Release Notes for Cisco Catalyst IE9300 Rugged Series Switches, Release 26.2.x

Available Languages

Download Options

  • PDF
    (464.1 KB)
    View with Adobe Reader on a variety of devices
Updated:September 27, 2026

Bias-Free Language

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Available Languages

Download Options

  • PDF
    (464.1 KB)
    View with Adobe Reader on a variety of devices
Updated:September 27, 2026
 

Cisco Catalyst IE9300 Rugged Series Switches, Release 26.2.x. 3

New software features. 3

New hardware features. 5

Change in behavior 5

Resolved issues. 6

Open issues. 6

Known issues. 6

Compatibility. 7

Supported hardware. 7

Supported software packages. 9

Related resources. 10

Legal information. 11

 


 

Cisco Catalyst IE9300 Rugged Series Switches, Release 26.2.x

This document provides release information for the following Cisco Catalyst IE switches.

●     Cisco Catalyst IE9310 GE Fiber switch

●     Cisco Catalyst IE9320 GE Fiber switch

●     Cisco Catalyst IE9320 Fiber switch with 10 GE uplinks

●     Cisco Catalyst IE9320 10 GE Copper Data switch

●     Cisco Catalyst IE9320 10 GE PoE switch

●     Cisco Catalyst IE9320 10 G mGig 4PPoE switch

●     Cisco Catalyst IE9320 GE PoE switch

●     Cisco Catalyst IE9310 GE mixed port switch

Cisco Catalyst IE9300 Rugged Series Switch

Cisco Catalyst IE9300 Rugged Series Switches provide rugged and secure switching infrastructure for harsh environments. They are suitable for industrial Ethernet applications, including manufacturing, utility substations, Intelligent Transportation Systems (ITS), rail transportation, and other similar deployments.

The switch fulfills the need for a high-density SFP, RJ-45, and Power over Ethernet (PoE) rack- or wall-mounted switch that can function as a Software-Defined Access (SDA) fabric edge. It provides end-to-end architectural uniformity in the Cisco Catalyst Center for Internet of Things (IoT) connected communities and extended enterprises.

In industrial environments, the switch can be connected to any Ethernet-enabled industrial communication devices. These devices include programmable logic controllers (PLCs), human-machine interfaces (HMIs), drives, sensors, and input and output (I/O) devices.

All Cisco Catalyst IE9300 Rugged Series Switches have 4 GB of DRAM, four alarm inputs, and one alarm output. Other I/O interfaces include the following:

●     SD card slot

●     Power input

●     RJ-45 (RS-232) console

●     Micro-USB console

●     USB-A host port

New software features

This section provides a brief description of the new software features introduced in Cisco IOS XE Release 26.2.x.

IOS XE 26.2.1

Table 1.             New software features release 26.2.1

Product Impact

Feature

Description

Security

Resilient Infrastructure

As part of Cisco’s Resilient Infrastructure program and Cisco’s commitment to secure infrastructure, this release includes additional changes aimed towards continuing to make Cisco IOS XE more secure by default. Note that some of these changes may require operational changes if you are not following secure best practices. This release includes the following changes:

●  The RADIUS client appends the Message-Authenticator attribute (Attribute 80 HMAC-MD5) to all outgoing Access-Request packets to mitigate cryptographic forgery and  Blast-RADIUS vulnerabilities (CVE-2024-3596).
●  The RADIUS client drops incoming Access-Accept, Access-Reject, and Access-Challenge packets if the Message-Authenticator is absent or invalid. Ensure AAA servers (example, Cisco ISE) are configured to return Attribute 80.
●  Outbound SSH connections enforce Trust-On-First-Use (TOFU). The device prompts to verify and store remote server host keys in the known-hosts database on first connection and validates against them on subsequent sessions.
●  Proxy ARP is disabled by default across all routed interfaces, SVIs, and subinterfaces to reduce Layer 2 broadcast domains and prevent ARP spoofing. Configure the  ip proxy-arp command explicitly if required.
●  The embedded web server daemon is disabled by default on factory configurations to restrict unauthenticated management access. Web UI and RESTCONF require explicit enablement of the  ip http secure-server command.
●  The IOS XE device rejects unauthenticated NTP Mode 6 and Mode 7 control queries (monlist) to prevent NTP reflection and amplification DDoS attacks. Standard time synchronization (Modes 3 and 4) is unaffected.
●  System logging timestamps automatically include the four-digit calendar year (service timestamps log datetime msec year) to standardize multi-year audit logs and SIEM compliance.
●  Integrates Linux auditd inside Cisco IOx Guest Shell. All commands, system calls, and privilege escalation events (sudo) executed inside the container are forwarded to the host syslog facility.
●  Warning messages are emitted on the console and logged to syslog whenever legacy insecure protocols (telnet, ftp, tftp, http) are enabled in the configuration.
●  Real-time tracking of active insecure services is published to the operational database (operDB) and YANG data models, allowing management controllers (such as Cisco Catalyst Center) to monitor security compliance.

