Catalyst 9300 vs 9300X: a Different Switch, and Not the One the Spec Sheets Claim
Written and maintained by Haink's network infrastructure team · Verified against Cisco data sheets and the architecture white paper, 22 August 2026 · authorized-channel, serial-verified
Start with a correction, because it is repeated almost everywhere including on large reseller sites: the Catalyst 9300X does not use the UADP 3.0 ASIC. Cisco's own architecture white paper identifies it as UADP 2.0sec. The 9300X is genuinely a much larger switch than the 9300 — but the reason is bandwidth and features, not a new ASIC generation.
What actually separates them comes down to three things a 9300 cannot do at any configuration: 100G uplinks, hardware IPsec, and UPOE+ combined with multigigabit on every port.
The comparison
| Catalyst 9300 | Catalyst 9300X | |
|---|---|---|
| ASIC | UADP 2.0 (2.0 XL on B models) | UADP 2.0sec — not 3.0 |
| ASIC bandwidth | 160G or 240G | 500G |
| Stack bandwidth | StackWise-480 | StackWise-1T |
| Throughput (48-port) | 580 Gbps standalone, 1,060 stacked (48UXM) | 1,760 Gbps standalone, 2,760 stacked (48HX) |
| IPv4 routes | 32,000 | 39,000 |
| IPv6 routes | 16,000 | 19,500 |
| Security ACL TCAM | 5,120 (18,000 on B) | 8,000 |
| DRAM | 8 GB | 16 GB |
| Uplinks | Up to 40G (C9300-NM-2Q) | Up to 100G (NM-2C, NM-4C) |
| Hardware IPsec | None | 100G line-rate, requires HSEC key |
| MACsec | AES-128 and AES-256 | AES-128 and AES-256 |
| UPOE+ 90 W | Only H models (24H, 48H) | All HX and HXN models |
| StackPower | StackPower | StackPower+ |
Models in the 9300X family: C9300X-24HX, C9300X-48HX, C9300X-48HXN, C9300X-48TX, C9300X-24Y and C9300X-12Y, each in -E, -A and -M variants.
The three reasons to pay for it
1. You need 100G uplinks from the access layer
The 9300's uplink ceiling is 40G, from the C9300-NM-2Q. The 9300X takes the C9300X-NM-2C or NM-4C at 40 or 100G. If the distribution layer is moving to 100G — which is increasingly the case where the campus core has been refreshed to Nexus 9300-GX — the access switch either follows or becomes the bottleneck.
Note the module restriction: the four-port C9300X-NM-4C fits only the C9300X-48HX, C9300X-48TX and C9300X-24Y. And modules do not travel between families in that direction — Cisco states that 9300X modules are supported only on 9300X models, though older Catalyst 3850 modules do work in a 9300.
2. You need IPsec in hardware
This is the capability with no equivalent anywhere else in the family. The 9300X does 100G line-rate IPsec in silicon, gated behind an HSEC key. For a site that needs encrypted transport between buildings or to a data centre without adding a separate router, that collapses two boxes into one.
The 9300 has no hardware IPsec at all. MACsec is available on both — including AES-256 — but MACsec encrypts a link between adjacent devices; it is not a substitute for a routed encrypted tunnel.
3. You need 90 W and 10G on the same port
The C9300X-48HX is the only 48-port model in the whole Catalyst 9300 range that gives UPOE+ at 90 W and multigigabit to 10G on every port. The standard 9300 forces a choice: 48H gives you 90 W on gigabit ports, 48UXM gives you 10G on twelve ports at 60 W.
For high-density Wi-Fi 7 — where CW9178I access points draw about 95 W and the airtime genuinely justifies a 10G uplink — the HX is the only single-switch answer. In a standard office it is usually more switch than the deployment needs; see the suffix comparison for where the cheaper models are correct.
When the 9300 is the right answer
Most of the time, honestly. If the uplinks are 10G or 40G, if there is no IPsec requirement, and if the PoE need is met by UPOE at 60 W, the 9300 does the same job for less. The extra tables on the 9300X — 39,000 IPv4 routes against 32,000 — are a marginal difference at the access layer, and the 500G ASIC bandwidth only shows up under load that an access switch rarely sees.
Where the 9300X earns its price is as a small-site core or a collapsed core-and-access, where one switch is doing routing, encryption and access simultaneously. Bought purely as an access switch it is usually over-specified.
What to check before choosing
- What speed is the uplink to distribution? If 100G, the family is decided.
- Is there an encryption requirement, and is it link-level or routed? MACsec covers the first on both families; only the 9300X covers the second in hardware.
- Do any ports need both 90 W and 10G? That combination exists only on HX and HXN.
- Check the module against the chassis — the NM-4C fits only three of the six 9300X models.
- Confirm the ASIC claim in any competing quote. If it says UADP 3.0, the quote was not written from the Cisco documentation.
Send the requirement, we'll say which family
Uplink speed, PoE loads, encryption requirement and port speeds. We come back with the family, the model, the uplink module that fits it, and firm lead times — and we will say when the 9300 does the job. Within one business day.
Frequently asked questions
Does the Catalyst 9300X use UADP 3.0?
No. Cisco's architecture white paper identifies the 9300X ASIC as UADP 2.0sec. It carries 500G of ASIC bandwidth against the 9300's 160G or 240G, but it is not a new ASIC generation.
Can a Catalyst 9300 take 100G uplinks?
No. The 9300's uplink ceiling is 40G with the C9300-NM-2Q. The 100G modules — C9300X-NM-2C and NM-4C — are supported only on 9300X chassis.
Does the Catalyst 9300 support IPsec?
Not in hardware. Only the 9300X offers line-rate hardware IPsec, and it requires an HSEC key. Both families support MACsec including AES-256, but MACsec is link encryption rather than a routed tunnel.
Which model gives 90 W and 10G on the same port?
The C9300X-48HX and C9300X-24HX. On the standard 9300, the 48H gives 90 W on gigabit ports and the 48UXM gives 10G on twelve of forty-eight ports at 60 W.
Can I use my existing network modules in a 9300X?
No. Cisco states that Catalyst 9300X network modules are supported only on 9300X models, which implies the reverse restriction as well. Catalyst 3850 modules do work in the standard 9300.
Is the 9300X worth it as a pure access switch?
Usually not. The larger tables and ASIC bandwidth rarely bind at the access layer. It earns its price as a small-site core or collapsed core-and-access doing routing and encryption alongside access.
Related
- How to read a Cisco Catalyst part number
- C9300 suffix comparison · Catalyst 9200 versus 9300
- Nexus 9300 refresh — where the 100G distribution layer comes from
- Cisco licensing explained — including the HSEC key
- Enterprise switches · Optic modules · Cisco stock and lead times
Sources
- Cisco — Catalyst 9300 architecture white paper (UADP 2.0sec, ASIC bandwidth)
- Cisco — Catalyst 9300 Series data sheet (models, modules, tables, throughput)
- Cisco — Catalyst 9300 ordering guide
