
Organizations still operating Cisco Catalyst 3650 or older Catalyst 3560 switches are increasingly evaluating the Catalyst 9200 Series as part of an access-layer refresh. A successful Catalyst 3650 to 9200 migration, however, involves more than replacing one 24-port or 48-port switch with another.
The existing environment may depend on specific PoE capacity, fiber uplinks, VLANs, EtherChannels, spanning-tree settings, Layer 3 routing, switch stacks, security policies, monitoring systems and legacy configuration commands. The new platform also introduces a different licensing and software environment that needs to be considered during procurement.
For most access-layer refresh projects, the correct replacement depends on matching the new Catalyst 9200 configuration to the functions the existing switch actually performs, while also allowing for future network requirements.
Why Organizations Are Moving Away from Catalyst 3560 and 3650
Catalyst 3560 and Catalyst 3650 switches have served enterprise access networks for many years. The reason for replacing them is not simply that newer hardware exists.
Older access infrastructure can become increasingly difficult to align with current operational requirements.
Product Lifecycle
Different Catalyst 3560 variants entered end-of-sale and end-of-support stages at different times. The Catalyst 3650 family is also a previous-generation platform.
The exact lifecycle status should always be checked against the specific SKU rather than treating every model in a family identically.
For organizations planning infrastructure for another five or more years, remaining on aging hardware can make lifecycle management, support planning and replacement strategy increasingly difficult.
Higher Bandwidth Requirements
A network designed around older endpoints may now support:
- Wi-Fi 6 and Wi-Fi 6E access points
- IP surveillance
- VoIP
- cloud applications
- video collaboration
- IoT devices
- higher-speed storage and server connections
Access-layer bandwidth and uplink requirements should therefore be reassessed instead of automatically replicating the old configuration.
Growing PoE Requirements
A switch that originally powered IP phones may now need to support phones, wireless access points, cameras and other powered devices simultaneously.
The question is no longer simply whether a switch supports PoE.
You need to know:
How many powered devices are connected, what does each device require, and what total PoE budget must the replacement provide?
Operational Standardization
Replacing legacy switches also creates an opportunity to standardize access infrastructure around Cisco IOS XE, current management workflows, automation capabilities and a consistent hardware generation.
This can simplify long-term administration compared with maintaining several generations of access switches with different software, licensing and hardware characteristics.
Is Catalyst 9200 a Replacement for Catalyst 3650 and 3560?
Yes, the Catalyst 9200 Series can be an appropriate modern access-layer replacement for many Catalyst 3650 and Catalyst 3560 deployments, but it is not a universal one-to-one replacement.
The Catalyst 9200 is primarily positioned for enterprise branch and campus access switching. That makes it a logical candidate where the existing 3560 or 3650 is performing standard access-layer functions such as:
- Layer 2 switching
- VLAN segmentation
- 802.1Q trunks
- PoE+ endpoint connectivity
- voice VLANs
- EtherChannel
- access-layer security
- static routing
- routed access
- selected dynamic routing
- switch stacking
- fiber uplinks
The replacement needs closer evaluation when the existing Catalyst 3650 is performing advanced Layer 3 functions, has demanding multigigabit requirements, uses specialized features, or plays a larger role in the campus architecture.
In those environments, Catalyst 9300 or another platform may be a more suitable candidate.
The key rule is:
Replace the functions and capacity of the existing environment, not simply the model number printed on the front of the switch.
Catalyst 3650 vs Catalyst 9200: What Changes?
Catalyst 3650 and Catalyst 9200 belong to different Cisco switching generations, even though both can perform enterprise access-layer roles.
| Feature | Catalyst 3650 | Catalyst 9200 | Migration Impact |
|---|---|---|---|
| Product generation | Previous generation | Catalyst 9000 family | Review lifecycle and software strategy |
| Operating system | Cisco IOS XE | Cisco IOS XE | Do not assume every command behaves identically |
| Primary role | Enterprise access | Enterprise/branch access | Often suitable for access-layer refresh |
| Port density | Varies by model | 24/48-port and other model-specific options | Match exact port requirement |
| PoE | PoE+/UPOE capabilities vary by SKU | PoE+ and higher-power capabilities vary by model | Calculate endpoint power requirement |
| Uplinks | Fixed uplinks on Catalyst 3650, varying by SKU | Modular on C9200; fixed on C9200L | Verify fiber speed and flexibility |
| Stacking | StackWise capabilities vary by model | C9200 and C9200L use different StackWise architectures | Existing stack hardware is not reused |
| Layer 3 | Depends on old license/feature set | Essentials vs Advantage capabilities | Map routing requirements before ordering |
| Licensing | Legacy feature-set model | Network Essentials/Advantage plus current subscription framework | Procurement must include licensing |
| Management | Traditional and IOS XE management | CLI plus modern Catalyst management/automation options | Review tooling and monitoring |
| Automation | Generation-dependent | NETCONF, RESTCONF, YANG and PnP capabilities available | Opportunity to modernize operations |
| Security | Feature-set dependent | Current Catalyst 9000 security capabilities | Validate exact requirements |
| Lifecycle | Legacy platform | Current-generation Catalyst access family | Better fit for refresh planning |
The table is a starting point. The existing Catalyst 3650 SKU and configuration must be audited individually.