Security

CIP Password encryption

Starting with Cisco IOS XE Release 26.2.1, Cisco Catalyst IE9300 Rugged Series Switches use Type 8 password protection for Common Industrial Protocol (CIP) configuration credentials. Type 8 password protection strengthens credential security by using a secure, nonreversible password-hashing mechanism.

Software Reliability

EVPN Multihoming All-Active Mode

EVPN multihoming all-active mode provides non-blocking Layer 2 connectivity by enabling traffic load balancing across redundant links. It improves network resiliency and utilization while maintaining continuous connectivity during link or device failures.

Enhanced Reliability

FlexLink+

FlexLink+ provides Layer 2 link redundancy without using STP. It supports active-standby failover on physical interfaces and EtherChannel bundles. VLAN load balancing lets both links forward traffic for different VLANs. After a failed link recovers, the preferred VLAN forwarding can be restored manually or automatically after a configured delay.

Security

HTTPS servers disabled by default except for express setup

Starting with Cisco IOS XE 26.2.1, HTTPS servers remain disabled by default, excluding express setup deployments which retain existing settings.

Security

Post Quantum Cryptography for MACsec with EAP-TLS

Cisco Industrial Ethernet switches can use ML-KEM-based key exchange with EAP-TLS 1.3 to provide quantum-resistant key establishment for MACsec connections. EAP-TLS derives keying material that MKA uses to establish secure MACsec communication between switches.

Security

Post Quantum Cryptography for SSHv2 Sessions

Cisco Industrial Ethernet switches can combine ML-KEM with traditional key-exchange algorithms to secure SSHv2 sessions. This hybrid approach provides quantum-resistant key establishment for secure remote management while retaining protection against classical attacks.

Security

PROFINET Netload-3 Robustness

This feature increases resilience to abnormal network traffic. It detects unexpected PROFINET Real-Time traffic, invokes Layer 2 source blocking, and rate-limits incoming Layer 3 traffic directed to the PROFINET VLAN IP address.

Upgrade

 

PTP over HSR

This release introduces Precision Time Protocol (PTP) over High-availability Seamless Redundancy (HSR), enabling millisecond-level time synchronization with zero network downtime. This feature ensures continuous PTP operation during network failures, eliminating the 4 to 10 second re-convergence delays that disrupt time-sensitive industrial applications. PTP over HSR supports Power Profile with Boundary Clock and P2P Transparent Clock modes for up to 50 nodes per HSR ring.

PTP over REP

 

This feature combines Precision Time Protocol with Resilient Ethernet Protocol to maintain millisecond-level time synchronization during network failures with <200 ms failover, eliminating PTP re-convergence delays that disrupt industrial applications.

Enhanced Reliability

26 segment support on REP fast

This feature now supports 26 open segments and 13 closed segments. For information about REP Fast and its configuration, see REP Fast.

Ease of Use

Support for Meraki cloud management

The Cisco Catalyst IE9300 Rugged Series Switches support cloud management mode, enabling centralized control through the Meraki dashboard. This functionality supports migration from Cisco IOS XE to cloud management mode for streamlined monitoring and configuration.

New hardware features

This section provides a brief description of the new hardware features introduced in Cisco IOS XE Release 26.2.x.

IOS XE 26.2.1

There are no new hardware features in this release.

Change in behavior

WebHelp documentation discontinued

Starting with Cisco IOS XE Release 26.2.1, WebHelp documentation is not available for Industrial Ethernet switches. We recommend using the product documentation available on Cisco.com.

MRP uses the VLAN 1 MAC address

Starting with Cisco IOS XE Release 26.2.1, MRP uses the MAC address of the VLAN 1 interface to identify the best manager host.

Resolved issues

This section lists resolved issues in Cisco IOS XE Release 26.2.x.

Note: This software release may contain bug fixes first introduced in other releases. To see additional information, click the bug ID to access the Cisco Bug Search Tool.

IOS XE 26.2.1

Table 2.             Resolved issues in release 26.2.1

Bug ID

Description

CSCwt45804

The switch could experience a memory leak and restart unexpectedly when PTP was configured over an unsupported port-channel interface.

