Platform Scope and Presales Positioning

The Cisco Catalyst 9800-40 is a fixed, 1RU wireless controller running Cisco IOS XE for midsize and large enterprise deployments. The supplied datasheet specifies support for up to 2000 access points, 32,000 clients, and 40 Gbps throughput. Supported deployment modes are centralized wireless, Cisco FlexConnect, and Fabric Wireless using SD-Access.

The hardware provides four 10G/1G data interfaces, separate management and redundancy interfaces, and optional redundant AC power. Controller resiliency includes stateful switchover, N+1 redundancy, software maintenance upgrades, and In-Service Software Upgrade (ISSU).

Presales rule: Evaluate AP count, client count, traffic demand, configuration scale, and failover requirements independently. The published maxima are capacity boundaries, not evidence that every maximum can be sustained simultaneously under every feature combination.

The source describes only one fixed controller SKU. It does not identify modular or compact controller models. Its modular operating system should not be confused with a modular chassis architecture.

Capacity and Deployment Sizing

Sizing metric Published maximum
Access points Up to 2000
Clients 32,000
Throughput Up to 40 Gbps
WLANs 4096
VLANs 4096
Site tags 2000
Flex APs per site 100
Policy tags 2000
RF tags 2000
RF profiles 4000
Policy profiles 1000
Flex profiles 2000

These limits require separate checks during design. A deployment below the AP ceiling may still exceed its client, policy-profile, or FlexConnect site limit.

Recommended presales checks are:

  • AP population: Include planned expansion and APs expected to move to the controller during failure scenarios.
  • Client population: Size for the projected connected-client population rather than employee count alone.
  • Traffic: Assess traffic that must traverse controller data ports for the selected forwarding design. The datasheet does not provide feature-specific throughput reductions or packet-size test conditions.
  • FlexConnect sites: Check the 100-Flex-AP-per-site maximum independently of the controller-wide AP limit.
  • Configuration objects: Count WLANs, VLANs, tags, and profiles from the proposed segmentation and RF design.
  • Redundancy: Verify that surviving controller resources can accommodate the intended failover population.

A controller pair should not automatically be presented as doubling usable capacity: the documented 1:1 arrangement is active/standby.

Interfaces and Cabling Architecture

The detailed port tables identify four dual-rate data interfaces, TE0 through TE3. Each supports 1 GE SFP or 10 GE SFP+ operation. These interfaces carry AP-to-controller traffic, wireless client traffic, northbound traffic, and in-band management, and must connect to a switch.

10/100-Mbps operation is not supported on the four data ports. The 10/100/1000 capability belongs to the RJ-45 management and redundancy interfaces.

Interface Quantity Documented purpose
1G SFP/10G SFP+ data port 4 Controller data traffic and in-band management
RJ-45 10/100/1000 service port 1 Out-of-band management
RJ-45 10/100/1000 redundancy port 1 SSO
1 GE SFP redundancy port 1 SSO
RJ-45 console 1 Out-of-band console access
USB console 1 Out-of-band console access
USB 3.0 external-memory port 2 External storage

The front-panel description calls the USB console connector Mini USB; the port-purpose table labels it USB 3.0 console. Confirm connector and cable requirements before installation.

The redundancy SFP port supports only GLC-SX-MMD and GLC-LH-SMD. The broader data-port transceiver list does not apply to that port.

IEEE 802.1Q VLAN tagging and 802.1AX link aggregation are listed. The source does not specify aggregation group limits, hashing behavior, or oversubscription guidance.

Controller, License, Spare, and Transceiver SKU Matrix

Platform and ordering items

Category Product ID as supplied Description or scope
Fixed controller C9800-40-K9 Catalyst 9800-40 Wireless Controller
Controller license LIC-C9800-DTLS-K9 Catalyst 9800 Series Wireless Controller DTLS License
Power spare/accessory C9800-AC-750W R= 750W AC power supply, reverse air
Modular controller Not listed No modular controller SKU supplied
Compact controller Not listed No compact controller SKU supplied

The power-supply product ID contains an embedded space in the extracted ordering table. Validate the orderable identifier rather than silently changing it.

Supported data-port modules

All individual transceiver and cable identifiers in the source are reproduced below. The DWDM entry remains a range because the datasheet does not enumerate its intermediate SKUs.

