Uniqcli

Cisco Catalyst 3560V2 (WS-C3560V2-48PS-S) to Catalyst 9200 Migration Guide

The WS-C3560V2-48PS-S reached Last Day of Support on May 31, 2021 — no PSIRT patches, no TAC, no RMA. Here is a practical, specs-driven plan to migrate from the Fast Ethernet 3560V2 to the gigabit, IOS-XE Catalyst 9200 (C9200-48P-A).

UT
Uniqcli Team
May 13, 2026 · 7 min read
Share
Cisco Catalyst 3560V2 (WS-C3560V2-48PS-S) to Catalyst 9200 Migration Guide

If you still have a Cisco Catalyst 3560V2 (WS-C3560V2-48PS-S) carrying access-layer traffic in a wiring closet, it is well past the point where it should remain in production. This was a capable Layer 3 fixed-configuration access switch in its day — 48 ports of 10/100 Fast Ethernet with inline PoE and four SFP Gigabit uplinks — but it went End of Sale on May 31, 2016 and crossed its Last Day of Support (LDoS) on May 31, 2021. From an engineering, security, and compliance standpoint, every day it stays racked is borrowed time. This guide explains exactly what the milestone dates mean for this PID, why the gap matters, and how to migrate cleanly to the current fixed-access replacement, the Catalyst 9200 (C9200-48P-A).

The 3560V2 EoL situation, and why acting now is non-negotiable

End-of-life on a Cisco platform is not a single switch-off; it is a sequence of milestones that progressively strip away support. The WS-C3560V2-48PS-S hit the final and most consequential one — LDoS — in 2021. After that date, the entitlement you paid for simply stops existing.

  • End of Sale (2016-05-31): the last day Cisco accepted new orders for this PID. After this, the only sources are secondary-market or remaining channel stock — relevant if you are trying to grow or maintain a 3560V2 footprint.
  • End of SW Maintenance (n/a for this model): the 3560V2 ran classic IOS (12.2 trains), not IOS-XE. Software maintenance and the LDoS effectively converged at the support cutoff, so there is no separate ongoing software-fix window to lean on.
  • Last Day of Support / LDoS (2021-05-31): the hard line. After this date Cisco TAC will not open cases, RMA hardware replacement ends, and — critically — Cisco PSIRT issues no further security fixes for the platform.

No patches, no RMA, no exceptions: Once a platform is past LDoS, a new IOS CVE against it is permanent. There is no fixed release to upgrade to. For any organization under FISMA, FedRAMP, HIPAA, PCI-DSS, or CMMC, running hardware that can no longer receive security patches is a finding waiting to happen — auditors increasingly flag past-LDoS gear as an unmitigated risk by definition.

There is also a quiet operational risk. The 3560V2 family is old enough that field failure rates climb, and with RMA gone, a dead switch means an emergency same-day scramble for a used unit of unknown provenance. Pull the current support status for your exact unit on the WS-C3560V2-48PS-S end-of-life page before you plan a budget cycle around it.

The replacement: Catalyst 9200 (C9200-48P-A) and what actually changes

Cisco positions the Catalyst 9200 as the direct fixed-access successor to the 3560/3650-class access switch. The C9200-48P-A is the closest one-for-one match to a 48-port PoE 3560V2: same port count, same role, but a generational leap in nearly every spec that matters. The differences are not cosmetic — they remove the constraints that defined the 3560V2.

Ports, speed, and PoE

  • Gigabit, not Fast Ethernet: the 3560V2-48PS gave you 48 ports of 10/100. The C9200-48P-A delivers 48 ports of 10/100/1000 — a 10x per-port jump that finally matches modern endpoints, Wi-Fi 6 APs, and IP cameras that saturate a 100 Mbps link.
  • Far more PoE headroom: the 3560V2-48PS shipped with a roughly 370W PoE budget delivering legacy PoE (802.3af, ~15.4W). The C9200-48P provides up to a 740W PoE budget with PoE+ (802.3at, up to 30W per port) — enough to power dense 802.11ax APs, pan-tilt-zoom cameras, and multi-cell phones the 3560V2 could not.
  • Modular uplinks: instead of four fixed SFP slots, the 9200 uses a swappable network module — choose 4x1G or 4x10G SFP+ uplinks, so the uplink can grow with the aggregation layer rather than capping you at 1G.

Stacking, throughput, and silicon

The 3560V2 was a standalone box — no true stacking, so a multi-switch closet meant independently managed devices and uplink sprawl. The Catalyst 9200 supports StackWise-160 (160 Gbps stack bandwidth on the C9200), letting up to eight switches operate as one logical unit with a single management IP, shared config, and resilient ring uplinks. Switching capacity moves from the low tens of Gbps on the old fixed box to a far higher fabric on the 9200, driven by Cisco's UADP 2.0 mini ASIC. That programmable ASIC is also what makes the platform future-relevant: it supports flexible NetFlow and the telemetry and segmentation features a 12.2-era IOS box simply cannot run.

Software and licensing: the biggest mindset shift

This is where teams get surprised, so plan for it. The 3560V2 ran classic IOS with a permanent, perpetual feature set baked into the image (the trailing -S in the PID denotes the IP Base / LAN Base-class image). The Catalyst 9200 runs IOS-XE 17.x — a modern, Linux-based, programmable OS with model-driven telemetry, NETCONF/RESTCONF, and a clean upgrade path. Licensing also moves to Cisco Smart Licensing with two tiers: Network Essentials and Network Advantage. The -A suffix on C9200-48P-A means it ships configured for the Network Advantage tier, which unlocks the richer routing, SD-Access/segmentation, and analytics features alongside Cisco DNA/Catalyst Center subscription entitlement. Budget for the subscription term and register the device to your Smart Account — there is no longer a one-time perpetual right-to-use to rely on.

