric tier. Budget the subscription term as its own line item, confirm your Smart Account is provisioned before deployment, and decide on connected vs. on-prem license reservation early — this is the step teams most often discover late.
A practical migration plan
1. Assessment and inventory
Pull an exact count of N9K-C93128TX units, their role (standalone NX-OS, VXLAN-EVPN leaf, or ACI leaf), and NX-OS/ACI version. For each switch capture per-port usage (how many of the 96 downlinks are actually live and at what speed), uplink GEM type and spine connections, vPC pairings, VLAN/VRF and VXLAN/EVPN mappings, and the structured-cabling run lengths. The live-port count drives how many 48-port FX3 leaves you need and confirms whether multigig steps would consolidate any mixed-speed endpoints.
2. Target design and license transition
Decide the target topology now: most copper rows land best as a vPC pair of 93108TC-FX3 leaves with dual 100G uplinks to the spine, or as two ACI leaves under the existing APIC. Provision the Smart Account and stage Smart Licensing before any switch is racked. If you are on ACI, confirm the FX3 is supported on your current APIC version and upgrade the controller/spines first if needed.
3. Config and feature parity
NX-OS configuration largely carries forward, but verify it rather than blind-pasting. Check that every feature the 93128TX used exists and is licensed on the FX3 tier you bought (VXLAN/EVPN, BGP, MACsec, PTP), revalidate buffer/QoS policies against the FX3's Cloud Scale buffer model, and confirm interface speed configs account for the new 2.5G/5G steps. For ACI, the leaf simply registers to the fabric and inherits policy — but confirm interface profiles and AAEPs map to the new port count.
4. Physical: rack, power, uplinks, optics, cabling
Plan rack and power for two FX3 leaves where one 93128TX sat, and confirm power feeds and airflow direction (port-side intake vs. exhaust) match the row. The big optics change is the spine path: you move from 40G QSFP+ on the old GEM to 40/100G QSFP28 on the FX3 — source the matching QSFP28 transceivers or 100G DAC/AOC and verify spine-side port availability. Copper downlinks reuse the existing Cat6a/Cat7 plant; validate runs support the multigig rates you intend to use.
5. Phased cutover and secure decommission
Stage the FX3 pair in parallel, bring up uplinks and verify EVPN/ACI adjacency before moving a single server. Cut over rack by rack (or vPC member by member) during maintenance windows, validating routing/bridging, vPC consistency, and east-west reachability after each move. Keep the 93128TX cabled but isolated as immediate rollback for the first window. Once stable, decommission securely: wipe NX-OS configuration and any stored credentials/keys, remove the device from monitoring and Smart Licensing, and follow your data-destruction and asset-disposal policy — important for federal and healthcare environments where the device touched regulated traffic.
Procurement notes for regulated buyers
Two things drive the timeline more than the technical work. First, lead times: current-generation leaf switches, QSFP28 optics, and Smart Licensing subscriptions all have to be quoted, approved, and sourced — start procurement before you schedule cutovers. Second, supply compliance: federal and SLED buyers should confirm Trade Agreements Act (TAA) compliance and the appropriate approved-products path for the platform. As an authorized Cisco partner, uniqcli sources TAA-compliant hardware, accepts the Government Purchase Card (GPC), and quotes the 93108TC-FX3 with the correct license tier, optics, and accessories so nothing is missing at install. Browse current Nexus and data center gear in our catalog, and see other retiring platforms on the Cisco end-of-life hub.
Frequently asked questions
When did the Cisco Nexus 93128TX reach end of life?
The Nexus 93128TX (N9K-C93128TX) went End-of-Sale on October 30, 2017, and reached its Last Day of Support (LDoS) on October 31, 2022. Past LDoS, Cisco provides no NX-OS security or bug-fix images and no TAC support or RMA hardware replacement, so any new vulnerability on the platform is a permanent, unremediated exposure.
What is the recommended replacement for the Nexus 93128TX?
The recommended copper-leaf successor is the Cisco Nexus 93108TC-FX3 (N9K-C93108TC-FX3), a Cloud Scale 1RU leaf with 48x 100M/1/2.5/5/10GBASE-T downlinks and 6x 40/100G QSFP28 uplinks. It runs current NX-OS 10.x standalone/VXLAN-EVPN or as an ACI leaf, and adds multigig copper, fixed 100G uplinks, MACsec, PTP, and hardware streaming telemetry the 93128TX lacked.
Is the 93108TC-FX3 a one-for-one swap for the 93128TX?
Not on density. The 93128TX had 96 copper downlinks in 1RU; the 93108TC-FX3 has 48. A fully used 93128TX typically maps to two FX3 leaves — often a vPC pair — which is also the modern, resilient design. You also move from a single 40G uplink module to six fixed 40/100G QSFP28 ports, so plan rack space, optics, and switch count accordingly.
Will my existing NX-OS configuration migrate to the 93108TC-FX3?
Most NX-OS configuration carries forward, but validate rather than blind-paste. Confirm every feature the 93128TX used is present and licensed on the FX3 Smart Licensing tier you purchase (VXLAN/EVPN, BGP, MACsec, PTP), revalidate QoS/buffer policy against the Cloud Scale buffer model, and account for the new 2.5G/5G interface speeds. In ACI, the new leaf registers to the fabric and inherits policy.
How does licensing change when moving to the 93108TC-FX3?
The 93128TX used older node-locked NX-OS feature PAKs. The 93108TC-FX3 uses Smart Licensing Using Policy with Essentials/Advantage tiers (plus a security add-on for MACsec), tracked through your Smart Account or an on-prem Smart Software Manager for offline data centers. Provision the Smart Account before deployment and budget the subscription term as its own procurement line item.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read