Uniqcli

Cisco Nexus 9396PX EoL: Migrate to Nexus 93180YC-FX3

The Nexus 9396PX (N9K-C9396PX) passed Last Day of Support on February 19, 2023 — here is why this original 9300 leaf has to come out and how to refresh cleanly to the Cloud Scale 93180YC-FX3.

UT
Uniqcli Team
April 2, 2026 · 10 min read
Share
Cisco Nexus 9396PX EoL: Migrate to Nexus 93180YC-FX3

If you still run Cisco Nexus 9396PX switches (PID N9K-C9396PX) as top-of-rack leaves, the lifecycle conversation is already over — you are now living past the end of it. This platform reached End of Sale on May 1, 2018, and its Last Day of Support (LDoS) was February 19, 2023. Every milestone has passed. From the LDoS date forward Cisco provides no NX-OS software fixes, no PSIRT security patches, and no TAC or RMA hardware replacement for this model. The switches keep forwarding frames exactly as they did in 2016, which is precisely why they linger in production racks long after the support floor vanished. This guide explains what each milestone means for a running fabric, why the recommended Nexus 93180YC-FX3 is a genuine generational jump rather than a like-for-like swap, and how to plan a controlled refresh.

What the Nexus 9396PX actually was

The 9396PX was the original workhorse of the Nexus 9300 line: a 2RU switch with 48 fixed ports of 1/10 Gigabit Ethernet on SFP+, plus a single modular uplink slot that took a 40G QSFP+ uplink module (commonly the N9K-M12PQ, giving up to 12 ports of 40G). That fixed-plus-module design is the defining trait of this generation. In standalone NX-OS it gave you a dense 10G leaf; populated with the right software and APIC controllers it became an ACI leaf in some of the first production application-centric fabrics Cisco shipped. For the spine-leaf designs of 2014–2016, where servers ran 10G NICs and 40G was the aspirational uplink speed, the 9396PX was a well-matched, capable box.

The limitations are structural, not tunable. Every downlink is capped at 10G, so the 9396PX cannot natively front the 25G NICs that ship as standard on current servers. Its uplinks top out at 40G via a separate module that is both a cost line and a single point of failure in the chassis. The first-generation Nexus 9300 ASIC predates the buffer architecture, table scale, and hardware overlay features that VXLAN/EVPN fabrics now assume, and 100G simply does not exist on this platform. It was the right leaf for its era; the rest of the data center moved past it.

Why acting now matters

With a platform already past LDoS, the risk is not a future deadline — it is the gap you are sitting in right now. Three exposures are live the moment LDoS passes, and for the 9396PX they have been live since February 2023:

  • No PSIRT security patches. When a new NX-OS vulnerability is disclosed, the 9396PX will not receive a fixed image. Whatever build it is frozen on is the build it dies on, and any CVE in that code path on this hardware is permanent and unremediable. The longer it runs, the more disclosed-but-unpatched issues accumulate against it.
  • No TAC or RMA. A failed unit cannot be opened as a support case or swapped under a service contract. Your only recovery is a spare you stockpiled before LDoS or a secondary-market unit of the same dead-end model — a fragile position for a switch carrying production east-west traffic.
  • Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under (FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS, and CISA BOD directives) expect supported, patchable infrastructure. An unsupported, unpatchable data-center switch is a finding waiting to be written, and 'the vendor no longer ships fixes' is not a defensible remediation plan.

There is also a fabric-aging trap. As you modernize ACI to current APIC trains, or move standalone NX-OS to the latest releases for VXLAN/EVPN features, first-generation 9300 leaves like the 9396PX fall out of the supported matrix. The leaf and the software you want to run on the rest of the fabric age out together, so deferring the swap quietly constrains every other upgrade in the rack.

What each milestone date means in practice

  • End of Sale (2018-05-01): the last day Cisco accepted new orders. Everything after this date drew down the support tail rather than extending it.
  • Last Day of Support / LDoS (2023-02-19): the hard wall, already crossed. No TAC, no RMA, no software or security fixes of any kind. The hardware has been entirely on its own for years, so this is remediation, not planning.
  • Because LDoS is already behind you, the runway is gone — the only remaining variables are how fast you can scope, fund, and stage the refresh, and how long fragile gray-market spares can paper over a failure in the meantime.

