cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
209
Views
3
Helpful
5
Replies

CISCO 9800

abtt-39
Level 1
Level 1

Hello, I have a 3504 wifi controller


A large majority of AP1832I-E-K9
And some more recent C9120AXI-E
The last update I made was in The last update I made was in early 2024.

On the Cisco website, I see that an update was released in May 2024. Unfortunately I no longer have access to the download.

But anyway, I see according to this link : https://www.cisco.com/c/en/us/products/collateral/wireless/3504-wireless-controller/eos-eol-notice-c51-744737.html

EOL in 2027.

But before, I don't understand all the dates

End of Vulnerability/Security Support: The last date that Cisco Engineering may release a planned maintenance release or scheduled software remedy for a security vulnerability issue. January 30, 2025.

Does this mean there will be no more new versions from the end of this month?

I was thinking of starting to look at replacing this controller, I guess I need to look at the 9800?

Catalyst 9800-L

And licence :

Licensing

No licenses are required to boot up a Cisco Catalyst 9800 Series Wireless Controller. However, in order to connect any access points to the controller, Cisco DNA software subscriptions are required. To be able to connect to a Cisco Catalyst 9800 Series controller, each access point requires a Cisco DNA subscription license.

So I have to buy APs and also the DNA license?

And for the APs that I already have in production? Do I also have to buy licenses?

AIR-AP1832I-E-K9 is supported with 9800 controlers?

5 Replies 5

https://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html

Check this for compatibility between old AP and your feature wlc 9800 series.

Also why you select 9800-L? What is your requirements?

MHM

For the maximum AP supported : 250, 500 with a special licence). And the price.

I'm not married to cisco, but if I go for another brand, I should also change the APs

I haven't looked at the price of the licenses yet (I may cry).

It's more like that End of Vulnerability/Security Support:
HW
January 30, 2025

In your opinion, can i still keep the 3504 and replace it later in the year (2025)?

marce1000
Hall of Fame
Hall of Fame

 

  - You may find this FAQ useful  https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/nb-06-cat9800-ser-wirel-faq-ctp-en.html

  M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

EOL dates 
End of SW Maintenance Releases Date: - Last date that maintenance release software will come out, Highly recommended to aleady have your migration strategy started before this date. Basically any bugs will not be fixed if not a security vulnerability

End of Vulnerability/Security Support: Last day that Cisco will release patches to fix security vulnerabilities. Do not recommend ever going past this date

Last Date of Support: Last day you can RMA hardware failure. And basically TAC will also not help post this date

 

As for licensing of the existing APs, best contacting your Cisco SE or a Cisco Partner to discuss there may be some migration paths available when purchasing the 9800

*****Help out other by using the rating system and marking answered questions as "Answered"*****
*** Please rate helpful posts ***

Rich R
VIP
VIP

> Does this mean there will be no more new versions from the end of this month?
Correct.  But there will only be a new version if there is a high severity security vulnerability announced before that date.

> So I have to buy APs and also the DNA license?
Yes 1 DNA license per AP.  C91XX APs are normally purchased with DNA licenses (although it is possible to opt out) so check - you might have already bought DNA licenses together with your 9120 APs.  When you buy the DNA licenses you buy a DNA subscription term license which expires after the 3/5/7 year period you buy (only required for certain advanced features and using with DNAC or Spaces for example), and that comes with a DNA network license which does not expire.  So even when the term license expires the controller and the APs will keep working with the perpetual network licenses. If you don't want to use DNA feature anymore you just reconfigure the controller licensing boot mode. For details of features which require the DNA subscription see:
https://www.cisco.com/c/m/en_us/products/software/dna-subscription-wireless/en-sw-sub-matrix-wireless.html?oid=porew018984
Note the DNA licenses come in Essentials and Advantage levels.
The licenses require Smart Licensing so any licenses you bought would be in your Smart Licensing account.  The controller needs to be connected to Smart Licensing so it can request licenses for each AP which joins.

> And for the APs that I already have in production? Do I also have to buy licenses?
Yes for any which were not bought with DNA licenses.

> AIR-AP1832I-E-K9 is supported with 9800 controlers?
Yes but take note of the EOL dates for the 1830 APs:
https://www.cisco.com/c/en/us/products/collateral/wireless/aironet-1830-series-access-points/aironet-1830-series-access-points-eol.html
So we can expect Cisco to drop support for them in a forthcoming 9800 software release.  They're currently still supported in the latest release:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-16/release-notes/rn-17-16-9800.html#supported-aps

Unfortunately I no longer have access to the download
Find a recent security advisory and find the section which says "Customers without Service Contracts" then contact TAC quoting the URL of the advisory, the paragraph just mentioned and the version and URL https://software.cisco.com/download/home/286312601/type/280926587/release/8.10.196.0 for the software you want to download and the serial number of your WLC.  Then TAC should publish it to you directly.

This advisory should be suitable: Cisco Wireless LAN Controller AireOS Software FIPS Mode Denial of Service Vulnerability because CSCwa40778 : Bug Search Tool (cisco.com) is fixed in 8.10.196.0.

"Customers Without Service Contracts

Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco TAC: https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html

Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade."

For the maximum AP supported : 250, 500 with a special licence).
You didn't mention how many APs you have but be very careful about running the 9800 WLC at full capacity - they often don't live up to data sheet spec and are generally more prone to suffering from high CPU than the AireOS WLCs.  See:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#designforlargescaledeployments
It all depends on what features you use and peak loads on the WLC.  9800-L does control plane and data in CPU (CPU cores are split between control plane and data) so only has a single WNCd instance - meaning all the control plane runs in a single process on a single CPU core.

Review Cisco Networking for a $25 gift card