
If you still have Cisco Small Business SG300-28 switches (PID SG300-28-K9) humming in a wiring closet, the hardware may be passing traffic fine, but it is past every Cisco lifecycle milestone that matters. The SG300-28 went End of Sale on May 31, 2017 and reached its Last Day of Support (LDoS) on May 31, 2022. From that LDoS date forward, Cisco provides no firmware fixes, no security patches, and no TAC support or RMA hardware replacement for this model. A switch that quietly works is exactly how a 2013-era platform survives a decade past when it should have been retired. This guide explains what the EoL dates mean for a live network, why the recommended Cisco Business CBS350-24T-4G is a genuine refresh and not just a relabel, and how to plan a clean cutover.
What the SG300-28 actually was
The SG300-28 (SG300-28-K9) is a 28-port Layer 2/3 managed switch from Cisco's Small Business 300 Series, aimed at small offices and branch closets. It provides 24x 10/100/1000 RJ45 access ports plus 2 combo Gigabit uplinks (each uplink is a copper-or-SFP combo port, not a dedicated fiber port — using fiber costs you a copper port). It delivers 56 Gbps of non-blocking switching capacity and roughly 41.7 Mpps forwarding. Crucially, its routing is 'Layer 3 lite': static inter-VLAN routing only, with no support for dynamic routing protocols. This base SKU is non-PoE; PoE was a separate SG300 part number. Management is via a web UI or CLI, on firmware that froze years ago.
Why acting now matters
The danger with an end-of-life access switch is not that it dies — it is that it keeps working while the support floor disappears beneath it. Three concrete exposures stack up after LDoS:
- No PSIRT security patches. When a new switch-OS or web-management vulnerability is disclosed against the 300 Series code base, the SG300-28 will not receive a fixed image. Its firmware is permanently frozen at the pre-LDoS build, so any CVE that lands in that code path on this hardware is unfixable for the life of the unit.
- No TAC or RMA. A failed SG300-28 cannot be opened as a Cisco support case or swapped under contract. Your only recovery is a spare you bought before LDoS or a same-model unit from the secondary market — another dead-end switch with no support runway.
- Audit and compliance exposure. The frameworks federal, DoD, SLED, and healthcare buyers operate under (FedRAMP, CMMC, HIPAA Security Rule, PCI DSS, and CISA directives) expect supported, patchable infrastructure. An unpatchable managed switch sitting on your VLANs is an audit finding waiting to happen, and 'the vendor stopped shipping fixes in 2022' is not a defensible remediation answer.
There is also a feature trap. The SG300-28's static-only routing and aging web stack increasingly clash with modern segmentation, 802.1X/RADIUS, and IPv6 expectations. As the rest of the network modernizes, the SG300 becomes the brittle link that blocks rollouts you want everywhere else.
What each milestone means in practice
- End of Sale (2017-05-31): the last day Cisco accepted new orders for the SG300-28. Everything since has been consuming the support tail.
- Last Day of Support / LDoS (2022-05-31): the hard wall. No TAC, no RMA, no firmware or security fixes of any kind. From this date the hardware is entirely on its own.
The recommended replacement: Cisco Business CBS350-24T-4G
Cisco steers SG300-28 buyers to the Cisco Business 350 Series, and the CBS350-24T-4G (PID CBS350-24T-4G) is the direct modern equivalent. It keeps the same 24x 10/100/1000 access-port density and the same 56 Gbps switching capacity / ~41.66 Mpps forwarding, so it drops into the same role without overbuying. But it fixes the two things the SG300-28 got wrong for a closet uplink switch:
- Four dedicated Gigabit SFP uplinks instead of two combo ports. On the SG300-28, lighting up fiber meant sacrificing a copper port from the shared combo pair. The CBS350-24T-4G gives you four true, separate GbE SFP cages — full 24 copper ports plus four independent fiber uplinks — so you can build real redundant or ring uplinks to the distribution layer without stealing access ports.
- Full Layer 3 routing, not Layer 3 lite. The CBS350 adds dynamic routing on top of static, so it can participate in routed campus designs and inter-VLAN routing scenarios the SG300's static-only engine could never handle.
Beyond ports, the CBS350 modernizes the operating model. It is managed through the Cisco Business Dashboard and the Cisco Business mobile app (in addition to web UI and CLI), giving small-site teams centralized, multi-device monitoring and firmware management that the standalone SG300 web UI never offered — and, critically, it runs current, actively patched firmware. The CBS350 is a fixed-license switch (no DNA/Smart Licensing tier to buy or track), which keeps the small-office cost model the SG300 buyer expects, while restoring a real support and security-update runway.
