Cisco Catalyst 9800-40 Wireless Controller
Cisco Catalyst 9800-40 Wireless Controller
Cisco public
D
Figure 1.
Cisco Catalyst 9800-40 Wireless Controller
Built from the ground-up for intent-based networking and Cisco DNA, Cisco Catalyst 9800 Series Wireless
Controllers are Cisco IOS XE based and integrate the RF excellence of Cisco Aironet access points, creating a
best-in-class wireless experience for your evolving and growing organization. The 9800 Series is built on an
open and programmable architecture with built-in security, streaming telemetry, and rich analytics.
The Cisco Catalyst 9800 Series Wireless Controllers are built on the three pillars of network excellence— always
on, secure, and deployed anywhere—which strengthen the network by providing the best wireless experience
without compromise, while saving time and money.
The Cisco Catalyst 9800-40 is a fixed wireless controller with seamless software updates for midsize and large
enterprises. It is feature rich and enterprise ready to power your business-critical operations and transform
end-customer experiences:
● High availability and seamless software updates, enabled by hot and cold patching, keep your clients
and services always on during planned and unplanned events.
● Secure air, devices, and users with the Cisco Catalyst 9800-40. Wireless infrastructure becomes the
strongest first line of defense with Cisco Encrypted Traffic Analytics (ETA) and Software-Defined Access
(SD-Access). The controller comes with built-in security: Secure Boot, runtime defenses, image signing,
integrity verification, and hardware authenticity.
● Built on a modular operating system, the 9800-40 features open and programmable APIs that enable
automation of day-0 to day-N network operations. Model-driven streaming telemetry provides deep
insights into the health of your network and clients.
● Cisco User Defined Network, a feature available in Cisco DNA Center, allows IT to give end users control
of their very own wireless network partition on a shared network. End users can then remotely and
securely deploy their devices on this network. Perfect for university dormitories or extended hospital
stays, Cisco User Defined Network grants both device security and control, allowing each user to choose
who can connect to their network.
● The Wi-Fi 6 readiness dashboard is a new dashboard in the Assurance menu of Cisco DNA Center. It will
look through the inventory of all devices on the network and verify device, software, and client
compatibility with the new Wi-Fi 6 standard. After upgrading, advanced wireless analytics will indicate
performance and capacity gains as a result of the Wi-Fi 6 deployment. This is an incredible tool that will
help your team define where and how the wireless network should be upgraded. It will also give you
insights into the access point distribution by protocol (802.11 ac/n/abg), wireless airtime efficiency by
protocol, and granular performance metrics.
Features
Table 1. Key features
Metric Value
Access points Aironet 802.11ac Wave 1 and Wave 2 access points, Cisco
Catalyst 9100 802.11ax access points
*
For information on compatibility: Compatibility Guide
Always on
Seamless software updates enable faster resolution of critical issues, introduction of new access points with
zero downtime, and flexible software upgrades. Stateful Switchover (SSO) with 1:1 active standby and N+1
redundancy keeps your network, services, and clients always on, even in unplanned events.
Secure
Secure air, devices, and users with the Cisco Catalyst 9800-40 Wireless Controller. Wireless infrastructure
becomes the strongest first line of defense with ETA and SD-Access. The controller comes with built-in
security: Secure Boot, runtime defenses, image signing, integrity verification, and hardware authenticity. Cisco
Advanced Wireless Intrusion Prevention System (aWIPS) is a complete wireless security solution that uses the
Cisco Unified Access infrastructure to detect, locate, mitigate, and contain wired and wireless rogues and
threats.
Open and programmable
The controller is built on the Cisco IOS XE operating system, which offers a rich set of open standards-based
programmable APIs and model-driven telemetry that provide an easy way to automate day-0 to day-N network
operations.
Details
Physical dimensions
Table 2. Physical dimensions
Dimension Value
Figure 2.
Front panel
Figure 3.
Front panel components
Figure 4.
10G/1G ports
Label Component
11 RP: 1 GE SFP port (the only SFPs supported on the RP port are GLC-SX-
MMD and GLC-LH-SMD)
Ports
Port Purpose
2x USB 3.0 ports USB 3.0 ports for plugging in external memory
1x RJ-45 management port Management port used for out-of-band management. Also known as
service port
1x SFP Gigabit Ethernet redundancy port Redundancy port used for SSO
● Redundancy port used for SSO; works with Cisco supported SFPs (GLC-LH-SMD
and GLC-SX-MMD) for RP port
4x 10G/1G SFP+ or SFP ports Ports used for sending and receiving traffic between access points and
controller, northbound traffic, in-band management traffic, and wireless
client traffic. Must be connected to the switch
USB console Green When LED is lit, USB Console is enabled (RJ-45 console is
disabled)
SSD activity Green Indicates active use of the hard disk SSD memory devices in
the unit
Rear panel
Figure 5.