For example, a 48-port 3650 providing high PoE capacity and 10G uplinks should not automatically be replaced with the cheapest 48-port Catalyst 9200.
Catalyst 3560 vs Catalyst 9200
The architectural gap is generally larger when replacing a Catalyst 3560.
The Catalyst 3560 family spans multiple generations and variants, so the first step is identifying exactly what is installed.
An older 3560 environment may have:
- slower uplinks
- older PoE capabilities
- older Cisco IOS releases
- different interface naming
- legacy security commands
- older monitoring configuration
- lower switching requirements
- configurations accumulated over many years
A Catalyst 3560 replacement is therefore an opportunity to clean up the network configuration rather than treating the old configuration as a template that must be preserved exactly.
Document what the switch is actually doing.
Then determine which functions are still required.
Catalyst 9200 or Catalyst 9200L?
Catalyst 9200 and Catalyst 9200L target similar access-layer use cases, but the C9200 provides greater hardware flexibility while the C9200L uses a more fixed architecture.
Catalyst 9200
C9200 models are generally preferable where the organization values:
- modular uplinks
- higher stacking bandwidth
- field-replaceable fans
- greater uplink flexibility
- stronger expansion options
Applicable C9200 models support modular uplink network modules, allowing the uplink architecture to be selected independently of the base access switch.
Catalyst 9200L
C9200L models use fixed uplinks and have lower stacking bandwidth than standard C9200 models.
They can be attractive for predictable access deployments where:
- uplink requirements are already known
- fixed uplinks are acceptable
- future uplink changes are unlikely
- budget is an important consideration
The C9200L should not automatically be viewed as an inferior choice. In a straightforward office or branch network, its fixed architecture may be entirely appropriate.
Conversely, saving money on the initial purchase is less useful if the switch later needs uplink flexibility it cannot provide.
Also remember that C9200 and C9200L use different stacking architectures and cannot simply be mixed into the same stack.
What to Check Before Replacing a Catalyst 3650
Before purchasing hardware, build an inventory of the existing switch.
1. Identify the Exact SKU
Record the complete Catalyst 3650 or 3560 product number.
Do not record only “3650 48-port.”
The exact SKU helps establish:
- port configuration
- PoE capability
- uplink type
- power supply
- feature set
- hardware capabilities
2. Count Active Ports
Document:
- total ports
- active ports
- unused ports
- reserved ports
- expected future ports
A switch with 34 active connections should generally not be replaced by a 24-port model simply because some endpoints could theoretically be consolidated elsewhere.
3. Document Copper and Fiber
Identify every connection that uses:
- copper Ethernet
- SFP
- SFP+
- other applicable transceivers
Fiber connections deserve special attention during procurement.
4. Audit Uplinks
For every uplink, record:
- speed
- media
- transceiver
- destination
- trunk configuration
- EtherChannel membership
- redundancy
A migration can fail even when all access ports are correct if the replacement was ordered with inappropriate uplinks.
5. Calculate PoE Demand
Inventory every powered endpoint:
- phones
- wireless APs
- cameras
- access-control devices
- IoT equipment
Record both current consumption and required capacity.
PoE+ support alone does not guarantee enough total PoE power.
6. Document VLANs and Port Roles
Record:
- VLAN IDs
- VLAN names
- access VLANs
- voice VLANs
- trunk native VLANs
- allowed VLAN lists
Missing one business-critical VLAN can affect dozens of users after cutover.
7. Record Layer 2 Dependencies
Capture:
- spanning-tree mode
- root priorities
- PortFast
- BPDU Guard
- Root Guard
- Loop Guard
- EtherChannels
- LACP/PAgP settings where applicable
Do not allow a hardware replacement to unintentionally change the spanning-tree topology.