A practical migration plan
1. Assess and inventory
Pull the running config from each SG300-28 and document VLANs, trunk/access port assignments, static routes, ACLs, SNMP, STP role, and any link aggregation. Note where the unit sits in the topology (access, or a small distribution doing static inter-VLAN routing) and which uplinks use the combo SFP ports today. Map serials to physical locations so each box has a named successor.
2. Config and feature parity
There is no direct config import from a 300 Series box to a CBS350 — rebuild the configuration on the new platform. Most settings map cleanly (VLANs, trunking, port security, STP, LACP). Two upgrades to plan for: the SG300's static routes can stay static or, where it helps, move to dynamic routing on the CBS350; and the four dedicated SFP uplinks let you redesign uplinks for redundancy instead of working around the combo-port limitation. Build a per-switch config sheet so cutover is paste-and-verify, not improvise.
3. Physical: rack, power, uplinks, optics
The CBS350-24T-4G is a standard 1RU fixed switch and slots into the same rack space and power footprint. Reuse compatible Cisco SFP optics where supported, but verify each transceiver against the CBS350 compatibility matrix before reusing it. Because uplinks move from combo to dedicated SFP cages, confirm fiber patching and DOM support during the rack stage, not at cutover.
4. Phased cutover
Stage and pre-configure the CBS350 on the bench, then cut over closet by closet during a maintenance window. Bring the new switch up alongside the old one, move uplinks first, validate routing and reachability, then migrate access ports in batches and watch for STP, VLAN, and PoE-budget issues before retiring the SG300.
5. Secure decommission
Erase the SG300-28 configuration (it holds VLAN topology, SNMP strings, and management credentials), record the serial against your asset register, and dispose through a certified, auditable channel — important for federal and healthcare chain-of-custody requirements. Do not resell or redeploy an LDoS switch into another part of the estate; that just relocates the unpatchable risk.
Procurement notes for regulated buyers
For US federal, DoD, and SLED purchases, confirm TAA compliance and country-of-origin on the specific CBS350 SKU before issuing a PO, and note that small-dollar refreshes often fit under the Government Purchase Card (GPC) threshold for fast turnaround. Because Cisco is retiring some CBS350 part numbers, lead times and SKU availability move — buy through an authorized Cisco partner who can confirm current stock, lock TAA documentation, and supply matching optics and any PoE variant in one order. Browse current models in our switch catalog, review the full lifecycle record on the SG300-28 EoL detail page or the broader Cisco end-of-life hub, and when you're ready to size the refresh, get a quote and we'll spec the right CBS350 configuration for your closets.
Frequently asked questions
Is the Cisco SG300-28 still supported?
No. The SG300-28 (SG300-28-K9) reached End of Sale on May 31, 2017 and its Last Day of Support on May 31, 2022. Cisco no longer provides firmware updates, security patches, or TAC/RMA support, so any new vulnerability on this model stays permanently unpatched.
What is the recommended replacement for the SG300-28?
Cisco directs SG300-28 buyers to the Cisco Business 350 Series, with the CBS350-24T-4G as the direct equivalent. It keeps the same 24 Gigabit access ports and 56 Gbps switching capacity while adding four dedicated SFP uplinks, full dynamic Layer 3 routing, current patched firmware, and Cisco Business Dashboard management.
How is the CBS350-24T-4G better than the SG300-28?
Same access density (24x GbE) and the same 56 Gbps / ~41.66 Mpps performance, but with four dedicated Gigabit SFP uplinks instead of two shared combo ports, full static-and-dynamic Layer 3 routing instead of static-only Layer 3 lite, centralized Cisco Business Dashboard/app management, and — most importantly — a supported, actively patched software stack.
Can I migrate the SG300-28 configuration directly to the CBS350?
No, there is no direct config import between the platforms. Document VLANs, port assignments, static routes, and ACLs from the SG300, then rebuild the configuration on the CBS350. Most settings map cleanly, and you can take advantage of the four dedicated uplinks and dynamic routing during the rebuild.
Does the CBS350-24T-4G require DNA or Smart Licensing?
No. The CBS350-24T-4G is a fixed-license Cisco Business switch — there is no DNA or per-feature subscription to purchase or track. That preserves the simple, low-cost ownership model SG300 buyers expect while restoring current firmware and security updates.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read