Cisco's migration path for the original 9300 leaves is the Nexus 9300-FX3 family, specifically the 93180YC-FX3 (N9K-C93180YC-FX3). It is built on Cisco's Cloud Scale ASIC and is a different class of machine. In a single 1RU box — half the rack height of the 2RU 9396PX — you get 48 downlink ports at 1/10/25-Gbps (SFP28) plus 6 built-in uplink ports at 40/100-Gbps (QSFP28), for 3.6 Tbps of switching capacity. The fixed-plus-module compromise of the 9396PX is gone: the uplinks are integrated, every downlink reaches 25G, and every uplink reaches 100G — the two speeds the older switch could not touch.

For this product type, the concrete gains over the 9396PX are:

  • 25G to the server, 100G to the spine. Current compute ships 25G NICs and modern leaf-spine fabrics are 100G. The FX3 speaks both natively, while existing 10G servers simply reuse SFP+ optics in the SFP28 cages — no breakout or media-conversion gymnastics that a 10G-only, 40G-uplink 9396PX forces.
  • Integrated, redundant uplinks. The six built-in QSFP28 ports replace the separate 9396PX uplink module entirely, removing a chassis component that was both a cost line and a failure point, while still auto-negotiating 40G for backward compatibility.
  • VXLAN/EVPN and dual-mode operation. The FX3 runs standalone NX-OS or as an ACI leaf, with hardware VXLAN bridging and routing plus EVPN — the modern overlay and spine-leaf scale the first-generation 9396PX ASIC never had.
  • Line-rate security and telemetry. MACsec encryption on the ports, plus streaming telemetry, sFlow, and Cloud Scale flow-table analytics, deliver the data-in-motion protection and east-west visibility that compliance regimes increasingly require and the 9396PX could not provide.
  • NX-OS Smart Licensing. The FX3 uses Smart Licensing Using Policy with tiered NX-OS feature licenses (Essentials and Advantage, with optional add-ons). Entitlements live in your Smart Account and follow the deployment rather than being baked into a per-box feature set, which simplifies audits and true-ups versus the pre-Smart-Licensing 9396PX era.
  • Lower footprint, higher density. Moving from a 2RU 48x10G box to a 1RU 48x25G box recovers rack units, power, and cooling headroom while increasing per-rack bandwidth — a meaningful TCO swing across a fleet of leaves.

A practical migration plan

1. Assessment and inventory

Pull the exact PID, serial, NX-OS or ACI software version, uplink module type, and per-port utilization from every 9396PX in the fabric. Flag which downlinks are doing real 10G work versus sitting idle, capture VLAN/VXLAN mappings, VRFs, port-channels, and the spine/APIC connectivity each leaf carries. Note any 9396PX co-resident with other EoL Nexus gear so you size one combined refresh rather than several. This inventory is also exactly what an authorized partner needs to quote accurately and to confirm TAA status on the replacements.

2. License transition

Stand up (or confirm) a Cisco Smart Account and Virtual Account before hardware lands. Map the NX-OS features you actually use on the 9396PX to the FX3 tiers — most leaf functions land in Essentials, while VXLAN/EVPN and advanced segmentation pull in Advantage. Pre-stage the licenses so the new switches register on first boot instead of running in evaluation mode, and resolve any ACI controller licensing in the same pass if the fabric is APIC-managed.

3. Config and feature parity

Do not blind-paste old configs. NX-OS has moved on substantially since the 9396PX's era, and first-generation 9300 constructs do not all map one-to-one onto Cloud Scale. Rebuild the config around FX3 equivalents — interface speeds, port-channels, VXLAN/EVPN where you are modernizing the overlay, QoS, and any NAT or PBR in use — and run a configuration diff against the legacy leaf so nothing silently drops. For ACI fabrics, validate the FX3 leaf profile and policy in a staging pod before it joins production. Lab-validate against your actual traffic profile before any production port moves.

The FX3 is 1RU versus the 9396PX's 2RU, so you recover rack space, but confirm per-rack power budget and that front-to-back versus back-to-front airflow matches your hot and cold aisle orientation. Plan optics deliberately: existing 10G servers can reuse SFP+ optics in the SFP28 cages, and 40G QSFP+ uplinks from the old module port into the FX3's QSFP28 cages for backward compatibility — but the upgrade value is in moving servers to 25G (SFP28) and spines to 100G (QSFP28). Optics and DAC/AOC cabling are frequently the longest-lead and most underestimated line items, so order them with the switches, not after.

