The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Feedback
Cisco Catalyst ESS9300 Embedded Series Switches, Release 26.2.x
Cisco Catalyst ESS9300 Embedded Series Switches, Release 26.2.x
This document provides release information for the Cisco Catalyst ESS9300 Embedded Series Switch. It is a small-form-factor, ruggedized 10-Gigabit Ethernet embedded platform for tactical, outdoor, and mobile environments. The compact design simplifies integration and offers the system integrator the ability to use the Cisco Catalyst ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switch in a wide range of applications. It consists of one switch card. Cooling plates are not included. The system integrator must provide an appropriate thermal solution. The switch has a typical power consumption of 35 W.
This section provides a brief description of the new software features introduced in the Cisco IOS XE Release 26.2.x.
IOS XE 26.2.1
Table 1. New software features release 26.2.1
| Product Impact |
Feature |
Description |
| Security |
As part of Cisco’s Resilient Infrastructure program and Cisco’s commitment to secure infrastructure, this release includes additional changes aimed towards continuing to make Cisco IOS XE more secure by default. Note that some of these changes may require operational changes if you are not following secure best practices. This release includes the following changes:
● The RADIUS client appends the Message-Authenticator attribute (Attribute 80 HMAC-MD5) to all outgoing Access-Request packets to mitigate cryptographic forgery and
Blast-RADIUS vulnerabilities (CVE-2024-3596).
● The RADIUS client drops incoming Access-Accept, Access-Reject, and Access-Challenge packets if the Message-Authenticator is absent or invalid. Ensure AAA servers (example, Cisco ISE) are configured to return Attribute 80.
● Outbound SSH connections enforce Trust-On-First-Use (TOFU). The device prompts to verify and store remote server host keys in the known-hosts database on first connection and validates against them on subsequent sessions.
● Proxy ARP is disabled by default across all routed interfaces, SVIs, and subinterfaces to reduce Layer 2 broadcast domains and prevent ARP spoofing. Configure the ip proxy-arp command explicitly if required.
● The embedded web server daemon is disabled by default on factory configurations to restrict unauthenticated management access. Web UI and RESTCONF require explicit enablement of the ip http secure-server command.
● The IOS XE device rejects unauthenticated NTP Mode 6 and Mode 7 control queries (monlist) to prevent NTP reflection and amplification DDoS attacks. Standard time synchronization (Modes 3 and 4) is unaffected.
● System logging timestamps automatically include the four-digit calendar year (service timestamps log datetime msec year) to standardize multi-year audit logs and SIEM compliance.
● Integrates Linux auditd inside Cisco IOx Guest Shell. All commands, system calls, and privilege escalation events (sudo) executed inside the container are forwarded to the host syslog facility.
● Warning messages are emitted on the console and logged to syslog whenever legacy insecure protocols (telnet, ftp, tftp, http) are enabled in the configuration.
● Real-time tracking of active insecure services is published to the operational database (operDB) and YANG data models, allowing management controllers (such as Cisco Catalyst Center) to monitor security compliance.
|
|
| Security |
HTTPS servers disabled by default except for express setup |
Starting with Cisco IOS XE Release 26.2.1, HTTPS servers remain disabled by default, excluding express setup deployments which retain existing settings. |
| Upgrade |
This feature combines Precision Time Protocol with Resilient Ethernet Protocol to maintain millisecond-level time synchronization during network failures with <200 ms failover, eliminating PTP re-convergence delays that disrupt industrial applications. |
This section provides a brief description of the new hardware features introduced in Cisco IOS XE Release 26.2.x.
IOS XE 26.2.1
There are no new hardware features in this Cisco IOS XE Release 26.2.1.
WebHelp documentation discontinued
Starting with Cisco IOS XE Release 26.2.1, WebHelp documentation is not available for Industrial Ethernet switches. We recommend using the product documentation available on Cisco.com.
This section lists resolved issues in Cisco IOS XE Release 26.2.x.
Note: This software release may contain bug fixes first introduced in other releases. To see additional information, click the bug ID in Cisco Bug Search Tool.
IOS XE 26.2.1
Table 2. Resolved issues in release 26.2.1
| Description |
|
| The switch could experience a memory leak and restart unexpectedly when PTP was configured over an unsupported port-channel interface. |
|
| PTP timestamp retrieval could fail on a 10-Gigabit Ethernet port after a link flap. |
|
| A Cisco Catalyst Industrial Ethernet switch may appear as Device Unresponsive after it is added to the Cisco Catalyst Center inventory. |
|
| An alternate port may fail to block traffic, potentially causing a network loop in a REP ring on Cisco Catalyst IE9300 Series switches. |
This section lists the open issues in Cisco IOS XE Release 26.2.x.
Note: This software release may contain open bugs first identified in other releases. To see additional information, click the bug ID to access the Cisco Bug Search Tool.
IOS XE 26.2.1
Table 3. Open issues in release 26.2.1
| Bug ID |
Description |
| CRC errors may increase on1-Gbps links on Cisco Catalyst IE9320 switches. |
This section lists known issues in Cisco IOS XE Release 26.2.x
IOS XE 26.2.1
SSH algorithms for common criteria certification limitation
Starting from Cisco IOS XE Release 17.10, the following key exchange and MAC algorithms are removed from the default list:
● Key exchange algorithm:
◦ diffie-hellman-group14-sha1
● MAC algorithms:
◦ hmac-sha1
◦ hmac-sha2-256
◦ hmac-sha2-512
Note: Use the ip ssh server algorithm kex command to configure the key exchange algorithm and the ip ssh server algorithm mac command to configure the MAC algorithms.
