Uniqcli

Nexus 9372PX EoL: Migrate to the Nexus 93180YC-FX

The Nexus 9372PX (N9K-C9372PX) passed Last Day of Support on February 28, 2023. Here is what each milestone means, why a first-gen 10G leaf has to come out, and how to refresh cleanly to the Cloud Scale Nexus 93180YC-FX.

UT
Uniqcli Team
February 12, 2026 · 8 min read
Share
Nexus 9372PX EoL: Migrate to the Nexus 93180YC-FX

If you still have Cisco Nexus 9372PX switches (PID N9K-C9372PX) carrying production traffic in a top-of-rack or leaf position, they are now past every Cisco lifecycle milestone that matters. The 9372PX reached its Last Day of Support on February 28, 2023. From that date forward Cisco provides no NX-OS or ACI software maintenance, no PSIRT security patches, and no TAC support or RMA hardware replacement for this platform. The switch still forwards at line rate, which is precisely why these first-generation leaves quietly persist in racks years after they should have been retired. This guide explains what the end-of-life dates actually mean for a running fabric, why the recommended Nexus 93180YC-FX is a real generational upgrade rather than a cosmetic swap, and how to plan a controlled refresh.

What the Nexus 9372PX actually was

The 9372PX is a first-generation Nexus 9300 leaf in a 1RU chassis: 48 fixed 10-Gbps SFP+ downlink ports and 6 fixed 40-Gbps QSFP+ uplink ports, delivering 1.44 Tbps of switching bandwidth and over 1,150 million packets per second, all at line rate. It boots in either standalone Cisco NX-OS mode or as an ACI fabric leaf under an APIC controller, which made it a popular building block for early spine-leaf data centers and VXLAN designs around 2014 to 2016. Its limitation is architectural: the downlinks are locked at 10G with no 25G option, the uplinks top out at 40G with no 100G path, and it predates Cisco's Cloud Scale ASIC family. For a 10G-centric server estate it was a strong leaf. For 25G NICs, 100G spines, and the buffer and telemetry demands of a modern fabric, it is a hard ceiling.

Why acting now matters

The risk of an end-of-life data center switch is not that it stops working. It is that it keeps working while the support floor disappears beneath it. After LDoS, three exposures compound on a 9372PX:

  • No PSIRT security patches. When a new NX-OS or ACI vulnerability is disclosed, the 9372PX receives no fixed image. Its last software build is frozen at the 2019 maintenance cutoff, so any CVE touching that code path on this hardware is permanent. In a data center fabric the switch often sits in the management and east-west path, so an unpatched leaf is not a low-value target.
  • No TAC or RMA. A failed switch cannot be opened as a support case or swapped under a service contract. Recovery depends entirely on a cold spare you bought before LDoS or a secondary-market unit of the same dead-end platform, with no Cisco backstop on either.
  • Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under (FedRAMP, CMMC, the HIPAA Security Rule, PCI DSS, and CISA directives) all expect supported, patchable infrastructure. An unsupported switch that cannot receive fixes is a finding waiting to surface, and 'the vendor no longer ships patches' is not a defensible remediation plan in an assessment.

There is also a software-floor trap. As you modernize spines and adopt current NX-OS releases or newer APIC versions, the 9372PX is left stranded on older code that the rest of the fabric is moving past. The first-generation leaf and the software train age out together, and eventually the only way to stay on a supported release across the fabric is to retire the 9372PX anyway.

What each milestone means in practice

  • End of Sale (2018-02-03): the last day Cisco accepted new orders for the 9372PX. Everything after this date has been consuming the support tail.
  • End of Software Maintenance (2019-02-03): the last day Cisco released maintenance and bug-fix images. After this, even non-security defects go unfixed.
  • Last Day of Support / LDoS (2023-02-28): the hard wall. No TAC, no RMA, no patches of any kind. The hardware is operating without a safety net.

Cisco's EoL guidance points 9372PX customers to the Nexus 9300-EX and 9300-FX series, and the Nexus 93180YC-FX (N9K-C93180YC-FX) is the representative one-for-one refresh. It keeps the familiar 1RU, 48-plus-6 layout but rebuilds it on the Cloud Scale ASIC. The 48 downlink ports run 1, 10, or 25 Gbps, and the 6 uplink ports run 40 or 100 Gbps, lifting total bandwidth from 1.44 Tbps to 3.6 Tbps at sub-microsecond latency. Where it concretely beats the 9372PX:

  • 25G to the server, 100G to the spine. The downlinks move from fixed 10G to 1/10/25G, and the uplinks from 40G-only to 40/100G. That is the single biggest reason to refresh: modern server NICs are 25G, and modern spines are 100G, neither of which the 9372PX can reach.
  • Cloud Scale ASIC with a large shared buffer. A 40 MB fully shared buffer absorbs incast and microbursts far better than the first-generation 9372PX silicon, which matters for storage, AI/ML, and bursty east-west workloads.
  • Built-in streaming telemetry and analytics. The FX generation supports hardware flow telemetry and model-driven streaming telemetry feeding Nexus Dashboard, replacing the SNMP-era visibility the 9372PX was built around.
  • Unified ports. The 48 downlinks can also serve as 16/32G Fibre Channel, so the same switch can act as a FC or FCoE access layer, an option the 9372PX never had.
  • NX-OS or ACI, same as before. The 93180YC-FX boots standalone NX-OS or as an ACI leaf, so it preserves your existing operating model whether you run a CLI-managed fabric or an APIC-driven one.

For environments standardizing on a single SKU across racks, the 93180YC-FX is an easy line item to pull, and we keep current Nexus 9300 leaves and the matching SFP28 and QSFP28 optics available through our catalog.

