Cisco 2 Tbps switching.24 ports of 25G.
2 Tbps switching.
24 ports of 25G.
One campus aggregation switch.
The C9300X-24Y-M packs 24x 1/10/25G SFP28 ports, modular uplinks, and up to 1 Tbps of stacking bandwidth into a fixed-config platform built for high-density campus core, aggregation, and Wi-Fi 6/6E backhaul.
Specifications at a glance
Core numbers for sizing the C9300X-24Y-M into a campus core, aggregation layer, or high-density access deployment.
What 24 ports of 25G actually delivers
Every fixed port on the C9300X-24Y-M runs at 1, 10, or 25 Gbps — no oversubscription tricks, no shared backplane guesswork.
= 2 Tbps fabric
Twenty-four wire-speed SFP28 ports plus a field-replaceable network module slot for 25G, 40G, or 100G uplinks — sized for aggregating dense Wi-Fi 6/6E access layers without a forklift upgrade.
Why the campus edge needs a switch like the C9300X-24Y-M
The campus edge doesn’t get a redesign — it gets replaced
Most campus networks don’t fail because of one bad switch. They fail slowly, as Wi-Fi 6E access points, video-heavy classrooms, and IoT sprawl quietly outgrow an aggregation layer that was sized for a different decade. The fix rarely gets budgeted until oversubscription turns into dropped packets during the exact moment everyone’s on a video call. The Cisco Catalyst 9300X-24Y-M exists to push that day out indefinitely — a fixed-configuration switch built with enough fabric and port speed headroom that the aggregation layer stops being the bottleneck.
It sits in Cisco’s Catalyst 9300X family, the higher-performance sibling to the standard 9300 line, built specifically for environments where 1G access ports are no longer the limiting factor and the aggregation and distribution layers need real 10/25G throughput to keep up.
Inside the C9300X-24Y-M
The hardware specifics are what make this a genuine aggregation-layer platform rather than a repackaged access switch. Twenty-four fixed SFP28 ports run at 1, 10, or 25 Gbps each, backed by a 2000 Gbps switching fabric and a 1488 Mpps forwarding rate — numbers that matter because they mean the switch isn’t relying on oversubscription to hit its advertised port count. Underneath sits Cisco’s UADP 2.0 Sec ASIC, which adds line-rate cryptographic acceleration, including hardware-based IPsec at up to 100G, without needing a separate security appliance in the path.
The control plane is built for the workloads modern network operating systems actually run: an x86 CPU complex with 16 GB of memory, 16 GB of onboard flash, and a USB 3.0 SSD slot that can add up to 240 GB of storage for hosting containerized applications directly on the switch. A separate USB 2.0 port is available purely for loading images and configurations, keeping day-one provisioning simple even before the switch touches a controller.
Built to scale: stacking and StackPower
Catalyst 9300X models support local stacking at up to 1 TBps of aggregate bandwidth, letting multiple physical units behave as a single logical switch with a shared control plane. That matters for both resiliency and operational simplicity — a stack fails over without an administrator needing to manually reroute traffic, and the entire group is managed, licensed, and upgraded as one entity rather than as separate boxes.
StackPower complements that by pooling and distributing power across stacked units through dedicated StackPower cabling, so a single power supply failure in one member doesn’t take that switch’s ports offline if the stack has power headroom to share. For wiring closets running mixed PoE and non-PoE gear, that redundancy is often the difference between a non-event and an emergency truck roll.
Security baked into silicon, not bolted on after
Because the UADP 2.0 Sec ASIC handles encryption in hardware, security features don’t come at the cost of throughput. The switch supports 802.1X authentication, Dynamic ARP Inspection, and role-based access control natively, alongside Cisco’s Adaptive Policy — a segmentation model that groups traffic using plain-language security groups like “IoT device” or “Guest” rather than sprawling IP-based access control lists. Policy intent (permit or deny) is then defined between groups once, and continues to apply correctly even as the underlying network topology changes. For network teams tired of rewriting ACLs every time a VLAN gets renumbered, that’s a meaningfully different operating model.
Two management personas, one piece of hardware
The same physical C9300X-24Y-M can run in either of two operating modes: traditional Cisco IOS XE, managed through the CLI, DNA Center, or existing network management tooling, or a Meraki-managed persona, where the switch is administered through the cloud-based Meraki dashboard as a Catalyst Meraki 9300X equivalent. Organizations aren’t locked into a management philosophy at time of purchase — a switch can migrate between personas later if operational preferences change, which reduces the risk of standardizing on the wrong platform early.
Uplink flexibility without a forklift upgrade
Rather than fixing uplink speed at time of manufacture, the Catalyst 9300X Series uses field-replaceable network modules for uplink ports, supporting 25G and 40G speeds today with a defined path to higher speeds later. That means a switch purchased for a 10G-to-25G migration doesn’t need to be replaced when the network eventually moves toward 100G — only the network module does. It’s the kind of design decision that quietly protects a hardware budget three or four years into a deployment.
Choosing the right license and support tier
The C9300X-24Y-M base hardware, as with the rest of the 9300/9300L/9300X family (excluding the Meraki MS390), is paired with a Catalyst 9300-M license structure offering Enterprise and Advanced feature tiers, available in 1, 3, 5, 7, or 10-year terms. Organizations already running other Catalyst 9300-M switches under a co-term licensing model should note that Meraki’s licensing generally requires an organization to standardize on one tier — Enterprise or Advanced — across its Catalyst 9300/L/X-M fleet rather than mixing tiers within the same org.
None of that needs to be finalized before requesting pricing. The base hardware SKU and the licensing/support tier are separate decisions, and a formal quote can walk through module, license, and power-supply options side by side once the target environment is known.
What the platform is built around
Adaptive Policy
Segment traffic into plain-language security groups instead of maintaining sprawling IP-based ACLs.
Dual Management Persona
Run as traditional IOS XE or migrate to a Meraki cloud-managed persona without swapping hardware.
StackPower + StackWise
Up to 1 TBps of stack bandwidth with pooled power redundancy across stacked members.
Modular Uplinks
Field-replaceable network modules protect the platform against future speed migrations.
Base hardware, uplink modules & licensing
The C9300X-24Y-M is the fixed-port base switch. These are commonly paired components and licensing options.
| Part Number / Item | Description | Type |
|---|---|---|
| C9300X-24Y-M | Base switch, 24× 1/10/25G SFP28, Meraki-managed persona capable | Hardware |
| C9300X-NM-8Y | 8-port 25G network module (uplink) | Module |
| C9300X-NM-4C | 4-port 40G/100G network module (uplink) | Module |
| C9300X-NM-2C | 2-port 40G module (100G with IOS-XE 17.15+) | Module |
| Catalyst 9300-M — Enterprise | Base feature license tier, 1/3/5/7/10-yr terms | License |
| Catalyst 9300-M — Advanced | Advanced feature license tier, 1/3/5/7/10-yr terms | License |
Request a Formal Quote
Catalyst 9300X hardware is configured to fit the environment — uplink modules, power supplies, and license tier all factor into final pricing. Send your requirements and a rep will follow up with a full Cisco Catalyst configuration and quote.