8. Audit Layer 3 Configuration
Check for:
- SVIs
- static routes
- default routes
- OSPF
- EIGRP
- first-hop redundancy
- multicast routing
- policy-based routing
- VRFs
These requirements directly affect the choice between Network Essentials, Network Advantage and potentially a higher platform.
9. Review Security and Services
Audit:
- ACLs
- port security
- DHCP snooping
- Dynamic ARP Inspection
- 802.1X
- AAA
- TACACS+
- RADIUS
- SSH
- SNMP
- syslog
- NTP
10. Review QoS and Voice
Legacy QoS configurations deserve particular attention.
Do not assume that every platform-specific QoS command from the old switch should be pasted into the Catalyst 9200.
11. Document the Existing Stack
For a stacked environment, record:
- member numbers
- switch priorities
- physical stack topology
- interface mappings
- uplink distribution
- EtherChannels
- power arrangement
A Catalyst 9200 replacement stack is a new stack design, not an extension of the Catalyst 3650 stack.
12. Back Up Everything
Retain:
- running configuration
- startup configuration
- software information
- license information
- VLAN information
- interface status
- trunk status
- EtherChannel status
- spanning-tree state
- routing table
- ARP/MAC information where useful
Keep the original switch available until the migration is validated.
How to Choose the Right Catalyst 9200 Replacement
A good replacement decision can be reduced to six major areas.
Port Density
Count today’s active ports and expected growth.
For a site using 20 ports, a 24-port model may be appropriate if growth is limited.
For a site already using 22 or 23 ports, a 48-port configuration may offer more practical expansion capacity.
PoE Requirements
Do not choose a switch merely because its product description says PoE+.
Calculate:
Total endpoint PoE demand + expected growth + required operational headroom
A site with 40 IP phones may have very different power requirements from one with 20 high-performance wireless APs and 15 cameras.
Uplink Requirements
Identify both current and future uplink speeds.
Standard C9200 modular models provide options that can include 1G, 10G and, on applicable hardware, higher-speed network modules.
C9200L models use fixed uplink configurations.
This makes uplink planning one of the most important differences between the two families.
Stacking
If the Catalyst 3650 deployment uses stacking, determine why.
Is stacking used for:
- simplified management?
- port density?
- uplink resiliency?
- cross-stack EtherChannel?
- operational redundancy?
C9200 supports StackWise-160, while C9200L uses StackWise-80 on applicable models.
Do not assume legacy Catalyst 3650 stack modules or cables migrate to the new platform.
Layer 3 Requirements
Network Essentials covers fundamental switching and selected routed-access capabilities.
Network Advantage adds capabilities for more advanced routing and segmentation.
If the existing switch runs more than basic access-layer routing, map every required feature to the new license before purchasing.
Power and Redundancy
Check:
- PSU type
- number of PSUs
- PoE budget
- power redundancy requirement
- rack power availability
A switch that supports the endpoint load with two power supplies may not maintain that full PoE load after one PSU fails.
Future Growth
Plan for what the network is becoming, not only what it is today.
Consider:
- additional APs
- higher-speed APs
- more cameras
- new floors
- 10G uplinks
- multigigabit access
- network segmentation
- automation
- future routing requirements
Catalyst 3650 to 9200 Migration: Step-by-Step
A controlled Catalyst 3650 to 9200 migration separates preparation from the actual cutover. Most of the engineering work should be completed before anyone disconnects a cable.
Step 1: Audit the Current Catalyst Environment
Collect the existing configuration and operational state.
Confirm ports, VLANs, trunks, routing, PoE, STP, EtherChannels, security services, management systems and physical connections.
Step 2: Export and Back Up Configurations
Save the running and startup configurations outside the switch.
Also capture relevant operational outputs so you can compare the network before and after migration.
Step 3: Document Physical Connections
Create a port map.
For example:
| Old Interface | Connected Device | VLAN/Role | New Interface |
|---|---|---|---|
| Gi1/0/1 | AP-01 | Wireless | Gi1/0/1 |
| Gi1/0/2 | Phone/User | Voice/Data | Gi1/0/2 |
| Gi1/0/47 | Distribution-1 | Trunk | Uplink 1 |
| Gi1/0/48 | Distribution-2 | Trunk | Uplink 2 |
Label cables before the maintenance window.
