Release Notes for Cisco IE3500 Series Switches, Release 26.2.x

Available Languages

Download Options

  • PDF
    (342.7 KB)
    View with Adobe Reader on a variety of devices
Updated:September 28, 2026

Bias-Free Language

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Available Languages

Download Options

  • PDF
    (342.7 KB)
    View with Adobe Reader on a variety of devices
Updated:September 28, 2026
 

                                               

Cisco IE3500 Series Switches, Release 26.2.x. 3

New software features. 3

New hardware features. 5

Change in behavior 5

Resolved issues. 6

Open issues. 6

Known issues. 7

Supported hardware. 7

Supported software packages. 9

Related resources. 10

Legal information. 11

 

 

Cisco IE3500 Series Switches, Release 26.2.x

This document provides Cisco IOS XE release information for the Cisco Industrial Ethernet (IE) switches.

Cisco IE3500/IE3505 Series Switches

Cisco IE3500 and IE3505 Series Switches are rugged switching platforms that provide high bandwidth and a high PoE power budget with Cisco IOS XE Software for industrial environments. These switches are designed to operate in harsh conditions, including temperatures from -40°C to +75°C (–40°F to 167°F), and can withstand severe shock and vibration.

These switches are designed for hardened deployments such as factory automation, smart cities, energy and process control, Intelligent Transportation Systems (ITS), energy production sites, and mining. They also provide improved scale, built-in security features, and simplified management. For more information, see the data sheet.

Cisco IE3500H/IE3505H Series Switches

Cisco IE3500H and IE3505H Series Switches are the next-generation managed IP67 switches powered by Cisco IOS XE. They are designed for deployment in harsh environments and are IP67-rated for water and dust resistance. These switches also operate in temperatures from -40°C to +75°C (-40°F to 167°F) and are built to withstand severe shock and vibration.

These switches are available with up to 24 ports. Fast Ethernet is supported through Fast Ethernet PIDs, and 1G PIDs can also operate at 100 Mbps. For a list of supported SFPs, see the data sheet. These switches can be wall-mounted and deployed without a housing cabinet. They offer a power budget of 240 W and support Power over Ethernet (PoE), PoE+, and Universal Power over Ethernet (UPoE) at 60 W.

These switches provide advanced security, segmentation, and visibility for demanding industrial IoT edge deployments such as mining, rail, and manufacturing. For more information, see the data sheet.

New software features

This section provides a brief description of the new software features introduced in Cisco IOS XE Release 26.2.x.

IOS XE 26.2.1

Table 1.        New software features in release 26.2.1

Product Impact

Feature

Description

Security

Resilient Infrastructure

As part of Cisco’s Resilient Infrastructure program and Cisco’s commitment to secure infrastructure, this release includes additional changes aimed towards continuing to make Cisco IOS XE more secure by default. Note that some of these changes may require operational changes if you are not following secure best practices. This release includes the following changes:

●  The RADIUS client appends the Message-Authenticator attribute (Attribute 80 HMAC-MD5) to all outgoing Access-Request packets to mitigate cryptographic forgery and  Blast-RADIUS vulnerabilities (CVE-2024-3596).
●  The RADIUS client drops incoming Access-Accept, Access-Reject, and Access-Challenge packets if the Message-Authenticator is absent or invalid. Ensure AAA servers (example, Cisco ISE) are configured to return Attribute 80.
●  Outbound SSH connections enforce Trust-On-First-Use (TOFU). The device prompts to verify and store remote server host keys in the known-hosts database on first connection and validates against them on subsequent sessions.
●  Proxy ARP is disabled by default across all routed interfaces, SVIs, and subinterfaces to reduce Layer 2 broadcast domains and prevent ARP spoofing. Configure the  ip proxy-arp command explicitly if required.
●  The embedded web server daemon is disabled by default on factory configurations to restrict unauthenticated management access. Web UI and RESTCONF require explicit enablement of the  ip http secure-server command.
●  The IOS XE device rejects unauthenticated NTP Mode 6 and Mode 7 control queries (monlist) to prevent NTP reflection and amplification DDoS attacks. Standard time synchronization (Modes 3 and 4) is unaffected.
●  System logging timestamps automatically include the four-digit calendar year (service timestamps log datetime msec year) to standardize multi-year audit logs and SIEM compliance.
●  Integrates Linux auditd inside Cisco IOx Guest Shell. All commands, system calls, and privilege escalation events (sudo) executed inside the container are forwarded to the host syslog facility.
●  Warning messages are emitted on the console and logged to syslog whenever legacy insecure protocols (telnet, ftp, tftp, http) are enabled in the configuration.
●  Real-time tracking of active insecure services is published to the operational database (operDB) and YANG data models, allowing management controllers (such as Cisco Catalyst Center) to monitor security compliance.