Rear panel
Label Component
1 Fans
4 Power/standby switch
Off 1 Hz blinking Power supply warning events in which the power supply
continues to operate (high temperature, high power, and
slow fan)
Power
The 9800-40 controller supports an optional redundant AC power supply.
The power entry modules (PEMs) provide redundant power to the system, and the 9800-40 can operate
continuously with only a single PEM installed. The PEMs are hot-swappable, and replacement of a single PEM
can be made without power interruption to the system. All external connections to the PEMs are made from the
rear panel of the chassis, and they are removed or inserted from the rear. The main power switch for the unit is
located directly next to the PEMs on the rear of the chassis.
GLC-BX-U
GLC-LH-SMD
GLC-SX-MMD
GLC-EX-SMD
GLC-ZX-SMD
GLC-TE
SFP-10G-AOC2M
SFP-10G-AOC3M
SFP-10G-AOC5M
SFP-10G-AOC7M
SFP-10G-AOC10M
SFP-10G-SR
SFP-10G-SR-S
SFP-10G-SR-X
SFP-10G-LR
SFP-10G-LRM
SFP-10G-LR-X
SFP-10G-ER
SFP-10G-ZR
SFP-H10GB-CU1M
SFP-H10GB-CU1.5M
SFP-H10GB-CU2M
SFP-H10GB-CU2.5M
SFP-H10GB-CU3M
SFP-H10GB-CU5M
SFP-H10GB-ACU7M
SFP-H10GB-ACU10M
DWDM-SFP10G-30.33 - DWDM-SFP10G-61.41
Benefits
Cisco IOS XE opens a completely new paradigm in network configuration, operation, and monitoring through
network automation. Cisco’s automation solution is open, standards-based, and extensible across the entire
lifecycle of a network device. The various mechanisms that bring about network automation are outlined below,
based on a device lifecycle.
● Automated device provisioning: This is the ability to automate the process of upgrading software
images and installing configuration files on Cisco access points when they are being deployed in the
network for the first time. Cisco provides turnkey solutions such as Plug and Play (PnP) that enable an
effortless and automated deployment.
● API-driven configuration: Modern wireless controllers such as the Cisco Catalyst 9800-40 Wireless
Controller support a wide range of automation features and provide robust open APIs over Network
Configuration Protocol (NETCONF) using YANG data models for external tools, both off-the-shelf and
custom built, to automatically provision network resources.
● Granular visibility: Model-driven telemetry provides a mechanism to stream data from a wireless
controller to a destination. The data to be streamed is driven through subscription to a data set in a
YANG model. The subscribed data set is streamed out to the destination at configured intervals.
Additionally, Cisco IOS XE enables the push model, which provides near-real-time monitoring of the
network, leading to quick detection and rectification of failures.
● Seamless software upgrades and patching: To enhance OS resilience, Cisco IOS XE supports
patching, which provides fixes for critical bugs and security vulnerabilities between regular maintenance
releases. This support allows customers to add patches without having to wait for the next maintenance
release.
◦ Image signing: Cryptographically signed images provide assurance that the firmware, BIOS, and
other software are authentic and unmodified. As the system boots, its software signatures are
checked for integrity.
◦ Secure Boot: Cisco Secure Boot technology anchors the boot sequence chain of trust to immutable
hardware, mitigating threats against a system's foundational state and the software that is to be
◦ Cisco Trust Anchor module: A tamper-resistant, strong cryptographic, single-chip solution uniquely
identifies the product so that its origin can be confirmed to Cisco, providing assurance that the
product is genuine.
◦ Cisco Wireless Intrusion Prevention System (WIPS): WIPS offers advanced network security to
detect, locate, mitigate, and contain any intrusion or threat on your wireless network. It can monitor
and detect wireless network anomalies, unauthorized access, and RF attacks. A new, dedicated
classification engine for rogues and aWIPS is built on Cisco DNA Center. A fully integrated stack for
the WIPS solution includes Cisco DNA Center, a Cisco Catalyst 9800 controller, Wave 2, and Cisco
Catalyst 9100 Access Point. This new architecture provides improved detection and security,
simplicity, and ease of use, and reduced false positive alarms.
Flexible NetFlow
● Flexible NetFlow (FNF): Cisco IOS FNF is the next generation in flow visibility technology, allowing
optimization of the network infrastructure, reducing operating costs, and improving capacity planning
and security incident detection with increased flexibility and scalability.
Application visibility and control
● Next-Generation Network-Based Application Recognition (NBAR2): NBAR2 enables advanced
application classification techniques, with up to 1400 predefined and well-known application signatures
and up to 150 encrypted applications on the Cisco Catalyst 9800-40. Some of the most popular
applications included are Skype, Office 365, Microsoft Lync, Cisco Webex, and Facebook. Many others
are already predefined and easy to configure. NBAR2 provides the network administrator with an
important tool to identify, control, and monitor end-user application usage while helping ensure a quality
user experience and securing the network from malicious attacks. It uses FNF to report application
performance and activities within the network to any supported NetFlow collector, such as Cisco Prime,
Stealthwatch, or any compliant third-party tool.
Quality of service
● Superior Quality of Service (QoS): QoS technologies are tools and techniques for managing network
resources and are considered the key enabling technologies for the transparent convergence of voice,
video, and data networks. QoS on the Cisco Catalyst 9800-40 consists of classification of traffic based
on packet data as well as application recognition and traffic control actions such as drop, marking and
policing. A modular QoS command-line framework provides consistent platform-independent and
flexible configuration behavior. The 9800-40 also supports policies at two levels of target: BSSID as well
as client. Policy assignment can be granular down to the client level.
Smart operation
● Bluetooth ready: The Cisco Catalyst 9800-40 has hardware support to connect a Bluetooth dongle to
the controller, enabling you to use this wireless interface as a management port. This port functions as
an IP management interface and can be used for configuration and troubleshooting using WebUI or the
Command-Line Interface (CLI), and to transfer images and configurations.
Specifications
Table 9. Specifications
Item Specification
Wired, switching, and IEEE 802.3 10BASE-T, IEEE 802.3u 100BASE-TX, 1000BASE-T.
routing standards 1000BASE-SX, 1000-BASE-LH, IEEE 802.1Q VLAN tagging, 802.1AX
Link Aggregation
● RFC 791 IP
● RFC 2460 IPv6
● RFC 792 Internet Control Message Protocol (ICMP)
● RFC 793 TCP
● RFC 826 Address Resolution Protocol (ARP)
● RFC 1122 Requirements for Internet Hosts
● RFC 1519 Classless Interdomain Routing (CIDR)
● RFC 1542 Bootstrap Protocol (BOOTP)
● RFC 2131 Dynamic Host Configuration Protocol (DHCP)
● RFC 5415 Control and Provisioning of Wireless Access Points (CAPWAP)
Protocol
● RFC 5416 CAPWAP Binding for 802.11
● RFC 1851 Encapsulating Security Payload (ESP) Triple DES (3DES) Transform
● RFC 2104 HMAC: Keyed-Hashing for Message Authentication
● RFC 2246 TLS Protocol Version 1.0
Encryption standards ● Static Wired Equivalent Privacy (WEP) RC4 40, 104 and 128 bits
● Advanced Encryption Standard (AES): Cipher Block Chaining (CBC), Counter
with CBC-MAC (CCM), Counter with CBC Message Authentication Code
Protocol (CCMP)
● Data Encryption Standard (DES): DES-CBC, 3DES
● Secure Sockets Layer (SSL) and Transport Layer Security (TLS): RC4 128-bit
and RSA 1024- and 2048-bit
● DTLS: AES-CBC
● IPsec: DES-CBC, 3DES, AES-CBC
● 802.1AE MACsec encryption
Nonoperating temperature:
● -40°to 65°C (-104° to 149°F)
Operating humidity:
● Nominal: 10% to 90% noncondensing
Operating altitude:
● Appliance operating: 0 to 3000 m (0 to 10,000 ft)
● Appliance nonoperating: 0 to 12,192 m (0 to 40,000 ft)
Electrical input:
● AC input frequency range: 47 to 63 Hz
● AC input range: 90 to 264 VAC with AC PEM
● 1100W AC with optional redundant power supply (hot-swappable)
EMC – Emissions:
● EN61000-3-2 Power Line Harmonics (EMI-3)
● EN61000-3-3 Voltage Changes, Fluctuations, and Flicker (EMI-3)
EMC – Immunity:
● IEC/EN61000-4-2 Electrostatic Discharge Immunity
● IEC/EN61000-4-3 Radiated Immunity
EMC (ETSI/EN)
● EN 300 386 Telecommunications Network Equipment (EMC) (EMC-3)
● EN55022 Information Technology Equipment (Emissions)
● EN55024/CISPR 24 Information Technology Equipment (Immunity)
● EN50082-1/EN61000-6-1 Generic Immunity Standard (EMC-4)
C9800-40-K9 Cisco Catalyst 9800-40 Wireless Controller Cisco IOS XE Software Release 16.10.1
Licensing
No licenses are required to boot up a Cisco Catalyst 9800 Series Wireless Controller. However, in order to
connect any access points to the controller, Cisco DNA software subscriptions are required. To be entitled to
connecting to a 9800 Series controller, each access point requires a Cisco DNA subscription license.