Step 4: Document VLANs and Dependencies
Confirm which VLANs must exist locally and which are transported through trunks.
Identify DHCP, DNS, gateway, authentication and management dependencies.
Step 5: Select the Correct Catalyst 9200 Hardware
Match:
- port count
- PoE budget
- access speed
- uplink speed
- stacking
- PSU requirements
- redundancy
- future capacity
Step 6: Verify Software and Licensing
Confirm the intended IOS XE release and required Network Essentials or Network Advantage feature level.
Current Catalyst 9200 procurement also requires attention to Cisco’s applicable subscription licensing framework. Licensing should therefore be part of the BOM, not something investigated after the hardware arrives.
Step 7: Prepare the Catalyst 9200 Offline
Where possible, stage the replacement before taking it to production.
Configure the basics:
- hostname
- management
- administrative access
- VLANs
- trunks
- security
- logging
- NTP
- AAA
- required routing
Step 8: Translate the Existing Configuration
Do not blindly paste the Catalyst 3650 configuration.
Use it as a source document.
Review every section and decide whether it should be:
retained → modified → replaced → removed
Step 9: Configure Management and Security
Test management access before deployment.
Verify:
- SSH
- AAA
- TACACS+/RADIUS
- management VLAN
- default gateway or routing
- SNMP
- syslog
- NTP
Step 10: Validate VLANs, Trunks and EtherChannels
Check trunk encapsulation assumptions, allowed VLANs, native VLANs and channel configuration.
Both ends of an EtherChannel need compatible settings.
Step 11: Schedule the Maintenance Window
Define:
- cutover start
- expected outage
- validation period
- decision point for rollback
- responsible engineers
- business contacts
Step 12: Replace the Physical Switch
Power down and disconnect the legacy switch according to the documented port map.
Install the Catalyst 9200 with the correct:
- PSUs
- uplink module where applicable
- stack components
- transceivers
- rack accessories
Step 13: Reconnect Uplinks First
Bring up the network-facing links and verify upstream connectivity.
Then reconnect endpoints in a controlled sequence.
Step 14: Verify Spanning Tree
Check:
- root bridge
- port roles
- blocked/forwarding state
- topology changes
- unexpected loops
Do not assume STP is correct simply because users can reach the network.
Step 15: Verify Routing
For Layer 3 deployments, validate:
- SVIs
- routes
- neighbors
- gateway reachability
- routing adjacencies
- required redundancy protocols
Step 16: Validate PoE Devices
Confirm APs, phones and cameras receive the expected power and boot correctly.
Check the switch’s total available and consumed PoE capacity.
Step 17: Test Business-Critical Services
Test actual services, not just ping.
Examples include:
- user authentication
- Internet access
- internal applications
- VoIP
- wireless
- cameras
- printing
- building systems
Step 18: Monitor Logs and Errors
Review:
- interface errors
- flaps
- authentication failures
- STP changes
- routing events
- PoE warnings
- EtherChannel problems
Step 19: Keep the Rollback Option
Do not immediately dismantle or erase the old switch.
If a critical issue cannot be resolved within the approved maintenance window, the rollback plan should allow the known working environment to be restored.
Step 20: Document the New Environment
Update:
- network diagrams
- port maps
- rack diagrams
- asset records
- switch inventory
- serial numbers
- software versions
- licenses
- monitoring
- backup systems
A migration is not complete until the documentation reflects production.
Can You Copy a Catalyst 3650 Configuration Directly to a 9200?
You should not blindly copy an entire Catalyst 3650 configuration onto a Catalyst 9200.
Both platforms use Cisco IOS XE, which means many familiar configuration concepts remain. That does not make their configurations universally interchangeable.
Differences may exist in:
- interface naming
- platform-specific commands
- QoS implementation
- stack configuration
- deprecated commands
- security features
- management commands
- licensing-dependent functions
- commands changed across IOS XE releases
A safer workflow is:
Existing configuration → Review → Remove obsolete commands → Translate → Stage → Validate → Deploy → Test
This is also an opportunity to remove years of unused configuration.
Configuration Areas That Need Special Attention
VLANs and Trunks
Verify VLAN IDs, names, access assignments, voice VLANs, trunk native VLANs and allowed VLAN lists.
Spanning Tree
Preserve the intended topology rather than blindly preserving every command.
Check root bridge priorities and edge-port protections.
EtherChannel / Port-Channel
Validate LACP or other channel configuration on both ends.
Ensure member interfaces have compatible speed, trunking and VLAN settings.