CSCwu25584

PTP timestamp retrieval could fail on a 10-Gigabit Ethernet port after a link flap.

CSCwt94316

Communication between translated addresses could fail when Layer 2 Network Address Translation (NAT) was configured.

CSCwu29126

IE9300 - ALT port failing to block traffic, causing network loops in REP ring.

CSCwt95175

A Cisco Catalyst Industrial Ethernet switch may appear as Device Unresponsive after it is added to the Cisco Catalyst Center inventory.

CSCwu78398

A powered device may be incorrectly reported as disconnected from a PoE interface.

CSCwt64311

Packet padding may not work correctly for VLAN-tagged traffic when PRP is enabled on Cisco Catalyst IE9300 or IE3500 Series switches.

Open issues

This section lists open issues in Cisco IOS XE Release 26.2.x.

Note: This software release may contain open bugs first identified in other releases. To see additional information, click the bug ID to access the Cisco Bug Search Tool.

IOS XE 26.2.1

Table 3.             Open issues in release 26.2.1

Bug ID

Description

CSCww30938

CRC errors may increase on1-Gbps links on Cisco Catalyst IE9320 switches.

Known issues

This section lists known issues in Cisco IOS XE Release 26.2.x.

IOS XE 26.2.1

There are no known issues in this release.

Compatibility

Refer to the Cisco IOS XE Migration Guide for IIoT Switches for the latest information about upgrading and downgrading switch software for Cisco Catalyst IE9300 Rugged Series Switches.

Supported hardware

This section lists supported hardware information.

This table lists the supported hardware models for Cisco Catalyst IE9300 Rugged Series Switches and the default license levels that they are delivered with.

Model Number

Default License Level

Stacking Support

Description

IE-9310-26S2C-A

Network Advantage

No

·       Total ports: 28

·       SFP uplinks: 4x 1 Gb SFP

·       SFP downlinks: 22x 100M/1000M SFP, 2x 100M/1000M dual-media

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9310-26S2C-E

Network Essentials

No

·       Total ports: 28

·       SFP uplinks: 4x 1 Gb SFP

·       SFP downlinks: 22x 100M/1000M SFP, 2x 100M/1000M dual-media

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9310-16P8S4X-E

Network Essentials

No

·       Total ports: 28

·       PoE+ ports: 16 ports 10/100/1000M

·       SFP downlinks: 8 ports 100/1000M

·       SFP uplinks: 4 ports 1/10G

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9310-16P8S4X-A

Network Advantage

No

·       Total ports: 28

·       PoE+ ports: 16 ports 10/100/1000M

·       SFP downlinks: 8 ports 100/1000M

·       SFP uplinks: 4 ports 1/10G

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-26S2C-A

Network Advantage

Yes

·       Total ports: 28

·       SFP uplinks: 4x 1 Gb SFP

·       SFP downlinks: 22x 100M/1000M SFP, 2x 100M/1000M dual-media

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-26S2C-E

Network Essentials

Yes

·       Total ports: 28

·       SFP uplinks: 4x 1 Gb SFP

·       SFP downlinks: 22x 100M/1000M SFP, 2x 100M/1000M dual-media

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-22S2C4X-A

Network Advantage

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP+

·       SFP downlinks:

·       22x 1 Gb SFP, 2x 1-Gb Dual-media ports

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-22S2C4X-E

Network Essentials

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP+

·       SFP downlinks:

·       22x 1 Gb SFP, 2x 1-Gb Dual-media ports

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-24T4X-A

Network Advantage

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP+

·       Copper downlinks: 24x 1 Gb RJ-45

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies.

IE-9320-24T4X-E

Network Essentials

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP+

·       Copper downlinks: 24x 1 Gb RJ-45

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies.

IE-9320-24P4X-A

Network Advantage

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP+

·       Copper downlinks: 24x 1 Gb RJ-45 PoE+

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-24P4X-E

Network Essentials

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP+

·       Copper downlinks: 24x 1 Gb RJ-45 PoE+

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-16P8U4X-A

Network Advantage

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP

·       Copper downlinks: 16 ports 1 Gb RJ-45 PoE+, 8 ports 2.5 Gb RJ-45 4PPoE (90W/port)

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-16P8U4X-E

Network Essentials

Yes

·       Total ports: 28

·       SFP uplinks: 4x 10 Gb SFP

·       Copper downlinks: 16 ports 1 Gb RJ-45 PoE+, 8 ports 2.5 Gb RJ-45 4PPoE (90W/port)

