Catalyst 9200 vs 9300: Four Things Decide It, and Port Count Is Not One of Them
Written and maintained by Haink's network infrastructure team · Verified against Cisco data sheets, 22 August 2026 · authorized-channel, serial-verified
The short version. The 9200 is an access switch that does access-switch things well and cheaply. The 9300 is what you buy when one of four specific requirements exists: power above 30 W per port, 256-bit MACsec, a fabric role beyond edge, or shared power across a stack. If none of those four apply, the 9200 is the correct answer and paying for a 9300 is paying for headroom you will not use.
Almost every other difference — table sizes, buffers, stack bandwidth — is real and rarely decisive at the access layer. These four are decisive, because each one is a capability the 9200 does not have at any configuration or price.
The four that decide
1. PoE above 30 watts
The Catalyst 9200 and 9200L top out at IEEE 802.3at PoE+ — 30 W per port. There is no UPOE option, no 802.3bt option, at any SKU in the family.
That is fine for Wi-Fi 6 access points, IP phones, cameras and most access-layer loads today. It is not fine for Wi-Fi 7. A Cisco CW9176I comes up on PoE+ but runs degraded — a 2.5G uplink instead of 10G and 2×2 instead of 4×4 on 2.4 GHz — and a CW9178I needs UPOE+ at 90 W. Since the Wi-Fi 6 access points went end-of-sale, this has moved from a theoretical difference to the most common reason a 9200 refresh turns into a 9300 order. The detail is in the Wi-Fi 6 end-of-sale guide.
2. MACsec-256
The 9200 does 128-bit MACsec. It does not do 256-bit — with the single exception of the 9200CX compact models. The 9300 does AES-256 across the range.
For most campus estates this is irrelevant. Where a security standard or a regulator specifies 256-bit link encryption, it is not a preference, and it eliminates the 9200 immediately regardless of everything else on the comparison sheet.
3. The SD-Access role
The 9200, 9200L and 9300L can serve as fabric edge nodes and nothing else. Border node, control plane node and Fabric-in-a-Box roles require a Catalyst 9300.
This is worth checking early, because a design that puts a 9200 in a role it cannot fill does not fail at procurement — it fails at deployment, when the fabric will not accept the device in that role.
4. StackPower
StackPower — shared power across the members of a stack, so a supply failure in one switch is covered by the others — exists on the 9300 and 9300X and not on the 9200, 9200L or even the 9300L. Cisco supports it only on models with modular uplinks.
Up to four switches share power in a ring without extra hardware; up to eight through an XPS-2200 in a star. If the resilience design assumes it, the 9200 and 9300L are both out.
Everything else, for completeness
| C9200L | C9200 | C9300 | C9300X | |
|---|---|---|---|---|
| ASIC | UADP 2.0 Mini | UADP 2.0 Mini | UADP 2.0 | UADP 2.0sec |
| MAC addresses | 16,000 | 32,000 | 32,000 | 32,000 |
| IPv4 routes | 11,000 | 14,000 | 32,000 | 39,000 |
| IPv6 routes | 1,500 | 2,000 | 16,000 | 19,500 |
| Multicast routes | 1,000 | 1,000 | 8,000 | 8,000 |
| ACL entries | 1,500 | 1,600 | 5,120 | 8,000 |
| SVIs | 512 | 512 | 1,000 | 1,000 |
| Virtual networks | 1 | 4 (32 on -PB) | Not published as a limit | |
| Stack bandwidth | 80 Gbps | 160 Gbps | 480 Gbps | 1 Tbps |
| Uplinks | Fixed in SKU | Modular to 40G | Modular to 40G | Modular to 100G |
| Hardware IPsec | No | No | No | Yes |
Two notes on things people commonly get wrong here. Modular uplinks are not the 9200/9300 dividing line — the 9200 has them too (C9200-NM-4G, -4X, -2Y, -2Q); it is the 9200L that has fixed uplinks. And the 9300X runs UADP 2.0sec, not the UADP 3.0 that gets quoted almost everywhere.
Three scenarios
Campus access, wired only, PoE+ sufficient
9200L. Fixed uplinks are fine when you know the uplink speed at purchase, and the price gap against the 9300 across a two-hundred-switch estate is substantial. This is the majority case and the 9200L is genuinely the right switch for it.
Campus access with a wireless refresh in the same budget cycle
9300, U or H suffix. The wireless requirement sets the PoE class, and the PoE class sets the family. Buying 9200 now and discovering the power ceiling in eighteen months means buying the access layer twice. Which suffix depends on whether CW9178-class access points are in scope — see the suffix comparison.
Small site acting as its own core
9300. A branch where the access switch also terminates routing, runs a fabric role, or needs the route table needs the 9300's tables and roles. The 9200's 14,000 IPv4 routes and 2,000 IPv6 routes are an access-layer allocation.
The cost comparison people skip
Both families carry the same licensing structure — a perpetual Network Essentials or Advantage tier, plus a mandatory subscription of three, five or seven years. So the comparison is not hardware against hardware; it is the whole stack against the whole stack, and the subscription is priced per switch either way.
What changes the arithmetic is the replacement horizon. A 9200 bought today with PoE+ has a defined ceiling: it cannot power a Wi-Fi 7 access point at full specification, ever. If the wireless refresh lands inside the switch's service life, the 9200's lower price buys a shorter life. If it does not — if the site is wired-heavy, or the wireless is someone else's budget in five years — the 9200 is simply cheaper and there is no catch.
The honest question to answer before choosing is not "which switch is better" but "when does this site's wireless get replaced, and out of whose budget."
Tell us the site, we'll tell you which family
Send port counts, what is being powered, and whether wireless is in the same refresh. We come back with the right family and suffix, the licence tier, and firm lead times — including the case for the cheaper switch where it holds. Within one business day.
Frequently asked questions
Can a Catalyst 9200 power a Wi-Fi 7 access point?
It can power one, but not at full specification. The 9200 and 9200L provide PoE+ at 30 W maximum, and a CW9176I on PoE+ runs with a 2.5G uplink instead of 10G and 2×2 instead of 4×4 on 2.4 GHz. Full performance needs UPOE or UPOE+, which means a 9300.
Does the Catalyst 9200 support MACsec?
128-bit, yes. 256-bit MACsec is not available on the 9200 or 9200L — only on the 9200CX compact models and on the 9300 range.
Can a Catalyst 9200 be an SD-Access border node?
No. The 9200, 9200L and 9300L support the fabric edge role only. Border node, control plane node and Fabric-in-a-Box require a Catalyst 9300.
Does the Catalyst 9200 support StackPower?
No. StackPower is supported only on models with modular uplinks — the 9300 and 9300X. The 9200, 9200L and 9300L do not have it.
Is the difference in route table size a practical problem?
Rarely at the access layer. The 9200's 14,000 IPv4 routes are ample for a switch doing routed access. It becomes a problem when the switch is also the site's router, which is when the 9300 is the right family for reasons beyond the table anyway.
Which is better value across a large estate?
Usually the 9200, if PoE+ is sufficient and will remain sufficient for the switch's service life. Both families carry the same licensing structure, so the saving is real rather than deferred — provided the wireless roadmap does not overtake the switch.
Related
- How to read a Cisco Catalyst part number
- C9300-48P vs 48U vs 48UXM vs 48UN — choosing within the 9300
- Wi-Fi 6 AP end-of-sale — the PoE requirement that decides the family
- Catalyst 2960-X replacement — where both families are the migration target
- Cisco licensing explained · Is the DNA subscription mandatory?
- Enterprise switches · Cisco stock and lead times
