Uniqcli

Cisco Catalyst 4948 (WS-C4948-S) EoL: Migrate to Catalyst 9300

The WS-C4948-S passed Last Day of Support on Jan 31, 2020. Here is why this top-of-rack workhorse has to come out and how to refresh cleanly to a stackable Catalyst 9300 (C9300-48T-A).

UT
Uniqcli Team
June 5, 2026 · 9 min read
Share
Cisco Catalyst 4948 (WS-C4948-S) EoL: Migrate to Catalyst 9300

If a Cisco Catalyst 4948 (PID WS-C4948-S) is still humming away at the top of a server rack, it is running well past every Cisco lifecycle milestone. The 4948 reached its Last Day of Support on January 31, 2020. From that date forward Cisco provides no software updates, no PSIRT security fixes, and no TAC support or RMA hardware replacement for this platform. The switch keeps forwarding frames at wire speed, which is exactly why these 1U boxes quietly outlive the racks they were bought for. This guide explains what the end-of-life dates mean for a switch you still depend on, why the recommended Catalyst 9300 is a genuine architectural upgrade rather than a like-for-like swap, and how to plan a clean migration to current hardware.

WS-C4948-S lifecycle at a glance: End of Sale: August 1, 2013. Last Day of Support (LDoS): January 31, 2020. Both dates have long passed. After LDoS there are no patches, no TAC cases, and no RMAs. The full milestone record lives on the EoL detail page for this PID.

What the Catalyst 4948 actually was

The WS-C4948-S was a fixed-configuration, 1RU, wire-speed switch built for one job: server aggregation and top-of-rack connectivity. It carried 48 ports of 10/100/1000 connectivity, with the four uplink ports implemented as combo (dual-purpose) connectors that could take SFP optics or copper, so you could run fiber uplinks to the distribution layer without sacrificing edge density. It delivered non-blocking, wire-speed Layer 2 through Layer 4 switching on a roughly 96 Gbps backplane, and it ran classic Cisco IOS, not IOS XE. The -S variant shipped with a single 300W AC power supply, no Power over Ethernet, and no stacking. It was a reliable, low-latency aggregation switch for its era. Three things define its limits today: it is a 1 Gigabit platform end to end, it has no PoE, and it is a standalone box with no native stacking fabric.

Why acting now matters

The risk of an end-of-life switch is not that it fails. It is that it keeps working while the support floor disappears beneath it. After LDoS, several exposures stack up on a box like this:

  • No PSIRT security patches. When a new IOS or hardware vulnerability is disclosed, the 4948 will never receive a fixed image. Its software is frozen at the last release it ever shipped. Any CVE that touches that code path on this platform is permanent and unpatchable.
  • No TAC or RMA. A failed unit cannot be opened as a support case or swapped under contract. Your only recovery is a cold spare you bought years ago or a secondary-market 4948 of the same dead-end model. For a top-of-rack switch carrying production server traffic, that is a single point of failure with no safety net.
  • Audit and compliance exposure. Frameworks that federal, DoD, SLED, and healthcare buyers operate under (FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS, and CISA directives) expect supported, patchable infrastructure. An unsupported switch that cannot receive fixes is an audit finding waiting to happen, and "the vendor stopped shipping patches in 2020" is not a defensible remediation plan.
  • Operational drag. The 4948 runs classic IOS with a CLI-only, per-box management model. It has no role in a modern automation or assurance workflow, so every change is a manual, untracked touch.

What each milestone date means

  • End of Sale (2013-08-01): the last day Cisco accepted new orders for the WS-C4948-S. Everything after this date has been consuming the support tail.
  • Last Day of Support / LDoS (2020-01-31): the hard wall. After this date Cisco provides no software fixes of any kind, no security advisories with remediation, no TAC engagement, and no return-and-replace. The hardware is entirely on its own.