Table 4. Hardware feature mapping between Cisco ESS 9300-10X-E and Cisco ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623:
| Category |
Feature |
Cisco ESS-9300-10X-E |
Cisco ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 |
| Hardware |
Single board |
Yes |
Yes |
| Small form-factor with mezzanine card |
Supported with 4.595 in.(H) x 2.904 in.(W) |
Supported with 5.1 in.(H) x 2.9 in.(W) |
|
| Ethernet management port |
Optional |
Not supported |
|
| Optical ports |
10X10 GE optical ports with Enhanced Small Form-Factor Pluggable (SFP+). |
· 8x10GE interfaces. By default, 2x10GE interfaces are configured in backplane mode and 6x10GE interfaces in the optical mode. · 10X1 GE Copper ports |
|
| RS-232 console |
Supported |
Supported |
|
| USB console |
Supported |
Not supported |
|
| Common +3.3VDC and +5VDC power inputs |
Supported |
Supported |
|
| Low power—35 W (typical) |
Supported |
Supported |
|
| ARM Quad-Core A53 |
Supported |
Supported |
|
| Alarms |
· Two—input · One— output |
· Four—input · One— output |
|
| 4 GB of DDR4 DRAM with ECC |
Supported |
Supported |
|
| Eight GB onboard eMMC flash storage (2.5 GB usable space). |
Supported |
Supported |
|
| Input/Output |
· SD card slot · Power input · RJ-45 (RS-232) console · Micro-USB console · USB-A host port |
· Power input · RJ-45 (RS-232) console · USB-A host port |
|
| Software |
IOS XE, Network Essentials and Network Advantage |
Supported |
Supported |
| Industrial temperature |
-40°C to +85°C |
Supported |
Supported |
Refer to Cisco IOS XE Migration Guide for IIoT Switches for the latest information about upgrading and downgrading switch software for Cisco Catalyst ESS9300 Series Switches.
Finding the software version
● The package files for Cisco IOS XE software can be found on the system board's internal flash memory device (flash:) or an external USB, depending on the platform configuration.
● Use the show version privileged EXEC command to display the software version running on the switch. The model name displayed at the end of the output reflects the factory configuration and does not change after software license upgrades.
● Use the dir <filesystem>: privileged EXEC command to view the names and versions of software images stored in flash memory.
Software images for Cisco IOS XE 26.2.x
This table provides the filename for the IOS XE 26.2.x software image for Cisco Catalyst ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switches.
Table 5. Software package for release 26.2.x
| Release |
Image Type |
Filename |
Switch Models |
| Universal |
ie9k_iosxe.26.02.01.SPA.bin |
Cisco Catalyst ESS-9300-10X-E Cisco Catalyst ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switches |
Software installation options
This table lists the options for the install command for the Cisco Catalyst ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switch.
To install and activate the specified file, and to commit changes to be persistent across reloads, enter the following command: install add file filename [activate commit].
Table 6. Summary of software installation commands for install mode
| Option |
Description |
| abort |
Abort the current install operation. |
| activate |
Activate an installed package. |
| add |
Install a package file to the system. |
| auto-abort-timer |
Install auto-abort-timer. |
| autoupgrade |
Initiate software auto-upgrade on all incompatible switches. |
| commit |
Commit the changes to the load path. |
| deactivate |
Deactivate an install package. |
| label |
Add a label name to any installation point. |
| remove |
Remove installed packages. |
| rollback |
Rollback to a previous installation point. |
Table 7. Additional references for Cisco Catalyst ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switches
| Document |
Description |
| Provides information about Cisco IOS XE |
|
| Cisco Catalyst ESS9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switches |
Provides information about Cisco Catalyst ESS-9300-8X16T-W-A of the Curtiss-Wright VPX3-623 Embedded Series Switches |
| Provides information about Cisco Validated Designs. |
|
| Provides tools for locating and downloading MIBs. |
|
| Provides timely and relevant information from Cisco. |
|
| Provides the business outcomes and technical support services needed to maximize the value of your Cisco technologies. |
|
| You can submit a service request here. |
|
| Enables you to discover and browse secure, validated, enterprise-class applications, products, solutions, and services. |
|
| Provides general networking, training, and certification titles. |
|
| Provides warranty information for a specific product or product family. |
|
| You can ask and answer questions, share suggestions, and collaborate with your peers. |
|
| Provides the most up-to-date, detailed troubleshooting information. Go to Product Support and select your product from the list or enter the name of your product. Look under Troubleshoot and Alerts, to find information for the problem that you are experiencing. |
|
| Provides platform support details and license level information for features. Cisco Feature Navigator also provides access to MIB Locator. |
|
| Documentation Feedback |
To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document. |
Licensing
For information about the licensing packages for features available on Cisco Catalyst ESS9300 Embedded Series Switch, see Licensing on the Cisco Catalyst IE9300 Series Switches.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/go/trademarks.
Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.
© 2026 Cisco Systems, Inc. All rights reserved.