Upgrade

CIP password encryption

This feature provides enhanced security by converting legacy CIP passwords to the irreversible Type 8 (SHA-256) algorithm to resist cryptographic attacks. It ensures credential integrity and uninterrupted authentication across industrial deployments.

Software Reliability

EVPN Multihoming All-Active Mode

EVPN multihoming all-active mode provides non-blocking Layer 2 connectivity by enabling traffic load balancing across redundant links. It improves network resiliency and utilization while maintaining continuous connectivity during link or device failures.

Security

HTTPS Servers Disabled by Default Except for Express Setup

Starting with Cisco IOS XE 26.2.1, HTTPS servers remain disabled by default, excluding express setup deployments which retain existing settings.

Enhanced Reliability

FlexLink+

FlexLink+ provides Layer 2 link redundancy without using STP. It supports active-standby failover on physical interfaces and EtherChannel bundles. VLAN load balancing lets both links forward traffic for different VLANs. After a failed link recovers, the preferred VLAN forwarding can be restored manually or automatically after a configured delay.

Security

Post Quantum Cryptography for MACsec with EAP-TLS

Cisco Industrial Ethernet switches can use ML-KEM-based key exchange with EAP-TLS 1.3 to provide quantum-resistant key establishment for MACsec connections. EAP-TLS derives keying material that MKA uses to establish secure MACsec communication between switches.

Security

Post Quantum Cryptography for SSHv2 Sessions

Cisco Industrial Ethernet switches can combine ML-KEM with traditional key-exchange algorithms to secure SSHv2 sessions. This hybrid approach provides quantum-resistant key establishment for secure remote management while retaining protection against classical attacks.

Security

PROFINET Netload-3 Robustness

This feature increases resilience to abnormal network traffic. It detects unexpected PROFINET Real-Time traffic, invokes Layer 2 source blocking, and rate-limits incoming Layer 3 traffic directed to the PROFINET VLAN IP address.

Enhanced Reliability

PTP over DLR

This feature maintains millisecond-level timing across Device Level Ring networks during link failures by preventing PTP re-convergence delays. Supporting multiple-VLAN transparent clock across up to three rings with 50 nodes each, you achieve continuous synchronization for time-sensitive automation in EtherNet/IP and CIP-based industrial deployments.

PTP over REP

This feature combines Precision Time Protocol with Resilient Ethernet Protocol to maintain millisecond-level time synchronization during network failures with <200 ms failover, eliminating PTP re-convergence delays that disrupt industrial applications.

PTP over HSR

This release introduces Precision Time Protocol (PTP) over High-availability Seamless Redundancy (HSR), enabling millisecond-level time synchronization with zero network downtime. This feature ensures continuous PTP operation during network failures, eliminating the 4-10 second re-convergence delays that disrupt time-sensitive industrial applications. PTP over HSR supports Power Profile with Boundary Clock and P2P Transparent Clock modes for up to 50 nodes per HSR ring.

Enhanced Reliability

12-Ring Support on Fast MRP

This feature expands Fast MRP support on IE3500 from 3 to 12 rings with 30 ms convergence and up to 50 nodes per ring. It enables you to build larger, more scalable industrial networks with near-zero downtime during failures, reducing infrastructure costs while maintaining continuous operation of critical manufacturing and automation systems.

Enhanced Reliability

26 Segment Support on REP Fast

This feature now supports 26 open segments and 13 closed segments. For details on REP Fast information and its configuration, refer to REP Fast.

New hardware features

This section provides a brief description of the new hardware features introduced in Cisco IOS XE Release 26.2.x.

IOS XE 26.2.1

There are no new hardware features in this release.

Change in behavior

WebHelp documentation discontinued

Starting with Cisco IOS XE Release 26.2.1, WebHelp documentation is not available for Industrial Ethernet switches. We recommend using the product documentation available on Cisco.com.

MRP uses the VLAN 1 MAC address

Starting with IOS XE Release 26.2.1, MRP uses the MAC address of the VLAN 1 interface to identify the best manager host.

