The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Feedback
Cisco C9610 Series Smart Switches, Release Cisco IOS XE 26.2.x
Cisco C9610 Series Smart Switches, Release Cisco IOS XE 26.2.x
Cisco C9610 Series Smart Switches are the next-generation hardware designed to redefine campus switching with high port density and exceptional bandwidth capabilities. Designed to power the AI Enterprise, these switches support 25G, 100G, and 400G uplinks and are ready for 50G, future-proofing your workplace.
Look up Cisco Feature Navigator for the complete list of supported features.
This section provides a brief description of the new software features introduced in Cisco IOS XE 26.2.x releases.
Software Features in Cisco IOS XE 26.2.1
Table 1. New software features for Cisco C9610 Series Smart Switches, Release Cisco IOS XE 26.2.1
| Product impact |
Feature |
Description |
| API experience |
Enhanced Network Traffic Monitoring |
You can now utilize Flexible NetFlow for enhanced network traffic monitoring and analysis, providing customizable flow records that improve anomaly detection and security. By defining specific key and non-key fields within flow records, you gather detailed statistics for efficient accounting, network monitoring, and planning, allowing for better insight into network behavior. |
| Ease of Setup |
Auto-QoS |
Auto-QoS simplifies QoS deployment by automatically generating and applying policies that classify, mark, police, and queue traffic for appropriate prioritization. It uses the Modular QoS CLI model to create global class maps and policy maps, assigns matched traffic to QoS groups, and maps traffic classes to output queues, including a priority queue for real-time traffic. Auto-QoS supports Layer 2 and Layer 3 ports. |
| Ease of Setup |
Local Area Bonjour in Multicast DNS (mDNS) |
Local Area Bonjour in Multicast DNS (mDNS) enables devices to discover local network services across LAN and wireless network segments. You can configure service definitions, service lists, and service policies to control the Bonjour service traffic allowed on each VLAN interface. Wireless deployments require transparent mDNS forwarding through the wireless LAN controller. |
| Software Reliability |
Flexible NetFlow Top N Talkers Support |
Flexible NetFlow (FNF) Top N Talkers support enabling identification of the highest-volume traffic flows. |
| Software Reliability |
Hierarchical Quality of Service (HQoS) |
Hierarchical Quality of Service (HQoS) provides granular bandwidth management by applying parent and child QoS policies to traffic. A parent policy manages overall bandwidth on an interface, while child policies classify, police, shape, queue, or remark specific traffic classes. This hierarchy enables prioritized handling of services, such as voice and video, within the parent bandwidth limit. |
| Software Reliability |
Live Protect |
Live Protect validates security shields that protect Cisco products without requiring device reloads or service interruptions. You can deploy security shields in two modes:
● Monitoring mode: Provides visibility into potential exploit attempts without enforcement, allowing you to assess threats before taking action.
● Enforce (Protecting) mode: Actively applies mitigation policies to reduce exposure to known vulnerabilities.
Live Protect allows you to monitor, enforce, disable, and retire the security shields enabling a smooth transition to remediation. This capability helps businesses maintain continuous operations while managing risks until the software upgrades or patches are deployed. |
| Software Reliability |
Multicast VPN-Rosen with PIM + GRE encapsulation (Rosen) IPv4/IPv6 |
Multicast VPN (mVPN) using the Rosen model is a mechanism for carrying IP multicast traffic across an MPLS/IP backbone, enabling service providers or large enterprises to deliver multicast services over a shared network infrastructure while maintaining per-VPN routing isolation. |
| Software Reliability |
Negotiated port-speed |
On-change subscriptions support negotiated-port-speed leaf to enable real-time notifications along with the existing subscription-based access. |
| Software Reliability |
Flexible NetFlow Enhancements |
The following enhancements have been introduced for Flexible NetFlow:
● Layer 2 fields, M/N sampling, multicast ingress, TCP flags, and VRF-aware NDE export
● AVC ACE support to learn flows only for TCP/UDP packets
● Multicast traffic on SVI or Layer 3
● Layer 3 AC and FWD VLAN ingress
● New insight commands
|
| Software reliability |
Optimize TCP Session Stability |
You can now prevent TCP sessions from being dropped by configuring the maximum segment size for transient TCP SYN packets using the ip tcp adjust-mss command. This adjustment ensures packets adhere to the correct MTU size, avoiding packet truncation and maintaining stable connections across different network environments. |
| Software Reliability |
PQC dual-sign support |
Dual signing enhances software authenticity and integrity by preparing systems for post quantum cryptographic requirements while maintaining backward compatibility. This approach adds both a legacy RSA signature and a quantum-resistant ML-DSA-87 signature to IOS-XE software images. Supported platforms verify the stronger quantum-resistant seal, while older systems continue to rely on the existing RSA signature. This method ensures seamless operation in mixed environments and reduces disruption during the transition to next-generation security standards. |
| Software Reliability |
RACL Multicast |
Enables RACL filtering for multicast packets. |
| Software Reliability |
Resilient Infrastructure changes |
As part of Cisco’s Resilient Infrastructure program and Cisco’s commitment to secure infrastructure, this release includes additional changes aimed towards continuing to make Cisco IOS XE more secure by default. Note that some of these changes may require operational changes if you are not following secure best practices. This release includes the following changes:
● The RADIUS client appends the Message-Authenticator attribute (Attribute 80 HMAC-MD5) to all outgoing Access-Request packets to mitigate cryptographic forgery and
Blast-RADIUS vulnerabilities (CVE-2024-3596).