Module category Supported identifiers
SFP GLC-BX-D, GLC-BX-U, GLC-LH-SMD, GLC-SX-MMD, GLC-EX-SMD, GLC-ZX-SMD, GLC-TE
SFP+ AOC entries SFP-10G-AOC1M, SFP-10G-AOC2M, SFP-10G-AOC3M, SFP-10G-AOC5M, SFP-10G-AOC7M, SFP-10G-AOC10M
SFP+ SR entries SFP-10G-SR, SFP-10G-SR-S, SFP-10G-SR-X
SFP+ LR/LRM entries SFP-10G-LR, SFP-10G-LRM, SFP-10G-LR-X
SFP+ ER/ZR entries SFP-10G-ER, SFP-10G-ZR
SFP+ CU entries SFP-H10GB-CU1M, SFP-H10GB-CU1.5M, SFP-H10GB-CU2M, SFP-H10GB-CU2.5M, SFP-H10GB-CU3M, SFP-H10GB-CU5M
SFP+ ACU entries SFP-H10GB-ACU7M, SFP-H10GB-ACU10M
DWDM range DWDM-SFP10G-30.33 through DWDM-SFP10G-61.41

Presales rule: Match the selected module to the actual interface role. Optical reach, fiber requirements, and individual DWDM channel ordering details are not specified in this source and require separate validation.

Availability and Software Maintenance

The controller supports 1:1 active/standby Stateful Switchover and N+1 redundancy. Redundant power addresses a different failure domain and does not replace controller redundancy.

Software maintenance capabilities include:

  • Software Maintenance Upgrades: Packages containing bug fixes or security resolutions for released images. IOS XE validates compatibility and rejects incompatible SMUs.
  • Hot and cold patching: Both are listed; the document does not establish that every patch is nondisruptive.
  • Rolling AP upgrades: AP upgrades can proceed in stages without restarting the entire network.
  • Standby monitoring: NETCONF/YANG, RESTCONF, and CLI access can monitor standby health without going through the active controller.
  • ISSU: The documented procedure upgrades the backup controller, transfers the active role, and upgrades the formerly active controller.

The datasheet describes ISSU as retaining AP and client sessions while forwarding continues. It also describes native, RF-based staggered AP upgrades without an external orchestrator or additional licenses.

Presales rule: Present these as documented capabilities, not an unconditional guarantee for every release transition. Establish the intended software versions and upgrade procedure before committing to maintenance-window outcomes.

Physical, Environmental, and Power Engineering

Parameter Published specification
Form factor 1RU
Width 17.3 inches / 43.94 cm
Depth 19.5 inches / 49.53 cm
Height 1.72 inches / 4.37 cm
Weight 22.8 lb / 10.34 kg
Internal storage SATA SSD; 240 GB listed in the storage section
Normal operating temperature 0 to 40 C / 32 to 104 F
Short-term operating temperature 0 to 50 C / 32 to 122 F
Nonoperating temperature -40 to 65 C
Nominal operating humidity 10% to 90%, noncondensing
Short-term operating humidity 5% to 90%, noncondensing
Nonoperating humidity 5% to 93% at 28 C / 82 F
Operating altitude 0 to 3000 m / 0 to 10,000 ft
Nonoperating altitude 0 to 12,192 m / 0 to 40,000 ft
AC input voltage 90 to 264 VAC
AC input frequency 47 to 63 Hz
Maximum power consumption 381 W
Heat dissipation 1300 BTU/hr
Acoustic entry 74.1 LpAm (dBA) at 27 C nominal operation
MTBF Not provided

Source discrepancies and missing installation data

The nonoperating temperature entry pairs -40 C with -104 F, an inconsistent conversion. Use the published Celsius range as the reference pending clarification rather than reproducing the Fahrenheit range as validated.

The acoustic entry is labeled “A-weighted sound power level” but uses “LpAm (dBA).” Preserve the published value with that qualification. Measurement distance, test arrangement, and alternative operating-condition readings are absent.

The specifications table lists 1100W AC power, while ordering information describes a 750W AC replacement supply. Neither value should replace the separately stated 381 W maximum system consumption. Confirm the appropriate supply before ordering.

No MTBF, short-term temperature duration, installation clearance, or complete chassis airflow specification is supplied. The spare description says “Reverse Air,” but that alone does not establish all rack airflow requirements.

Power resiliency and facility planning

The controller can operate continuously with one power entry module installed. PEMs are hot-swappable, with rear-panel insertion, removal, and electrical connections. Replacement of one PEM can occur without interrupting the system when the remaining power arrangement sustains operation.

Use the published maximum consumption and heat dissipation as facility-planning inputs. Do not derive an AP PoE budget from the supply rating: the datasheet specifies no controller PoE output or PoE budget.