5. Phased cutover

Migrate leaf by leaf, never the whole fabric at once. Cable an FX3 in parallel with the 9396PX it replaces, bring it up on the spine (or as an ACI leaf under APIC), validate routing, overlay, and port-channel/vPC behavior, then move server connections in maintenance windows. In a vPC pair, replace one peer at a time so the rack never loses redundancy. Keep the old switch powered and reversible until the new leaf has carried production load cleanly through a full business cycle.

6. Secure decommission

Once retired, wipe NX-OS configuration and any stored credentials, keys, and certificates, then dispose through a process that satisfies your data-handling and chain-of-custody requirements: NIST SP 800-88 media sanitization and a certificate of destruction for federal, DoD, and healthcare environments. Remove the switch from APIC/NMS inventory and monitoring. Do not let a decommissioned leaf with live config and keys sit on a shelf or leak into the secondary market.

Procurement notes for regulated buyers

For federal, DoD, and SLED purchases, confirm TAA-compliant country of origin and request the relevant documentation up front; the 93180YC-FX3 is available in TAA-compliant configurations through authorized channels. If you buy on a GSA schedule or via Government Purchase Card (GPC), line up the SKUs, optics, and NX-OS licenses against that vehicle early. Switch and optics lead times move with demand, and because the 9396PX is already past LDoS this is overdue remediation — scope and order ahead of any further failures rather than waiting on a unit you can no longer RMA. Buying through an authorized Cisco partner protects warranty, Smart Licensing entitlement, and TAA traceability; gray-market FX3 or used 9396PX units can void support and break the very compliance posture you are refreshing to fix.

Start with the live milestone record on the Nexus 9396PX EoL detail page, browse the broader Cisco end-of-life catalog to catch other aging gear in the same racks, and check current Nexus 9300 availability and pricing. When you are ready to scope the refresh, get a quote and we will map your 9396PX fleet to TAA-compliant 93180YC-FX3 hardware, optics, and NX-OS licensing — and close the support gap you are already sitting in.

Frequently asked questions

Is the Cisco Nexus 9396PX (N9K-C9396PX) still supported?

No. The 9396PX reached End of Sale on May 1, 2018 and passed its Last Day of Support on February 19, 2023. Cisco no longer issues NX-OS software fixes, PSIRT security patches, or TAC and RMA hardware replacement for this platform. It still forwards traffic, but it is unpatchable and unsupported, which is a direct audit and compliance liability for regulated buyers.

What replaces the Nexus 9396PX?

Cisco's migration path is the Nexus 9300-FX3 family, specifically the 93180YC-FX3 (N9K-C93180YC-FX3). It delivers 48 ports of 1/10/25G (SFP28) plus 6 ports of 40/100G (QSFP28) — 3.6 Tbps — on the Cloud Scale ASIC, with native 25G to the server and 100G to the spine that the original 1/10G 9396PX could never reach without breakout penalties.

My 9396PX uses a 40G uplink module — does the FX3 still give me 40G and add 100G?

Yes. The 9396PX took a separate uplink module (such as the M12PQ) to get 40G QSFP+ uplinks on top of its 48 fixed 1/10G SFP+ downlinks. The 93180YC-FX3 has 6 built-in QSFP28 uplinks that auto-negotiate 40G and 100G, so you keep 40G compatibility, gain 100G, and eliminate the separate, single-point-of-failure uplink module entirely.

Can the FX3 run in my existing ACI fabric?

Yes. The 93180YC-FX3 operates as either a standalone NX-OS switch or an ACI leaf, the same dual-mode role the 9396PX filled in early ACI fabrics. Confirm your APIC controllers are on a software train that supports the FX3 before you stage leaves, and migrate within a maintenance window leaf by leaf so the fabric never loses redundancy.

Should I just buy used 9396PX units to extend the fabric?

It is strongly discouraged. The 9396PX is past every lifecycle milestone, so any unit you acquire is unsupported and unpatchable on arrival and is almost always gray-market with no clean Smart Licensing entitlement. For federal, DoD, and healthcare buyers that deepens the audit problem rather than solving it. Refresh to TAA-compliant FX3 hardware through an authorized Cisco partner instead.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote