Cisco remains the default in enterprise campus networking, and the questions we field about it are less about how the technology works than about how the commercial model works. That is where the money and the surprises live.
Disclosure: BlackHawk Data is a Cisco Premier Partner. Licensing programs and naming change regularly; verify specifics against current Cisco documentation before purchase.
1. Catalyst or Meraki?
Catalyst when you need depth and control. Meraki when you need simplicity and scale of sites.
Catalyst gives you full IOS-XE — the complete feature set, CLI access, deep routing, granular control and the ability to do unusual things. It suits large campuses, complex routing, regulated environments and organizations with network engineering staff.
Meraki gives you cloud management, fast deployment and an interface a generalist can operate. It suits distributed estates with many small sites, lean IT teams and organizations that value time-to-deploy over configuration depth.
Two commercial differences matter more than the feature comparison: Meraki licensing is co-terminated and all-or-nothing, and Meraki hardware stops functioning when its licence lapses. Catalyst hardware keeps switching packets regardless of subscription state. That distinction should be explicit in any risk conversation about either platform.
Many estates run both — Catalyst in the core and large campuses, Meraki in branches. That is a legitimate design, not a compromise.
2. Network Essentials vs. Network Advantage — what is the actual difference?
These are IOS-XE feature tiers, tied to the hardware.
Essentials covers standard enterprise switching: Layer 2, basic Layer 3 with static routing and RIP, QoS, standard security and telemetry. It is sufficient for the majority of access-layer deployments.
Advantage adds full dynamic routing (OSPF, EIGRP, BGP), VXLAN/EVPN, SD-Access fabric capability, advanced multicast, MPLS features and richer automation and assurance hooks.
The rule of thumb: access layer runs Essentials unless something specific requires more; distribution and core run Advantage. Buying Advantage estate-wide because it is simpler to order is one of the most common sources of avoidable spend we find in an audit.
3. What is Catalyst Center and do I need it?
Catalyst Center — previously DNA Center — is Cisco's on-premises management, automation and assurance platform: network-wide provisioning, policy, telemetry-driven assurance, software image management and the control plane for SD-Access.
You need it if you are deploying SD-Access, if you have enough devices that image and configuration consistency is a real operational problem, or if assurance analytics would materially change how your team troubleshoots.
You do not need it for a small estate with stable configurations. It is an appliance with its own lifecycle, upgrade path and operational learning curve, and it is frequently bought as part of a bundle and then never fully deployed. If that describes your environment, the licences are still being paid for.
4. What happens when the subscription expires?
The switch keeps switching. Unlike Meraki, Catalyst hardware does not stop forwarding when the subscription layer (historically DNA, now sold under Cisco's networking subscription naming) lapses.
What you lose is the entitlement to the management and automation capability those subscriptions unlock — Catalyst Center functionality, assurance, and in some cases the right to run software features you are currently using. There is also a renewal consideration: allowing subscriptions to lapse entirely and repurchasing later is generally more expensive than continuous renewal.
Treat the subscription as an operational entitlement with a hard date, not as a nice-to-have.
5. Why does my switch say it is out of compliance?
Because of Smart Licensing Using Policy, and the message is usually less alarming than it sounds.
Modern IOS-XE releases use an honour-based model: the device runs the features you configure and reports usage to your Smart Account, either directly, via a Smart Licensing Utility on-premises, or through offline file exchange. There is no enforcement gate that blocks the feature.
An out-of-compliance state normally means one of three things: usage has not been reported within the policy window, the reported usage exceeds the licences in the Smart Account, or the device has no path to report at all. In air-gapped environments, offline reporting is the intended answer and should be scheduled rather than improvised.
The operational risk is not the switch stopping. It is discovering at true-up that consumption exceeded entitlement across the estate.
6. What does SmartNet cost, and which tier do I need?
Support commonly runs from roughly 8% of list price per year at entry tiers to over 20% at premium tiers with fast replacement and onsite service. Compounded across a five-to-seven-year life, support frequently accounts for 50–80% of an asset's total cost of ownership — more than the hardware.