Layer 3 Interfaces
Review every SVI and routed interface.
Confirm addresses, masks, helper addresses and operational dependencies.
Static and Dynamic Routing
Network Essentials and Network Advantage do not provide identical Layer 3 feature sets.
Advanced routing requirements should be identified during procurement.
ACLs
Check syntax, placement, direction and object dependencies.
After migration, test the applications the ACL is intended to protect or permit.
QoS
Legacy QoS deserves explicit review because platform architecture and configuration methods can differ.
Do not migrate old QoS commands purely because they existed on the previous switch.
Voice VLANs
Test both phone registration and attached workstation connectivity.
Voice problems can exist even when the data VLAN appears normal.
PoE
Confirm the new switch has sufficient total budget and appropriate per-port capability.
After cutover, verify actual power allocation.
Port Security
Review learned MAC behavior, maximum addresses, violation mode and whether the old configuration remains appropriate.
DHCP Snooping
Confirm trusted interfaces, required VLANs and related security dependencies.
AAA
Test local emergency access before relying entirely on TACACS+ or RADIUS.
An AAA error during a migration can leave engineers unable to administer the new switch.
SNMP and Monitoring
Ensure monitoring platforms recognize the new device and receive the required telemetry, SNMP and syslog data.
Management Access
Verify SSH, source interfaces, ACLs, management routes, DNS and NTP.
Stack Configuration
Design the Catalyst 9200 stack independently.
Member numbering, physical cabling and interface mappings should be planned before cutover.
Example Migration Checklist
| Migration Item | Before Cutover | After Cutover |
|---|---|---|
| Configuration backup | Saved externally | Retain legacy backup |
| VLANs | Document all required VLANs | Confirm active |
| Uplinks | Verify speed/optics | Confirm links and traffic |
| PoE | Calculate required budget | Verify allocation |
| Routing | Document routes/neighbors | Validate reachability |
| STP | Record root/port states | Compare topology |
| EtherChannel | Record members/protocol | Verify bundled state |
| Management | Stage and test | Confirm remote access |
| Monitoring | Record integrations | Confirm telemetry/alerts |
| Endpoints | Build port map | Test connectivity |
| Voice | Record voice VLANs | Test calls/registration |
| Wireless | Record AP ports | Confirm AP operation |
| Security | Audit ACL/AAA features | Test enforcement |
| Logs | Capture baseline | Review warnings/errors |
| Rollback | Old hardware/config ready | Retain until sign-off |
Common Catalyst 3650 to 9200 Migration Problems
Wrong Uplink Configuration
A replacement switch may have enough access ports but the wrong uplink architecture.
Prevention: verify speed, connector, network module and optics before ordering.
Insufficient PoE Budget
The new switch supports PoE+, but total available watts are insufficient.
Prevention: calculate the total endpoint load before selecting PSU and switch configuration.
Transceiver Compatibility Problems
Existing optics should not automatically be assumed appropriate for the new hardware.
Prevention: inventory exact transceiver part numbers and validate them during design.
Configuration Syntax Differences
Old commands may be rejected, modified or inappropriate.
Prevention: translate and stage the configuration rather than pasting it during cutover.
Missing VLANs
A trunk can be operational while an application still fails because a required VLAN is missing.
Prevention: document VLAN dependencies and compare before/after state.
Incorrect Trunk Allowed VLANs
A single omitted VLAN can isolate phones, APs or servers.
Prevention: explicitly compare allowed VLAN lists.
EtherChannel Mismatch
Inconsistent channel mode or interface settings can prevent links from bundling correctly.
Prevention: verify both ends before migration.
Unexpected STP Changes
The new switch can alter root selection or path calculations if the topology is not understood.
Prevention: capture the old STP state and deliberately reproduce the intended topology.
Licensing Mismatch
The purchased license may not support an advanced feature used by the legacy environment.
Prevention: map required features to Network Essentials or Network Advantage before ordering.
AAA Failure
The switch is reachable but administrators cannot log in.
Prevention: test AAA and maintain a controlled local fallback method during staging.
Monitoring Failure
The network works, but operations teams lose visibility.
Prevention: include SNMP, telemetry, syslog and monitoring validation in the acceptance checklist.
Incorrect Port Mapping
Endpoints are connected to interfaces with the wrong VLAN or security policy.
Prevention: create and physically verify the port map before cutover.
Stack Problems
Stack cables, member planning or switch configuration may be incorrect.