The recommended replacement: Catalyst 9300 (C9300-48T-A)

Cisco positions the stackable Catalyst 9300 family as the modern successor for high-density access and aggregation, and the C9300-48T-A maps cleanly onto what the 4948 did. The -48T gives you 48 ports of 10/100/1000 (data-only, copper RJ-45; like the 4948 it has no PoE, so it is the right SKU for a server-aggregation role where PoE is not needed and you do not want to pay for it). The trailing -A denotes the DNA Network Advantage license tier. Where the 9300 is a real step up:

  • Modular uplinks instead of fixed combo ports. The C9300-48T-A takes a hot-swappable uplink module: 4x 1G, 4x 10G (SFP+), 8x 10G, or 2x 25G/40G options depending on the module you choose. You are no longer capped at 1G uplinks the way you were on the 4948, so the path to the distribution or spine layer can run at 10G, 25G, or 40G as the rack grows.
  • StackWise-480 stacking. Up to eight 9300s join into a single logical switch over a 480 Gbps stacking backplane, with StackPower binding the power supplies into a shared pool. That replaces the 4948's standalone, no-redundancy model with a stack that survives a member failure and is managed as one device. The 4948 could never do this.
  • UADP 2.0 ASIC and a multicore x86 CPU. The 9300 runs Cisco's programmable UADP application-specific silicon and an Intel x86 control-plane processor, versus the fixed-function ASIC and modest CPU of the 4948. That headroom is what enables modern features (flexible NetFlow, encrypted-traffic analytics, application visibility, programmable telemetry) that the 4948 has no capacity for.
  • IOS XE 17.x, not classic IOS. The 9300 runs the modern IOS XE train with a Linux-based, modular software architecture: patchable subsystems, model-driven programmability (NETCONF/RESTCONF, YANG), and a real automation surface. This is the single biggest operational difference from the 4948's monolithic IOS image.
  • Dual modular, field-replaceable power supplies and FRU fans. Where the WS-C4948-S had one fixed 300W supply, the 9300 supports redundant hot-swap supplies and fan trays, removing the standalone box's single points of failure.
  • DNA / Smart Licensing. The Network Advantage tier (the -A) unlocks the assurance, automation, and SD-Access capabilities the 4948 predates by a decade, all managed through Smart Licensing rather than per-device PAKs.

Sizing the swap: One C9300-48T-A is a clean one-for-one replacement for a single WS-C4948-S in port count and the data-only (no PoE) role. If the 4948 was one of several aggregation switches in a row of racks, plan the 9300s as a StackWise-480 stack so the whole row is managed and powered as one logical unit with built-in redundancy. Choose the uplink module to match your distribution layer: 4x 10G (SFP+) is the common default; step to 25G/40G if the spine supports it.

A practical migration plan

1. Assess and inventory

Start with a hardware and software audit of every 4948 in scope. Pull show version, show inventory, and the running configuration off each unit. Record port utilization, which optics are populated in the combo/uplink ports, the VLAN and trunk topology, any Layer 3 SVIs or static routes the 4948 is carrying, and what is connected to each rack (which servers, which storage, which out-of-band links). This inventory is what sizes the 9300 count, the uplink module choice, and the optics bill of materials.

2. Plan licensing and feature parity

The 4948 had no subscription licensing; the 9300 uses Smart Licensing with a base DNA tier (Network Essentials or Network Advantage) plus an optional DNA term subscription. The C9300-48T-A is the Advantage SKU. Set up or reuse a Smart Account, decide on a 3-, 5-, or 7-year DNA term that matches your refresh horizon, and confirm which features you actually need (most 4948 aggregation deployments are well served by the base perpetual Network Advantage entitlement). Then map the 4948 feature set to IOS XE: classic-IOS configs do not paste in cleanly, so rebuild VLANs, trunking, SVIs, ACLs, QoS, and any routing in IOS XE syntax in a lab or staging stack and validate before cutover.

3. Plan the physical refresh

Both platforms are 1RU, so rack space is not an issue, but plan the details: the 9300 supports redundant power, so provision a second PDU feed per switch or per stack; confirm front-to-back airflow matches your hot/cold aisle; order StackWise-480 and StackPower cables if you are stacking; and re-source optics. The 4948's 1G uplink optics may need to become SFP+ (10G) or SFP28 (25G) optics for the 9300 uplink module, so build the optics BOM against the new uplink speeds, not the old ones. Confirm patch-cable counts for 48 copper ports per switch.