● The RADIUS client drops incoming Access-Accept, Access-Reject, and Access-Challenge packets if the Message-Authenticator packet is absent or invalid. Ensure AAA servers (example, Cisco ISE) are configured to return Attribute 80.
● Outbound SSH connections enforce Trust-On-First-Use (TOFU). The device prompts to verify and store remote server host keys in the known-hosts database on first connection and validates against them on subsequent sessions.
● Proxy ARP is disabled by default across all routed interfaces, SVIs, and subinterfaces to reduce Layer 2 broadcast domains and prevent ARP spoofing. Configure the
ip proxy-arp command explicitly if required.
● The embedded web server daemon is disabled by default on factory configurations to restrict unauthenticated management access. Web UI and RESTCONF require explicit enablement of the
ip http secure-server command.
● The IOS XE device rejects unauthenticated NTP Mode 6 and Mode 7 control queries (monlist) to prevent NTP reflection and amplification DDoS attacks. Standard time synchronization (Modes 3 and 4) is unaffected.
● System logging timestamps automatically include the four-digit calendar year (service timestamps log datetime msec year) to standardize multi-year audit logs and SIEM compliance.
● Integrates Linux auditd inside Cisco IOx Guest Shell. All commands, system calls, and privilege escalation events (sudo) executed inside the container are forwarded to the host syslog facility.
● Warning messages are emitted on the console and logged to syslog whenever legacy insecure protocols (telnet, ftp, tftp, http) are enabled in the configuration.
● Real-time tracking of active insecure services is published to the operational database (operDB) and YANG data models, allowing management controllers (such as Cisco Catalyst Center) to monitor security compliance.
For more information, refer Resilient Infrastructure. |
| Software Reliability |
Switch-to-switch MACsec encryption |
MACsec is the IEEE 802.1AE standard for authenticating and encrypting packets between two MACsec-capable devices. Support for switch-to-switch MACsec encryption was introduced. |
| Upgrade |
PQC support with ML-DSA algorithm |
Secure your enterprise data against future quantum threats with the new ML-DSA algorithm support. This update integrates quantum-resistant technology to protect your systems from advanced quantum-mechanical calculations. By adopting these algorithms, you ensure long-term data integrity and maintain robust security standards for your environment. |
This section provides a brief description of the new hardware features introduced in Cisco IOS XE 26.2.x releases.
Hardware Features in Cisco IOS XE 26.2.1
There are no new hardware features in this release.
This section provides a brief description of the behavior changes introduced in Cisco IOS XE 26.2.x releases.
Hardware and Software Behavior Changes in Cisco IOS XE 26.2.1
Table 2. Behavior changes for Cisco C9610 Series Smart Switches, Release Cisco IOS XE 26.2.1
| Description |
Behavior changes |
| CDP and LLDP device ID |
In cloud-managed mode, CDP and LLDP use the device hostname as the device ID instead of the switch MAC address. |
| ISSU behavior on C9610R SVL |
ISSU from Cisco IOS XE 17.18.2 to 17.18.3 or 26.2.1 is impacted on C9610R SVL. |
| Line card OBFL storage |
Line card OBFL flash size is increased to 4 MB. When upgrading to a release with this change, existing historical line card OBFL data is erased once during the upgrade. |
| Port-channel VLAN configuration synchronization |
When the switchport trunk allowed vlan command is applied to a portchannel via the configuration database (CDB) or NETCONF, the inherited configurations on member interfaces do not synchronize with the CDB database. |
| SSD Online Insertion and Removal (OIR) |
When the disk0 SSD eject button is pressed on the C9610R Supervisor, SSD details are not displayed on the show inventory fru and show file systems command outputs. Any services dependent on disk0 (example, IOx) are gracefully stopped preventing the console from hanging. |
There are no resolved caveats in Cisco IOS XE 26.2.x releases.
There are no open caveats in Cisco IOS XE 26.2.x releases.
This section lists the limitations for this release.