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-24P4S-A

Network Advantage

Yes

·       Total ports: 28

·       SFP uplinks: 4x 1Gb SFP

·       Copper downlinks: 24 ports 1 Gb RJ-45 PoE+

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

IE-9320-24P4S-E

Network Essentials

Yes

·       Total ports: 28

·       SFP uplinks: 4x 1Gb SFP

·       Copper downlinks: 24 ports 1 Gb RJ-45 PoE+

·       Power supplies: Support for field-replaceable, redundant AC or DC power supplies

Note: Documentation sometimes uses these terms:

●     IE9310 GE Fiber switch when referring to both IE-9310-26S2C-A and IE-9310-26S2C-E switches

●     IE9320 GE Fiber switch when referring to both IE-9320-26S2C-A and IE-9320-26S2C-E switches

●     IE9320 Fiber switch with 10 GE uplinks when referring to both IE-9320-22S2C4X-A and IE-9320-22S2C4X-E switches

●     IE9320 10 GE Copper Data switch when referring to both IE-9320-24T4X-A and IE-9320-24T4X-E switches

●     IE9320 10 GE PoE switch when referring to both IE-9320-24P4X-A and IE-9320-24P4X-E

●     IE9320 10 G mGig 4PPoE switch when referring to both IE-9320-16P8U4X-A and IE-9320-16P8U4X-E

●     IE9320 GE PoE switch when referring to both IE-9320-24P4S-A and IE-9320-24P4S-E

●     IE9310 GE mixed port when referring to both IE-9310-16P8S4X-A and IE-9310-16P8S4X-E switches.

Supported software packages

Finding the software version

●     The package files for Cisco IOS XE software can be found on the system board's internal flash memory device (flash:) or an external USB, depending on the platform configuration.

●     Use the show version privileged EXEC command to display the software version running on the switch. The model name displayed at the end of the output reflects the factory configuration and does not change after software license upgrades.

●     Use the dir <filesystem>: privileged EXEC command to view the names and versions of software images stored in flash memory.

Software images for Cisco IOS XE 26.2.x

This table provides the filename for the Cisco IOS XE Release 26.2.x software image for Cisco Catalyst IE9300 Rugged Series Switches.

Table 4.             Software packages for Cisco IOS XE Release 26.2.x

Release

Image type

Filename

Switch Models

Cisco IOS XE 26.2.1

 Universal

ie9k_iosxe.26.02.01.SPA.bin

Cisco Catalyst IE9300 Rugged Series Switches

To install and activate the specified file, and to commit the changes so that they persist across reloads, enter the command: install add file filename [activate commit]

This table lists the options for the install command for the Cisco Catalyst IE9300 Rugged Series Switches.

Table 5.             Summary of software installation commands for install mode

Command

Description

abort

Abort the current install operation.

activate

Activate an installed package.

add

Install a package file to the system.

auto-abort-timer

Install auto-abort-timer.

auto-upgrade

Initiate software auto-upgrade on all incompatible switches.

commit

Commit the changes to the load path.

deactivate

Deactivate an install package.

label

Add a label name to any installation point.

remove

Remove installed packages.

rollback

Roll back to a previous installation point.

Related resources

Table 6.             Additional references for Cisco IOS XE IE9300 Rugged Series Switches

Document

Description

Cisco IOS XE

Provides information about Cisco IOS XE.

Cisco Validated Designs

Provides information about Cisco Validated Designs.

Cisco MIB Locator

Provides tools for locating and downloading MIBs.

Cisco Profile Manager

Provides timely and relevant information from Cisco.

Cisco Services

Provides the business outcomes and technical support services needed to maximize the value of your Cisco technologies.

Cisco Support

You can submit a service request here.

Cisco DevNet

Enables you to discover secure, validated applications and integrations for Cisco networking platforms.

Cisco Press

Provides general networking, training, and certification titles.

Cisco Warranty Finder

Provides warranty information for a specific product or product family.

Cisco Community

You can ask and answer questions, share suggestions, and collaborate with your peers.

Cisco TAC

Provides the most up-to-date, detailed troubleshooting information. Go to Product Support and select your product from the list or enter the name of your product. Look under Troubleshoot and Alerts to find information for the problem that you are experiencing.

Cisco Feature Navigator

Provides platform support details and license level information for features.

Documentation Feedback

To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document.

Licenses

Provides information about the licensing packages for features.

Legal information

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)

Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.

© 2026 Cisco Systems, Inc. All rights reserved.

 

Learn more