Prevention: build and validate the new stack offline where possible.
When Catalyst 9200 May Not Be the Best Replacement
Catalyst 9200 should not be selected automatically simply because it is newer than Catalyst 3650 or 3560.
A Catalyst 9300 or another platform deserves consideration where the site requires:
- more demanding routing
- higher access-layer performance
- greater scale
- more advanced segmentation
- more demanding stacking architecture
- advanced campus capabilities
- higher-density multigigabit connectivity
- architecture extending beyond a conventional access-layer role
The distinction becomes especially important if the existing Catalyst 3650 has gradually taken on functions beyond basic access switching.
For example, a switch performing substantial dynamic routing and acting as an important aggregation point should not automatically be replaced with an access switch chosen only by matching its 48 copper ports.
The migration is a chance to correct the architecture rather than perpetuate it.
Catalyst 9200 Replacement Planning for GCC Businesses
Organizations in the UAE, Saudi Arabia, Qatar, Kuwait, Bahrain and Oman should include procurement considerations in the migration plan alongside the technical design.
Confirm the complete bill of materials before ordering:
- exact Catalyst SKU
- Network Essentials or Network Advantage
- current applicable software subscription
- PSU configuration
- power cables
- network modules
- stacking components
- optics
- transceivers
- rack accessories
- support requirements
Hardware availability also matters for multi-site refresh projects.
If 30 branches need to be upgraded, consistency across the deployment can be more valuable than sourcing different configurations for each location based only on immediate availability.
Organizations preparing a Cisco access-layer refresh can compare Netseg’s Catalyst 9200 replacement options based on port density, PoE requirements, uplinks and deployment architecture.
For larger projects, create a standard approved configuration for each site type, such as:
Small branch → Standard office → High-PoE site → Large campus access closet
This makes procurement, configuration templates, spares and operational support easier to standardize.
Frequently Asked Questions
What replaces the Cisco Catalyst 3650?
Catalyst 9200 is a suitable replacement candidate for many Catalyst 3650 access-layer deployments, but there is no universal one-to-one replacement. The correct model depends on ports, PoE, uplinks, stacking, routing and licensing. More demanding environments may justify evaluating Catalyst 9300.
Can I replace a Catalyst 3650 with a Catalyst 9200?
Yes, in many enterprise access-layer networks. Before replacing it, verify the existing 3650’s exact SKU, PoE load, uplinks, stack configuration, Layer 3 functions and software features. The new switch should be selected around these requirements rather than only matching the port count.
What replaces a Cisco Catalyst 3560?
Catalyst 9200 can be an appropriate modern replacement for many legacy Catalyst 3560 access deployments. Because the 3560 family spans several generations, first identify the exact model and feature set. Older configurations may require more configuration translation and hardware redesign than a straightforward 3650 refresh.
Can a Catalyst 3650 configuration be used on a Catalyst 9200?
Parts of the configuration may be reusable, but the entire configuration should not be copied blindly. Review VLANs, trunks, STP, EtherChannels, routing, ACLs, QoS, security, management and stacking individually. Remove obsolete or platform-specific commands and validate the translated configuration before production cutover.
What is the difference between Catalyst 9200 and 9200L?
C9200 provides modular uplinks and StackWise-160 on applicable models, while C9200L uses fixed uplinks and StackWise-80. C9200 also provides more hardware flexibility in areas such as field-replaceable components. C9200L can be a cost-effective choice where fixed uplinks and its stacking architecture meet the site’s requirements.
Should I choose Catalyst 9200 or Catalyst 9300?
Choose based on workload and architecture rather than product hierarchy. Catalyst 9200 fits many branch and enterprise access deployments. Catalyst 9300 deserves evaluation where greater scale, performance, advanced capabilities, stacking requirements or future campus architecture exceed what the selected Catalyst 9200 configuration provides.
Do I need new licenses when migrating to Catalyst 9200?
Yes, plan licensing as part of the new Catalyst 9200 purchase rather than assuming the legacy Catalyst 3650 license transfers directly. Select Network Essentials or Network Advantage according to required features and account for Cisco’s current applicable subscription licensing requirements when building the bill of materials.
What should I check before upgrading from Catalyst 3650?
Start with the exact SKU, port usage, PoE load, uplinks, optics, stack design, VLANs, STP, EtherChannels, routing, security, QoS, AAA, management and licensing. Back up the configuration and operational state, create a port map, define post-cutover tests and maintain a tested rollback plan.