Catalyst 9300 Series
Cisco’s lead stackable access switch — up to 1 TB stacking, 90W UPOE+, 100G IPsec.
Cisco Catalyst 9300 Series switches are Cisco’s lead stackable enterprise access platform, built for a hybrid world where the workplace is anywhere and endpoints could be anything. With StackWise-1T (up to 1 TB stacking), 90W UPOE+, 100G line-rate IPsec on the 9300X, application hosting, and the foundation for Software-Defined Access, they enforce security and policy at the access layer. Faltrox deploys, segments, and manages them.
Overview
What Catalyst 9300 Series is
The Catalyst 9300 Series is the workhorse access switch of the Catalyst 9000 family, engineered to transform the network for a hybrid workforce. It leads the industry in stacking density with StackWise-1T (up to 1 TB), offers the highest 90W UPOE+ density for powering OT/IT devices, and — on the 9300X models — brings 100G line-rate IPsec in hardware for secure edge connectivity to secure internet gateways, cloud providers, and site-to-site tunnels.
It is the foundation of Cisco Software-Defined Access (SD-Access), enabling policy-based automation from edge to cloud with group-based policy, network segmentation, and context-based analytics. Application hosting lets it run signed applications — including a Cisco ASAc firewall — directly on the switch, ThousandEyes provides end-to-end path visibility, and it can be managed on-premises, virtually, or from the Meraki cloud. Faltrox deploys it, applies SD-Access segmentation and hardening, and operates its telemetry as part of the monitoring it runs.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Enterprise Campus Access
Cisco’s lead stackable access platform for the hybrid-workforce campus edge.
90W UPOE+ Devices
Highest UPOE+ density powers demanding OT/IT devices — up to 384 ports across a stack.
SD-Access Segmentation
The foundation of Software-Defined Access with group-based policy from edge to cloud.
100G IPsec Edge
9300X models bring 100G line-rate IPsec for secure tunnels to SIGs, cloud, and sites.
On-Switch Firewall
Application hosting runs a Cisco ASAc firewall and signed apps directly on the switch.
ThousandEyes Visibility
End-to-end path visualisation from campus and branch to cloud and data centre.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Stack
StackWise-1T combines switches into a single logical unit with up to 1 TB of stacking bandwidth and StackPower resilience.
- 02
Fabric
As the foundation of SD-Access, it enforces group-based policy and network segmentation with policy-based automation from edge to cloud.
- 03
Secure the Edge
9300X models terminate 100G line-rate IPsec tunnels with AES-256 to secure internet gateways, cloud providers, and other sites.
- 04
Host
Application hosting runs signed apps and a Cisco ASAc firewall on the switch, adding stateful inspection without new hardware.
- 05
Operate
Faltrox applies segmentation and hardening, maintains software, and feeds ThousandEyes and telemetry into ongoing monitoring.
Capabilities
Key capabilities
StackWise-1T
Up to 1 TB of stacking bandwidth — the industry’s highest-density stacking with flexible uplinks.
90W UPOE+
Highest UPOE+ density: 48 ports standalone, 384 ports across an 8-member stack for OT/IT power.
100G Hardware IPsec
9300X models deliver 100G line-rate IPsec with AES-256 for secure edge and tunnel connectivity.
SD-Access Foundation
Policy-based automation, group-based policy, and segmentation from edge to cloud.
Application Hosting
Run Cisco-signed apps and a Cisco ASAc firewall directly on the switch via QAT and AppGig ports.
ThousandEyes
End-to-end path visualisation from campus/branch to cloud and data centre, included with DNA Advantage.
Encrypted Traffic Analytics
Detects threats in encrypted traffic without decryption, and enforces MACsec on the wire.
Flexible Management
Manage on-premises, virtually, or migrate to the Cisco Meraki cloud dashboard.
Works with
Part of the platform
Cisco products this pairs with, and the Faltrox services that operate it.
Cisco products
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Cisco Catalyst 9300 Series for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What makes the 9300 Cisco’s "lead" access switch?
It combines the industry’s highest stacking bandwidth (StackWise-1T, up to 1 TB), the highest 90W UPOE+ density, 100G hardware IPsec on the 9300X, on-switch application hosting including a firewall, and its role as the foundation of Software-Defined Access — making it the default enterprise campus access platform.
02Can the switch itself run a firewall?
Yes. Through application hosting, the Cisco ASAc (Adaptive Security Virtual Appliance) and stateful traffic inspection can be added directly on the switch without additional hardware — one of several signed apps it can host.
03What is SD-Access and why does it matter here?
Software-Defined Access is Cisco’s network fabric for policy-based automation and segmentation from edge to cloud. The 9300 is its foundation, so segmentation and group-based policy are enforced in the fabric rather than hand-configured VLAN by VLAN — which is what makes containment scalable.
04How does it secure connections to the cloud?
The 9300X models bring 100G line-rate IPsec in hardware with AES-256, enabling secure tunnels to secure internet gateways, cloud service providers, and site-to-site connectivity directly from the access switch.
05How does Faltrox operate it?
We deploy the switches, design and apply SD-Access segmentation and hardening, maintain software, and feed ThousandEyes and Encrypted Traffic Analytics telemetry into the network monitoring and SOC services we run — delivering secure infrastructure, not just switches.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us