A practical migration plan

1. Assessment and inventory

Start by documenting every 3560V2 by serial, location, current IOS train, port utilization, and connected device types. Note which ports actually draw PoE and at what class — this tells you whether a 740W 9200 budget is comfortable or whether you need to size up. Capture the running config from each switch; you will use it as the parity baseline.

2. Config and feature parity

  • Translate, do not paste: IOS-XE syntax is close to classic IOS but not identical. VLANs, SVIs, trunking, port-security, and basic ACLs port over with minor edits; QoS (MQC vs the older 3560 MLS QoS model) and any legacy macro/SDM-template tuning need rework.
  • Re-evaluate Layer 3: the 3560V2 IP Base image had limited routing. On the 9200 with Network Advantage, confirm whether you want to keep routing at the access layer or collapse it into a routed-access or SD-Access design now that the hardware supports it.
  • Map features to license tier: make sure every feature you depend on is available in Network Advantage before cutover, so there are no surprises post-deployment.

3. Physical: rack, power, PoE, uplinks, optics

Both units are 1RU, so rack space is a wash — but power is not. Verify your PDU and circuit can support the larger 9200 PoE budget if you intend to use it. Critically, audit optics: 3560V2 uplinks used legacy 1G SFPs, and if you move the 9200 to a 10G uplink module you will need new SFP+ transceivers and possibly new fiber/DAC. Order optics with the switch, not after — they are a common cause of cutover-day delays.

4. Phased cutover

Avoid a flash-cut of an entire campus. Stage and pre-configure each 9200 (or stack) on the bench, validate against the parity baseline, then cut over closet by closet during a maintenance window. Keep the outgoing 3560V2 powered but disconnected for a short rollback window before you decommission it.

5. Secure decommission

Do not let a retired switch leave the building with its config intact. Wipe the startup config and any stored credentials, certificates, and SNMP strings (a full write-erase plus VLAN.dat removal). For federal and healthcare environments, follow your media-sanitization policy (NIST SP 800-88 lines) and retain a certificate of data destruction or asset-disposition record for the audit trail.

Procurement notes for regulated buyers

For federal, DoD, and SLED purchases, specify TAA-compliant Catalyst 9200 units and confirm country of origin up front — this is non-negotiable on GSA and contract vehicles, and it is one more reason secondary-market 3560V2 stock is the wrong answer. Catalyst 9200 sits within Cisco's standard lead-time and General Purpose Catalyst availability, but PoE models and 10G uplink modules can vary, so lock quantities and optics early. Buying through an authorized Cisco partner ensures genuine hardware, valid Smart Licensing registration, and a clean warranty and support entitlement — all of which matter when an auditor asks for provenance.

You can browse current Catalyst 9200 configurations and PoE options in our catalog, and if you are planning a fleet-wide refresh, see the full Cisco end-of-life hub to catch any other past-LDoS gear in the same closets.

Ready to scope your 3560V2 refresh?: Send us your 3560V2 inventory and we will return a TAA-compliant Catalyst 9200 bill of materials — switches, uplink modules, optics, and the right Smart Licensing tier — sized to your actual PoE and port load. Start at /get-a-quote.

Frequently asked questions

Is the WS-C3560V2-48PS-S still safe to run in production?

No. It passed Last Day of Support on May 31, 2021, which means Cisco PSIRT no longer issues security patches for it, TAC will not open cases, and there is no hardware RMA. Any IOS vulnerability discovered against it now is permanent and unfixable, which makes it an audit finding under most federal, healthcare, and PCI frameworks.

Why is the Catalyst 9200 (C9200-48P-A) the right replacement?

It is the direct fixed-access successor and a one-for-one match on form factor and port count, but a generational upgrade everywhere else: 10/100/1000 ports instead of 10/100, up to a 740W PoE+ budget instead of ~370W of legacy PoE, modular 1G/10G uplinks, StackWise-160 stacking, and IOS-XE 17.x with model-driven telemetry. It removes the throughput, PoE, and software constraints that defined the 3560V2.

How does licensing change moving from the 3560V2 to the Catalyst 9200?

Significantly. The 3560V2 used classic IOS with a perpetual feature set baked into the image. The Catalyst 9200 uses Cisco Smart Licensing with Network Essentials and Network Advantage tiers — the -A in C9200-48P-A denotes Network Advantage — plus a Cisco DNA/Catalyst Center subscription. You register the switch to a Smart Account and budget for the subscription term rather than relying on a one-time perpetual right-to-use.

Can I reuse my existing optics and cabling?

Partly. The 3560V2's 1G SFP uplinks may carry over if you stay at 1G on the 9200's uplink module, but if you move to a 10G SFP+ uplink module you will need new SFP+ transceivers and possibly new fiber or DAC cables. Audit and order optics alongside the switch to avoid cutover-day delays.

What are the procurement considerations for federal and SLED buyers?

Specify TAA-compliant Catalyst 9200 units and confirm country of origin for GSA and contract-vehicle compliance — another reason used 3560V2 stock is the wrong path. Buy through an authorized Cisco partner so you get genuine hardware, valid Smart Licensing registration, and clean warranty and support entitlement, and lock in PoE models and uplink modules early since those can carry longer lead times.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote