cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
568
Views
3
Helpful
6
Replies

Migrate from catalyst switches to small business

chpmotry
Level 1
Level 1

Hi guys.

our network is old about 15 years  with a lot of catalyst 2960 switches : c2960g, c2960+ and c2960s that their ios are for 2018 and older.and the edge of our internet access is fortinet firewall and we dont have c2960s or c2960g that is in edge of internet access.  is it making problem for our network security and are we forced to migrate to c9000 and small business switches?

is the using catalyst switches dangrous in terms of security threats such as unallowable login that couses denial-of-service or watchdog crash and othe cve that reported in cisco website?

6 Replies 6

Hello!

If you follow security best practices and regularly upgrade switches, especially when a critical vulnerability emerges, I would say that Cisco Catalyst switches are among the most secure options you can get.

BR

****Kindly rate all useful posts*****

Thank you @DanielP211 . The switches c2960s and c2960g are no longer supported in terms of  Vulnerability/Security.and i cant upgrade their ios

Best practice is to migrate to newer switches which have support ASAP. In your case SMB switches.,

****Kindly rate all useful posts*****

M02@rt37
VIP
VIP

Hello @chpmotry 

In wich environnement? Datacenter? Office?

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

These c2960 are in offices that maximum have three clients.

Joseph W. Doherty
Hall of Fame
Hall of Fame

"is the using catalyst switches dangrous in terms of security threats such as unallowable login that couses denial-of-service or watchdog crash and othe cve that reported in cisco website?"

Yes it is, however often many don't understand it's not so much a question of dangerous but how much dangerous.

In the case of a no longer supported IOS, it's difficult to even really know if you're at higher risk until a security flaw is found in current software which also applies to older software too.

Even if a non-fixed security flaw is identified, what's the risk that someone will use it against you?

"is it making problem for our network security and are we forced to migrate to c9000 and small business switches?'

Are you forced?  No.  However, it can be very difficult to scientifically analyze the situation because you end up with probabilities not certainties. For example, you might run your existing equipment for another 20 years, without a security exploitation or be running the latest and best and be hit by a zero day exploit.

So, must you upgrade?  Not really.

So, should you upgrade?  Cannot say.  That's something you need to decide.

I will say, much like insurance vendors recommend (buying) as much insurance as possible, hardware vendors also recommend (buying) newer equipment too.

Review Cisco Networking for a $25 gift card