Security, Application Visibility, and QoS

The platform includes Secure Boot, image signing, integrity verification, runtime defenses, hardware authenticity, and a Trust Anchor module. Cryptographically signed images are checked during boot; the Trust Anchor provides a tamper-resistant product identity.

Encrypted Traffic Analytics is described as identifying malware in encrypted access-layer traffic. WIPS/aWIPS detects, locates, mitigates, and contains wireless threats and rogues. The documented integrated WIPS architecture includes Cisco DNA Center, a Catalyst 9800 controller, and Wave 2 or Catalyst 9100 APs.

NBAR2 supports up to 1400 predefined application signatures and up to 150 encrypted applications. Flexible NetFlow reports application activity and performance to supported collectors, including compliant third-party tools.

QoS supports packet-based and application-based classification, dropping, marking, and policing. Policies can target BSSIDs and individual clients.

The standards list includes WPA, WPA2, WPA3, 802.1X, RADIUS authentication/accounting, dynamic authorization, EAP-TLS, web authentication, and TACACS for management users. Encryption entries include AES, DTLS, IPsec, and 802.1AE MACsec, alongside legacy algorithms.

Engineering rule: A standards listing is not a recommended security baseline. Confirm protocol configuration and feature applicability for the selected release; the source does not map every listed encryption capability to specific interfaces or operating modes.

Management, Automation, and Compatibility

The controller supports Cisco DNA Center, Cisco Prime Infrastructure, integrated WebUI, and third-party management through open APIs. WebUI is included in the default image without a separate license or enablement requirement.

Automation functions include Plug and Play provisioning, NETCONF with YANG models, and subscription-based streaming telemetry. Management interfaces include HTTP/HTTPS, SSH, Telnet, serial console, SNMP, and NETCONF.

Hardware support for a Bluetooth dongle permits an IP management interface for WebUI, CLI, and image/configuration transfer. No dongle SKU is supplied.

Supported AP families are Aironet 802.11ac Wave 1 and Wave 2 and Catalyst 9100 802.11ax. The wireless standards list also covers 802.11a/b/g/d/e/h/n/k/r/u/w.

AireOS interoperability, ISE integration, CMX, Cisco Spaces, and management-platform compatibility are explicitly subject to the referenced Compatibility Guide. Cisco DNA Center also supplies the described User Defined Network and Wi-Fi 6 readiness dashboard functions.

The listed minimum software for C9800-40-K9 is IOS XE 16.10.1. Treat this as the published baseline, not proof that every later-described integration works on that initial release.

Licensing and Commercial Qualification

No license is required to boot the controller. Each connected AP requires a Cisco DNA subscription entitlement.

License level Source-described behavior
Cisco DNA Essentials DNA Essentials feature set; includes Network Essentials
Cisco DNA Advantage DNA Advantage feature set; includes Network Advantage
Network Essentials, NE Perpetual features remain after subscription expiration
Network Advantage, NA Perpetual features remain after subscription expiration

Subscription terms are 3, 5, or 7 years. DNA features expire at term end, while the associated perpetual Network features remain. Initial controller boot is at DNA Advantage level; that default is not a substitute for purchased entitlement.

A Smart Account is mandatory. Smart Licensing supports pooled, transferable licensing and centralized visibility. Specific License Reservation provides node-based reservation per controller without communicating usage to Cisco or a satellite.

Presales rule: Separate controller hardware, AP subscription quantities, term lengths, feature tiers, and the listed DTLS license item in the commercial review. The datasheet does not explain the DTLS SKU’s detailed applicability or supply subscription SKUs and prices.

Warranty, Service, and Acceptance Checks

The hardware warranty is one year. Cisco or its service center will use commercially reasonable efforts to ship replacement parts within 10 working days after receipt of an RMA request. Actual delivery varies by location, and Cisco reserves the right to refund the purchase price as its exclusive warranty remedy.

Embedded software is governed by the applicable EULA, SEULA, or specific software warranty terms.

This is not a stated next-business-day delivery or onsite restoration commitment. The source provides no support-service SKU, TAC coverage schedule, onsite response time, or extended-service price. Separately qualify service coverage against the required recovery objective.

Before final approval:

  1. Validate capacity and failover loads against every applicable ceiling.
  2. Confirm AP, software, management, and security-platform compatibility.
  3. Resolve the power-supply rating and extracted spare identifier.
  4. Verify data-port and redundancy-port optics separately.
  5. Confirm rack, temperature, acoustic, power, and cooling suitability.
  6. Review subscription expiration and perpetual feature expectations.
  7. Document the upgrade procedure and contracted service commitments.

These checks distinguish published platform capability from the implementation and service conditions needed for an engineering-ready proposal.