Meraki mode changes to cloud management mode

Starting with Cisco IOS XE Release 26.2.1, Meraki mode is renamed to cloud management mode (also known as cloud-mgmt). Use cloud management mode to manage the device through the Meraki cloud.

Migration from Meraki mode (also known as cloud-mgmt mode) to Catalyst mode

Starting with Cisco IOS XE Release 26.2.1, the Cisco Catalyst IE3500 switches support migrating a device from Meraki mode to Catalyst mode. This option changes the device mode to Catalyst mode.

Resolved issues

This section lists resolved issues in Cisco IOS XE Release 26.2.x.

Note: This software release may contain bug fixes first introduced in other releases. To see additional information, click the bug ID in Cisco Bug Search Tool.

IOS XE 26.2.1

Table 2.        Resolved issues in release 26.2.1

Bug ID

 Description

CSCwt45045

Triggering a contact alarm could generate both assertion and clearing syslog messages even when the contact was closed and the alarm remained deasserted.

CSCwt94316

Communication between translated addresses could fail when Layer 2 Network Address Translation (NAT) was configured.

CSCwt95175

A Cisco Catalyst Industrial Ethernet switch may appear as Device Unresponsive after it is added to the Cisco Catalyst Center inventory.

CSCwt94165

A peer device may report input errors and fail to process packets received from a Cisco Catalyst IE3500 switch.

CSCwt56767

The serial number displayed in the software may not match the serial number printed on the physical device.

Open issues

This section lists open issues in Cisco IOS XE Release 26.2.x.

Note: This Cisco IOS XE software release may contain open bugs first identified in other releases. To see additional information, click the bug ID in Cisco Bug Search Tool.

IOS XE 26.2.1

Table 3.        Open issues in release 26.2.1

Bug ID

 Description

CSCwv57930

 IE3505 DLR: Inconsistent convergence times observed following a power-cycle event.

CSCwv83174

IE3505 DLR access ring: Multicast traffic experiences convergence delays of up to 300 ms following a device power-off event.

CSCwv87192

IE3505 DLR trunk ring: Multicast traffic experiences convergence delays of 700 to 1000 ms following a device power-off event.

 

Known issues

This section lists known issues in Cisco IOS XE Release 26.2.x.

IOS XE 26.2.1

There are no known issues in this release.

Supported hardware

This section lists supported hardware information.

Table 4.        Supported IE3500 SKUs

PID

Uplink Ports

Downlink Ports

Type

Ports

Interface name

Type

Ports

Interface name

IE-3500-8T3S

SFP/SFP+

3

Gigabit Ethernet 1/1-3

Copper

8

Gigabit Ethernet 1/4-11

IE-3500-8P3S

IE-3505-8T3S

IE-3505-8P3S

IE-3500-8U3X

TenGigabit Ethernet 1/1-3

IE-3500-8T3X

Table 5.        Supported IE3500H SKUs

System

PIDs

SW

Uplinks

Downlinks

Data Path FPGA

PoE

Alternate PIDs (TAA and COO)

All Gig Copper

IE-3500H-8T

Network Essentials or Network Advantage

4x1G Copper

4x1G Copper

No

No

none

IE-3500H-16T

12x1G Copper

none

IE-3500H-24T

20x1G Copper

 none

Mixed Gig/GE Copper

 

 

 

 

 

IE-3500H-12FT4T

12xFE Copper

No

No

none

IE-3500H-20FT4T

20xFE Copper

Advanced Copper

 

 

IE-3505H-16T

12x1G Copper

Yes

No

none

PoE

IE-3500H-14P2T

2x1G Copper

14x1G Copper

No

Yes

none

IE-3500H-12P2MU2X

2x10G SFP

12x1G PoE and 2 x mGig/4PPoE

Supported expansion modules

Table 6.        Supported expansion modules

PID

Downlink Ports

Type

Ports

Interface name

IEM-3500-16P

Copper RJ-45

16 PoE

Gigabit Ethernet 2/1-16

IEM-3500-16T

16

Gigabit Ethernet 2/1-16

IEM-3500-8P

8 PoE

Gigabit Ethernet 2/1-8

IEM-3500-8T

8

Gigabit Ethernet 2/1-8

IEM-3500-4MU

4 PoE

Gigabit Ethernet 2/1-4

IEM-3500-8S

SFP

8

Gigabit Ethernet 2/1-8

IEM-3500-14T2S

 

 

Copper RJ-45/ SFP

Copper RJ-45: 14

SFP: 2

Gigabit Ethernet 2/1-16

IEM-3500-6T2S

Copper RJ-45: 6

SFP: 2

Gigabit Ethernet 2/1-8

Web UI system requirements

The Web UI is a web browser-based switch management tool that runs on the switch.

