CiscoEnterprise Switching

    Catalyst 9300 Series

    Cisco’s lead stackable access switch — up to 1 TB stacking, 90W UPOE+, 100G IPsec.

    Cisco Catalyst 9300 Series switches are Cisco’s lead stackable enterprise access platform, built for a hybrid world where the workplace is anywhere and endpoints could be anything. With StackWise-1T (up to 1 TB stacking), 90W UPOE+, 100G line-rate IPsec on the 9300X, application hosting, and the foundation for Software-Defined Access, they enforce security and policy at the access layer. Faltrox deploys, segments, and manages them.

    Overview

    What Catalyst 9300 Series is

    The Catalyst 9300 Series is the workhorse access switch of the Catalyst 9000 family, engineered to transform the network for a hybrid workforce. It leads the industry in stacking density with StackWise-1T (up to 1 TB), offers the highest 90W UPOE+ density for powering OT/IT devices, and — on the 9300X models — brings 100G line-rate IPsec in hardware for secure edge connectivity to secure internet gateways, cloud providers, and site-to-site tunnels.

    It is the foundation of Cisco Software-Defined Access (SD-Access), enabling policy-based automation from edge to cloud with group-based policy, network segmentation, and context-based analytics. Application hosting lets it run signed applications — including a Cisco ASAc firewall — directly on the switch, ThousandEyes provides end-to-end path visibility, and it can be managed on-premises, virtually, or from the Meraki cloud. Faltrox deploys it, applies SD-Access segmentation and hardening, and operates its telemetry as part of the monitoring it runs.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Enterprise Campus Access

    Cisco’s lead stackable access platform for the hybrid-workforce campus edge.

    02

    90W UPOE+ Devices

    Highest UPOE+ density powers demanding OT/IT devices — up to 384 ports across a stack.

    03

    SD-Access Segmentation

    The foundation of Software-Defined Access with group-based policy from edge to cloud.

    04

    100G IPsec Edge

    9300X models bring 100G line-rate IPsec for secure tunnels to SIGs, cloud, and sites.

    05

    On-Switch Firewall

    Application hosting runs a Cisco ASAc firewall and signed apps directly on the switch.

    06

    ThousandEyes Visibility

    End-to-end path visualisation from campus and branch to cloud and data centre.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Stack

      StackWise-1T combines switches into a single logical unit with up to 1 TB of stacking bandwidth and StackPower resilience.

    2. 02

      Fabric

      As the foundation of SD-Access, it enforces group-based policy and network segmentation with policy-based automation from edge to cloud.

    3. 03

      Secure the Edge

      9300X models terminate 100G line-rate IPsec tunnels with AES-256 to secure internet gateways, cloud providers, and other sites.

    4. 04

      Host

      Application hosting runs signed apps and a Cisco ASAc firewall on the switch, adding stateful inspection without new hardware.

    5. 05

      Operate

      Faltrox applies segmentation and hardening, maintains software, and feeds ThousandEyes and telemetry into ongoing monitoring.

    Capabilities

    Key capabilities

    StackWise-1T

    Up to 1 TB of stacking bandwidth — the industry’s highest-density stacking with flexible uplinks.

    90W UPOE+

    Highest UPOE+ density: 48 ports standalone, 384 ports across an 8-member stack for OT/IT power.

    100G Hardware IPsec

    9300X models deliver 100G line-rate IPsec with AES-256 for secure edge and tunnel connectivity.

    SD-Access Foundation

    Policy-based automation, group-based policy, and segmentation from edge to cloud.

    Application Hosting

    Run Cisco-signed apps and a Cisco ASAc firewall directly on the switch via QAT and AppGig ports.

    ThousandEyes

    End-to-end path visualisation from campus/branch to cloud and data centre, included with DNA Advantage.

    Encrypted Traffic Analytics

    Detects threats in encrypted traffic without decryption, and enforces MACsec on the wire.

    Flexible Management

    Manage on-premises, virtually, or migrate to the Cisco Meraki cloud dashboard.

    Works with

    Part of the platform

    Cisco products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Cisco Catalyst 9300 Series for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What makes the 9300 Cisco’s "lead" access switch?

    It combines the industry’s highest stacking bandwidth (StackWise-1T, up to 1 TB), the highest 90W UPOE+ density, 100G hardware IPsec on the 9300X, on-switch application hosting including a firewall, and its role as the foundation of Software-Defined Access — making it the default enterprise campus access platform.

    02Can the switch itself run a firewall?

    Yes. Through application hosting, the Cisco ASAc (Adaptive Security Virtual Appliance) and stateful traffic inspection can be added directly on the switch without additional hardware — one of several signed apps it can host.

    03What is SD-Access and why does it matter here?

    Software-Defined Access is Cisco’s network fabric for policy-based automation and segmentation from edge to cloud. The 9300 is its foundation, so segmentation and group-based policy are enforced in the fabric rather than hand-configured VLAN by VLAN — which is what makes containment scalable.

    04How does it secure connections to the cloud?

    The 9300X models bring 100G line-rate IPsec in hardware with AES-256, enabling secure tunnels to secure internet gateways, cloud service providers, and site-to-site connectivity directly from the access switch.

    05How does Faltrox operate it?

    We deploy the switches, design and apply SD-Access segmentation and hardening, maintain software, and feed ThousandEyes and Encrypted Traffic Analytics telemetry into the network monitoring and SOC services we run — delivering secure infrastructure, not just switches.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us