● 1G transceivers are not supported on SFP+ management interfaces. Only 10G transceivers are supported on SFP+ management interfaces.
● In a chassis, do not configure a C9610-SUP-3 Supervisor Module with an existing C9610-SUP-3XL Supervisor Module or vice versa. If you do so, the supervisor module inserted later will be kept in ROMMON mode and will not be allowed to boot up.
● On Cisco C9610 Smart Switch with C9610-SUP-3/3-XL Supervisor Modules, only 10G transceiver is supported with CVR/QSA. Transceivers lower than 10G speed are not supported with CVR/QSA.
● On Cisco C9610 Smart Switch, SFP-10G-T-X module cannot operate in 1G mode.
● Hardware Limitations (Power Supply Modules):
◦ Input voltage for AC power supply modules: All AC-input power supply modules in the chassis must have the same AC-input voltage level.
◦ Using power supply modules of different types: When mixing AC-input and DC-input power supplies, the AC-input voltage level must be 220 VAC.
◦ The switch is not designed to operate with a combination of 2000W and 3000W PSUs together in a chassis.
To view the software compatibility information between Cisco C9610 Series Smart Switches, Cisco Identity Services Engine, and Cisco Prime Infrastructure, go to Cisco C9000 Series Smart Switches Software Version Compatibility Matrix.
This section lists the hardware support information.
Supported Cisco C9610 Series Smart Switches model numbers
The following table lists the supported switch models.
Table 3. Cisco C9610 Series Smart Switches model numbers
| Switch model |
Default license level |
Description |
Introductory release |
| C9610R |
Network Advantage |
Cisco C9610 Smart Switch
● Two redundant supervisor module capability
● Eight linecard slots
● Eight power supply module slots
● Four fan tray modules
|
Cisco IOS XE 17.18.1 |
Supported hardware on Cisco C9610 Series Smart Switches
Table 4. Supported hardware
| Product ID |
Description |
Introductory release |
| Supervisor Modules |
||
| C9610-SUP-3 |
Cisco C9610 series Supervisor 3 Module This supervisor module is supported on the C9610 chassis. |
Cisco IOS XE 17.18.1 |
| C9610-SUP-3XL |
Cisco C9610 series Supervisor 3XL Module This supervisor module is supported on the C9610 chassis. |
Cisco IOS XE 17.18.1 |
| Line Cards |
||
| C9610-LC-32CD |
30 QSFP28 ports that support 100G/40G and two QSFP-DD ports that support 400G/100G/40G. |
Cisco IOS XE 17.18.1 |
| C9610-LC-40YL4CD |
40 SFP56 ports of 50G/25G/10G/1G, two QSFP56 ports of 200G/100G/40G, and two QSFP-DD ports of 400G/200G/100G/40G. |
Cisco IOS XE 17.18.1 |
| C9600-LC-48TX |
48 Multigigabit Ethernet RJ45 copper ports that support 10G/1G. |
Cisco IOS XE 17.18.1 |
| C9600-LC-40YL4CD |
40 SFP56 ports of 50G/25G/10G/1G, two QSFP56 ports of 200G/100G/40G, and two QSFP-DD ports of 400G/200G/100G/40G. |
Cisco IOS XE 17.18.1 |
| C9600X-LC-32CD |
30 QSFP28 ports that support 100G/40G and two QSFP-DD ports that support 400G/100G/40G. |
Cisco IOS XE 17.18.1 |
| C9600X-LC-56YL4C |
56 SFP ports of 50G/25G/10G/1G and four QSFP28 ports of 100G/40G. |
Cisco IOS XE 17.18.1 |
Supported optics modules
Cisco Catalyst Series Switches support a wide range of optics and the list of supported optics is updated on a regular basis. Use the Transceiver Module Group (TMG) Compatibility Matrix tool, or consult the tables at this URL for the latest transceiver module compatibility information: https://www.cisco.com/en/US/products/hw/modules/ps5455/products_device_support_tables_list.html
This section provides information about the release packages associated with Cisco C9610 Series Smart Switches.
Finding the software version
The package files for the Cisco IOS XE software are stored on the system board flash device (flash:).
You can use the show version privileged EXEC command to see the software version that is running on your switch.
Note: Although the show version output always shows the software image running on the switch, the model name shown at the end of this display is the factory configuration and does not change if you upgrade the software license.
You can also use the dir filesystem: privileged EXEC command to see the directory names of other software images that you might have stored in flash memory.
Finding the software Images
Table 5. Software images
| Release |
Image type |
File name |
| Cisco IOS XE 26.2.1 |
CISCO9K_IOSXE |
cisco9k_iosxe.26.2.01.SPA.bin |
| No Payload Encryption (NPE) |
cisco9k_iosxe_npe.26.2.01.SPA.bin |
To download software images, visit the software downloads page: Cisco C9610 Series Smart Switches.