4. Phased cutover

Stage and burn-in the 9300 (or stack) on the bench with the validated IOS XE config and current software, then schedule a maintenance window per rack. Because the 4948 is typically a top-of-rack aggregation switch, the cleanest approach is to rack the 9300 alongside it, move uplinks first to bring the new switch into the topology, then migrate server ports rack-by-rack so any issue is contained to one rack rather than the whole row. Keep the old 4948 powered and reversible until the new switch has run clean through a full business cycle.

5. Secure decommission

Do not just unrack the old switch. Erase the configuration (write erase, delete the vlan.dat, and wipe flash) so no credentials, SNMP strings, ACLs, or topology details leave with the hardware. For federal, DoD, and healthcare environments, follow your media-sanitization standard (NIST SP 800-88) and capture a certificate of data destruction or asset-disposition record for the audit trail. A properly sanitized 4948 still has resale or trade-in value on the secondary market.

Procurement notes for regulated buyers

Buy the 9300 the right way the first time. As an authorized Cisco partner, we source TAA-compliant C9300-48T-A units suitable for federal and DoD procurement, quote in a form payable by Government Purchase Card (GPC) for under-threshold buys, and handle Smart Account and DNA license registration so the switch lands fully entitled. Lead times on current Catalyst hardware and the matching uplink modules and optics can swing with demand, so confirm availability before you commit a maintenance window, and order optics and StackWise cables on the same PO so nothing blocks the cutover. Browse current Catalyst 9300 configurations and optics in our catalog, confirm the exact 4948 milestone dates on the WS-C4948-S EoL page, and see other affected platforms on the main Cisco end-of-life hub.

Get a tailored migration quote: Send us your 4948 inventory (show version and show inventory output is ideal) and we will return a sized, TAA-compliant Catalyst 9300 refresh quote with the right uplink modules, optics, stacking, and DNA licensing for your environment. Start at get a quote.

Frequently asked questions

Is the Cisco Catalyst 4948 (WS-C4948-S) still supported?

No. The WS-C4948-S reached End of Sale on August 1, 2013 and its Last Day of Support (LDoS) on January 31, 2020. After LDoS Cisco provides no software or security fixes, no TAC support, and no RMA hardware replacement, so any unit still in production is unpatchable and unsupported.

What replaces the Catalyst 4948?

Cisco recommends the stackable Catalyst 9300 family. For a direct, data-only (no PoE) 48-port replacement matching the 4948's server-aggregation role, the C9300-48T-A is the closest fit: 48x 1G RJ-45, modular 10G/25G/40G uplinks, StackWise-480 stacking, IOS XE 17.x, and DNA Network Advantage licensing.

Can I reuse my 4948 optics and configuration on the Catalyst 9300?

Plan to re-source both. The 9300's uplinks live on a separate module that typically runs at 10G (SFP+) or higher, so your 1G uplink optics may not carry over. And the 4948 runs classic IOS while the 9300 runs IOS XE, so configs do not paste cleanly; rebuild VLANs, trunks, SVIs, ACLs, and QoS in IOS XE and validate in a lab before cutover.

Does the C9300-48T-A have PoE like a typical access switch?

No, and that is intentional. The -48T is a data-only model with no PoE, which matches the 4948's server-aggregation role and avoids paying for PoE you do not need. If you need PoE/PoE+/UPOE for endpoints, choose a C9300-48P, -48U, or -48H model instead.

Is the Catalyst 9300 TAA-compliant and GPC-payable for government buyers?

Yes. As an authorized Cisco partner we supply TAA-compliant C9300-48T-A units for federal, DoD, and SLED procurement, quote in a Government Purchase Card-payable form for under-threshold buys, and register the Smart Account and DNA licensing so the switch arrives fully entitled.

UT
Written & maintained by

Uniqcli Team

The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.

Ready to scope your Cisco build?

Build a quote