Tier by role, not by policy:
| Device role | Typical appropriate tier |
|---|---|
| Access switch, stacked, with spares on shelf | 8x5xNBD |
| Distribution / core | 24x7x4 |
| Single points of failure, remote sites without spares | 24x7x2 or onsite |
Most organizations over-buy at the access layer and under-buy at the core. A stack with redundant members and a cold spare does not need four-hour replacement; a single core switch three hours from your nearest engineer does.
7. What do the end-of-life milestones actually mean?
Cisco publishes a sequence, and each milestone changes what your support contract buys:
| Milestone | What changes |
|---|---|
| End of Sale | No longer orderable; spares market only |
| End of Software Maintenance | No new features; platform frozen |
| End of Routine Failure Analysis | Only critical fixes remain |
| End of Vulnerability/Security Support | No further security patches |
| Last Day of Support | No TAC, no RMA |
The date that belongs in your capital plan is End of Vulnerability/Security Support, not Last Day of Support. Running switches that will never receive another security fix is a risk acceptance, and in regulated environments it is an audit finding. The gap between those two milestones is where organizations get caught, because a device can be "supported" and unpatchable at the same time.
8. How long do switches actually last, and when should I refresh?
Physically, seven to ten years or more. In practice enterprises refresh every five to seven years, and the trigger is support expiry and capacity — not failure.
Plan the refresh from published EoL dates for the exact models you own, not from a general assumption. Pull that list now for your installed base; it is the single most useful hour of capital planning you will do this year.
9. Is an Enterprise Agreement worth it?
Sometimes. An EA can simplify administration, provide portability across the estate and give predictable annual cost. It can also lock in spend against consumption that never materializes.
Evaluate honestly: model your actual device count and licence tier requirements over the term, compare against EA cost including the growth assumptions built into it, and ask what happens at renewal if your estate shrinks. EAs reward growing estates and penalize flat or shrinking ones. Also model a double-digit percentage increase at renewal — recent renewal cycles have made that the prudent assumption rather than the pessimistic one.
10. StackWise or modular chassis?
Stacking for access, chassis for core remains the right default.
Stacking gives you a single management point, shared uplinks and member redundancy at low cost, and it scales by adding units. A chassis gives you redundant supervisors, redundant power, higher backplane capacity and in-service software upgrade, at a price that only makes sense where an outage is genuinely unacceptable.
The most common design error is a stack at the core with all members in one rack fed by one power path. That is a single point of failure wearing redundancy branding.
11. Catalyst 9800 or Meraki for wireless?
Catalyst 9800 wireless controllers — physical, virtual or cloud-hosted — give you full control, advanced RF tuning, deep troubleshooting and integration with Catalyst Center and SD-Access. Meraki wireless gives you cloud management, quick deployment and adequate RF for most environments.
The dividing line is density and complexity. High-density environments — lecture halls, arenas, terminals, manufacturing floors with RF-hostile physics — benefit materially from the tuning depth of the 9800. Standard office and retail coverage generally does not.
12. How do I avoid renewal shock?
Four practices, and none of them are exotic:
- Maintain a licence and contract register with every expiry date, owner and renewal value, reviewed quarterly. Most organizations do not have one.
- Right-size at every renewal. Re-examine tier by device rather than repeating last term's order. Estates accumulate Advantage licences on access switches that never needed them.
- Start renewal conversations at 120 days, not at 30. Leverage requires time.
- Budget for increases. Assume list and renewal pricing rises during the term, because it consistently has.
If you want an independent read on a Cisco estate — licence posture, EoL exposure, support-tier fit and whether the design still matches the requirement — our architecture review and network health check cover exactly that. We also compared seven-year lifecycle costs across Cisco, Fortinet, HPE Aruba and Arista in this breakdown. Practice detail is at /solutions/networking.