Note: StackWise Virtual feature is not supported on an NPE image.
ROMMON versions
ROMMON, also known as the boot loader, is firmware that runs when the device is powered up or reset. It initializes the processor hardware and boots the operating system software (Cisco IOS XE software image). The ROMMON is stored on the following Serial Peripheral Interface (SPI) flash devices on your switch:
● Primary: The ROMMON stored here is the one the system boots every time the device is powered-on or reset.
● Golden: The ROMMON stored here is a backup copy. If the one in the primary is corrupted, the system automatically boots the ROMMON in the golden SPI flash device.
ROMMON upgrades may be required to resolve firmware defects, or to support new features, but there may not be new versions with every release.
Table 6. ROMMON versions
| Release |
ROMMON Version |
| 26.2.1 |
26.2.1r |
| 26.1.2 |
26.1.1[FC4] |
| 26.1.1a |
26.1.1[FC4] |
| 17.18.2 |
17.18.2r |
| 17.18.1 |
17.18.1r |
Field-programmable gate array version upgrade
A field-programmable gate array (FPGA) is a type of programmable memory device that exists on Cisco switches. They are re-configurable logic circuits that enable the creation of specific and dedicated functions.
To check the current FPGA version for all the components on the C9610 switch, use the show firmware version all command.
Notes:
● Not every software release has a change in the FPGA version.
● The version change occurs as part of the regular software upgrade, and you do not have to perform any other additional steps.
This section provides troubleshooting information, links to the product documentation, and licensing information.
Troubleshooting
For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at Support & Downloads.
Go to Product Support and select your product from the list or enter the name of your product. Look under Troubleshoot and Alerts, to find information for the problem that you are experiencing.
Accessing hidden commands
Hidden commands have always been present in Cisco IOS XE but were not equipped with CLI help. That is, entering a question mark (?) at the system prompt did not display the list of available commands. These commands were only meant to assist Cisco TAC in advanced troubleshooting and were not documented either.
Hidden commands are available under:
● Category 1—Hidden commands in privileged or User EXEC mode. Begin by entering the service internal command to access these commands.
● Category 2—Hidden commands in one of the configuration modes (global, interface and so on). These commands do not require the service internal command.
Further, the following applies to hidden commands under Category 1 and 2:
● The commands have CLI help. Enter enter a question mark (?) at the system prompt to display the list of available commands.
● Note: For Category 1, enter the service internal command before you enter the question mark; you do not have to do this for Category 2.
● The system generates a %PARSER-5-HIDDEN syslog message when a hidden command is used. For example:
*Feb 14 10:44:37.917: %PARSER-5-HIDDEN: Warning!!! 'show processes memory old-header ' is a hidden command.
Use of this command is not recommended/supported and will be removed in future.
Apart from category 1 and 2, there remain internal commands displayed on the CLI, for which the system does NOT generate the %PARSER-5-HIDDEN syslog message.
Important: We recommend that you use any hidden command only under TAC supervision.
If you find that you are using a hidden command, open a TAC case for help with finding another way of collecting the same information as the hidden command (for a hidden EXEC mode command), or to configure the same functionality (for a hidden configuration mode command) using non-hidden commands.
Related documentation
For all support documentation of Cisco C9610 Series Smart Switches, visit Cisco C9610 Series Smart Switches.
For information about Cisco IOS XE, visit Cisco IOS XE.
For information about Cisco IOS XE releases, visit Networking Software (IOS & NX-OS).
For Cisco Validated Designs documents, visit Cisco Validated Design Zone.
To locate and download MIBs for selected platforms, Cisco IOS releases, and feature sets, use Cisco MIB Locator found at Cisco Feature Navigator.
Communications, services, and additional information
● To receive timely, relevant information from Cisco, sign up at Cisco Profile Manager.
● To get the business results you’re looking for with the technologies that matter, visit Cisco Services.
● To submit a service request, visit Cisco Support.
● To discover and browse secure, validated enterprise-class apps, products, solutions and services, visit Cisco DevNet.
● To obtain general networking, training, and certification titles, visit Cisco Press.
● To find warranty information for a specific product or product family, access Cisco Warranty Finder.
Licensing
For information about licenses required for the features available on Cisco 9000 Series Smart Switches, see Cisco Networking Subscription for Cisco C9000 Series Smart Switches.
Cisco bug search tool
Cisco Bug Search Tool (BST) is a web-based tool that acts as a gateway to the Cisco bug tracking system that maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. BST provides you with detailed defect information about your products and software.
Documentation feedback
To provide technical feedback on this document, or to report an error or omission, send your comments to cisco9k-docfeedback@cisco.com.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.
© 2026 Cisco Systems, Inc. All rights reserved.