Minimum hardware requirements

Table 7.        Minimum hardware requirements

Processor Speed

DRAM

Number of colors

Resolution

233 MHz minimum

1 GHz recommended

512 MB

1 GB recommended

256

1280 x 800 or higher

Operating systems

●     Windows 10 or later

●     macOS 10.9.5 or later

Browsers

●     Google Chrome: Version 59 or later (On Windows and Mac)

●     Microsoft Edge

●     Mozilla Firefox: Version 54 or later (On Windows and Mac)

●     Safari: Version 10 or later (On Mac)

Supported software packages

Finding the software version

●     The package files for Cisco IOS XE software can be found on the system board's internal flash memory device (flash:) or an external USB, depending on the platform configuration.

●     Use the show version privileged EXEC command to display the software version running on the switch. The model name displayed at the end of the output reflects the factory configuration and does not change after software license upgrades.

●     Use the dir filesystem: privileged EXEC command to view the names and versions of software images stored in flash memory.

Software images for Cisco IOS XE 26.2.x

This table provides the file names for the Cisco IOS XE 26.2.x software images for Cisco IE3500 Series Switches.

Table 8.        Software package for release 26.2.x

Release

Image Type

Platform

File Name

Cisco IOS XE 26.2.1

Universal

IE3500, IE3505, IE3500H and IE3505H

ie35xx-universalk9.26.02.01.SPA.bin

Automatic boot loader upgrade

When you upgrade from the existing Cisco IOS XE release on your switch to a later or newer Cisco IOS XE release for the first time, the boot loader may be automatically upgraded based on the hardware version of the switch. If a boot loader upgrade occurs, it takes effect on the next reload.

For later Cisco IOS XE releases, if a new boot loader is included, it may also be automatically upgraded when the new image is booted for the first time.

Caution: Do not power cycle your switch during the upgrade.

Software installation commands

To install the software successfully, Cisco recommends having free space in flash equal to at least twice the image size. If insufficient space is available, remove inactive packages with the install remove inactive command or manually delete unnecessary files such as old core files or any other files that occupy a large amount of space in flash.

To install and activate the specified file, and to make the changes persistent across reloads, use the install add file filename [activate commit] command.

Table 9.        Summary of software installation commands for install mode

Command

Description

add file tftp: filename

Copies the install file package from a remote location to the device and performs a compatibility check for the platform and image versions.

activate [auto-abort-timer]

Activates the file and reloads the device. The auto-abort-timer keyword automatically rolls back image activation.

commit

Makes changes persistent over reloads.

remove

Deletes all unused and inactive software installation files.

Related resources

Table 10.      Additional references for Cisco IE3500 Rugged and IE3500 Heavy Duty Series Switches

Document

Description

 Cisco IOS XE

Provides information about Cisco IOS XE.

Cisco Warranty Finder

Provides warranty information for a specific product or product family.

Cisco IE3500 Rugged Series Switches

Provides information about Cisco IE3500 Rugged Series Switches.

Cisco IE3500 Heavy Duty Series Switches

Provides information about Cisco IE3500 Heavy Duty Series Switches.

Cisco Validated Designs

Provides information about Cisco Validated Designs.

Cisco Profile Manager

Provides timely and relevant information from Cisco.

Cisco Services

Provides the business outcomes and technical support services needed to maximize the value of your Cisco technologies.

Cisco Support

You can submit a service request here.

Cisco DevNet

Enables you to discover and browse secure, validated, enterprise-class applications, products, solutions, and services.

Cisco Press

Provides general networking, training, and certification titles.

Cisco Community

You can ask and answer questions, share suggestions, and collaborate with your peers.

Cisco TAC

Provides the most up-to-date, detailed troubleshooting information. Go to Product Support and select your product from the list or enter the name of your product. Look under Troubleshoot and Alerts to find information for the problem that you are experiencing.

Documentation Feedback

To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document.

Legal information

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html
Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)

Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.

© 2026 Cisco Systems, Inc. All rights reserved.

 

Learn more