Figure 6.
Determining license requirements for access points connecting to Cisco Catalyst 9800 Series Wireless Controllers
They can support both tiers of Cisco DNA software: Cisco DNA Essentials and Cisco DNA Advantage.
Cisco DNA software subscriptions provide Cisco innovations on the access point. They also include perpetual
Network Essentials and Network Advantage licensing options, which cover wireless fundamentals such as
802.1X authentication, QoS and PnP; telemetry and visibility; and single sign-on, as well as security controls.
Cisco DNA subscription software has to be purchased for a 3-, 5-, or 7-year subscription term. Upon expiry of
the subscription, the Cisco DNA features will expire, whereas the Network Essentials and Network Advantage
features will remain.
For the full feature list of Cisco DNA Software, including the perpetual Network Essentials and Network
Advantage, please see the feature matrix: https://www.cisco.com/c/m/en_us/products/software/dna-
subscription-wireless/en-sw-sub-matrix-wireless.html?oid=porew018984.
● Cisco Smart Licensing is a flexible licensing model that provides you with an easier, faster, and more
convenient way to purchase and manage software across the Cisco portfolio and across your
organization. And it’s secure- you control what users can access. With Smart Licensing you get:
◦ Easy Activation: Smart licensing establishes a pool of software licenses that can be used across the
entire organization-no more PAKs (Product Activation Keys).
◦ Unified Management: My Cisco Entitlements (MCE) provides a complete view into all of your Cisco
Products and services in an easy-to-use portal, so you always know what you have and what you are
using.
◦ License Flexibility: Your software is not node-locked to your hardware, so you can easily use and
tranfer licenses as needed.
To use Smart Licensing, you must first set up a Smart Account on Cisco Software Central
(software.cisco.com).
Four levels of license are supported on the Cisco Catalyst 9800 Series Wireless Controllers. The controllers
can be configured to function at any one of the four levels.
● Cisco DNA Essentials: At this level the Cisco DNA Essentials feature set will be supported.
● Cisco DNA Advantage: At this level the Cisco DNA Advantage feature set will be supported.
● NE: At this level the Network Essentials feature set will be supported. This is available with Cisco DNA
Essentials.
● NA: At this level the Network Advantage feature set will be supported. This is available with Cisco DNA
Advantage.
Initial bootup of the controller will be at the Cisco DNA Advantage level.
For questions, contact the Cisco Catalyst 9800 Series Wireless Controllers Licensing mailer group at
ask-catalyst 9800 licensing.
Warranty
Find warranty information on Cisco.com at the Product Warranties page.
Cisco 1-year limited hardware warranty terms
The following are terms applicable to your hardware warranty. Your embedded software is subject to the Cisco
General Terms (link available below) and/or any SEULA or specific software warranty terms for additional
software products loaded on the device.
Duration of hardware warranty: One (1) year
Replacement, repair, or refund procedure for hardware: Cisco or its service center will use commercially
reasonable efforts to ship a replacement part within ten (10) working days after receipt of the Return Materials
Authorization (RMA) request. Actual delivery times may vary depending on customer location.
Cisco reserves the right to refund the purchase price as its exclusive warranty remedy.
Reference links to information about key environmental sustainability topics (mentioned in the “Environment
Sustainability” section of the CSR Report) are provided in the following table:
Information on electronic waste laws and regulations, including products, batteries, and WEEE compliance
packaging
Ordering information
Table 12. Ordering information
Accessories, spares C9800-AC-750W R= Cisco Catalyst 9800-40 750W AC Power Supply Reverse Air
Cisco Capital
Flexible payment solutions to help you achieve your objectives
Cisco Capital makes it easier to get the right technology to achieve your objectives, enable business
transformation and stay competitive. We can help you reduce the total cost of ownership, conserve capital, and
accelerate growth. In more than 100 countries, our flexible payment solutions can help you acquire hardware,
software, services and complementary third-party equipment in easy, predictable payments.
Learn more.
Cisco DNA Spaces name change Updated product name to Cisco Spaces 10/21/22