A practical migration plan

1. Assessment and inventory

Start from the wire, not the spreadsheet. Pull the running configuration and 'show interface status' from each 9372PX to capture exactly which downlinks are in use, at what speed, and with which optics, plus all VLAN, VRF, VXLAN/EVPN, port-channel, and routing state. Record whether each switch runs standalone NX-OS or sits in an ACI fabric, because the migration path differs. Cross-reference every serial against the Cisco EoL hub so you have a defensible, dated record of what is unsupported and where it sits.

2. License transition

This is where the 9372PX era and the FX era diverge. The 9372PX largely predates Cisco's current subscription model; the 93180YC-FX uses NX-OS software tiers (Essentials and Advantage) plus optional Nexus Dashboard and Day-2 Ops add-ons, all administered through Smart Licensing. In an ACI fabric the leaf is licensed through the APIC tier. Map the features you actually use today to the correct FX tier, set up a Smart Account, and budget the subscription as a recurring cost rather than the perpetual licensing many teams associate with the older platform.

3. Config and feature-parity validation

Translate, then verify. Most NX-OS configuration carries forward, but validate feature parity explicitly: VXLAN EVPN behavior, port-channel and vPC peer settings, QoS and buffer policies (the larger Cloud Scale buffer can change shaping behavior), ACLs, and any telemetry or NetFlow/sFlow configuration. Confirm the target NX-OS or APIC release is on a supported train across the whole fabric, not just the new leaf. Build and test the config in a lab or a single non-production rack before touching production.

Both switches are 1RU with front-to-back or back-to-front airflow options, so rack and PDU planning is straightforward, though confirm the FX power and airflow SKU matches your hot/cold aisle. Optics are the detail that trips teams up: existing 10G SFP+ and 40G QSFP+ transceivers will operate in the 93180YC-FX, but realizing the upgrade means SFP28 optics or 25G DACs on the downlinks and QSFP28 on the 100G uplinks. Audit every transceiver against the FX compatibility matrix first, which matters doubly in TAA-restricted environments where optic sourcing is scrutinized.

5. Phased cutover

Refresh by rack or by fabric position, never all at once. In a vPC pair, replace one peer at a time so the surviving peer keeps the rack online, validating EVPN and port-channel convergence before swapping the second. In an ACI fabric, decommission and re-register one leaf at a time through the APIC. Keep a documented rollback for each window, and run a soak period on each new leaf before you treat the migration as complete.

6. Secure decommission

A retired 9372PX still holds configuration, credentials, certificates, and topology detail in NVRAM and flash. Before it leaves the rack, wipe the startup and running configuration, clear stored keys and certificates, and follow your media-sanitization standard (NIST SP 800-88 for federal and regulated environments). Capture the serials and disposition for your asset and audit records so the device is provably accounted for.

Procurement notes

For federal, DoD, and SLED buyers, source the 93180YC-FX as a TAA-compliant configuration and confirm country-of-origin documentation up front; the same applies to the SFP28 and QSFP28 optics, which are easy to overlook on a compliance review. Data center leaf hardware can carry real lead times, so order ahead of your cutover windows rather than against them. As an authorized Cisco partner, uniqcli can validate the right NX-OS or ACI license tier, build a TAA-conformant bill of materials including optics, and align delivery to your migration schedule.

Frequently asked questions

Is the Cisco Nexus 9372PX still safe to run after February 2023?

It still forwards traffic, but it is past Last Day of Support, so Cisco issues no NX-OS or ACI software fixes, no PSIRT security patches, and no TAC or RMA hardware replacement. Any new vulnerability that touches its frozen software image stays unpatched permanently, and a hardware failure means a cold-spare swap with no vendor support behind it. For FedRAMP, CMMC, HIPAA, and PCI environments, an unpatchable switch is a standing audit finding.

Is the Nexus 93180YC-FX a drop-in replacement for the 9372PX?

Physically it is close: both are 1RU, 48 SFP downlinks plus 6 QSFP uplinks, with similar power and airflow options. Functionally it is a generation ahead. The 9372PX downlinks are fixed 10G; the 93180YC-FX downlinks run 1/10/25G, the uplinks step from 40G to 40/100G, throughput jumps from 1.44 Tbps to 3.6 Tbps, and it adds the Cloud Scale ASIC, a 40 MB shared buffer, and unified Fibre Channel support. It is a refresh that buys capacity, not a like-for-like swap.

Can I reuse my existing optics and DACs from the 9372PX?

Your 10G SFP+ transceivers and 40G QSFP+ optics will operate in the 93180YC-FX, so a same-speed migration can reuse much of the existing cabling and optics. To gain the upgrade you are paying for, plan SFP28 optics or 25G DACs on the downlinks and QSFP28 on the 100G uplinks. Audit every transceiver against the 93180YC-FX compatibility matrix before cutover, especially in TAA-restricted environments where optic sourcing matters.

Does the licensing model change when moving to the 93180YC-FX?

Yes. The 9372PX predates Cisco's current Nexus subscription model. The 93180YC-FX uses NX-OS software tiers (Essentials and Advantage) plus optional Nexus Dashboard / Day-2 Ops add-ons, managed through Smart Licensing. In ACI fabrics, the switch is licensed per leaf through the APIC tier. Budget the subscription as a recurring line item rather than the one-time perpetual licensing many teams remember from the 9372PX era.

What is the difference between NX-OS mode and ACI mode for this migration?

Both the 9372PX and the 93180YC-FX can boot as a standalone NX-OS switch or as an ACI fabric leaf. If you run standalone NX-OS today, the cleanest path is NX-OS to NX-OS with config translation and feature-parity validation. If you are also modernizing toward an ACI or VXLAN EVPN fabric, the FX-generation hardware is the supported leaf, so a refresh is the natural moment to make that architectural move. Decide the target mode before you rack anything.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote