Catalyst 9300 StackWise vs StackWise Virtual: Which to Use? - 夜莺博客

Catalyst 9300 StackWise vs StackWise Virtual: Which to Use?

Cisco offers two very different "stacking" technologies on the Catalyst 9000 family, and mixing them up leads to wrong purchases and failed designs. StackWise is a physical stacking technology for access switches such as the Catalyst 9300, while StackWise Virtual is a logical pairing of two chassis - supported on Catalyst 9400, 9500 and 9600 - that works over standard fiber links. This article compares the two architectures, explains the StackWise-320/480/1T bandwidth variants, and shows how StackWise Virtual protects against split-brain with dual-active detection.

The confusion is understandable because both features use the word "stack" and both present the network as a single logical device. But they live at different layers of the design: StackWise is about how many ports you can put in one physical location, while StackWise Virtual is about how two chassis can share a control plane and eliminate a Spanning Tree blocking link between them. Choosing the wrong one is not a licensing mistake you can fix later - on the Catalyst 9300, StackWise Virtual simply does not exist, and on the Catalyst 9500 there is no stack cable to plug in.

StackWise: Physical Stacking for the Access Layer

StackWise connects up to eight Catalyst 9300 switches in a ring topology using proprietary stack cables, creating one logical switch with a single management plane. The Catalyst 9300 portfolio offers several stack bandwidth options: StackWise-320 on the Catalyst 9300L, StackWise-480 on the standard Catalyst 9300, and StackWise-1T (1 Tbps) on the Catalyst 9300X. The Catalyst 9200 family uses StackWise-160. StackWise is designed to live inside one wiring closet - stack cables are limited to roughly three meters - and it provides high availability through an active/standby supervisor model plus StackPower for power sharing.

Cabling is the defining constraint, and it is worth being blunt about it. Each Catalyst 9300 uses a StackWise adapter on the rear panel, and the cables are short copper assemblies: one cable delivers 160 Gbps of stack bandwidth, while two cables double that to 320 Gbps. The 9300X uses a high-bandwidth adapter to reach 1 Tbps across the ring. Because the assemblies cannot exceed roughly three meters, every member has to sit in the same rack row or, at the very most, in an adjacent cabinet. That single physical fact is what makes StackWise an access-layer technology - it is designed for the closet where switches are already inches apart, not for connecting closets together.

StackWise also gives you StackPower, a separate cable ring that pools power supplies across up to four members. In a PoE-heavy deployment this matters: one switch can borrow power from a neighbor with spare capacity, so you buy fewer power supplies and the stack survives a single PSU failure without shedding PoE to the phones and access points on that member. The stack therefore provides two independent forms of redundancy - forwarding and power - over two separate cable rings.

Operationally, a StackWise stack behaves as one device. There is one management IP address, one running configuration, one VLAN database and one Spanning Tree instance. The stack elects an active switch and a standby switch; the remaining members are ordinary stack members. Because every member holds the full configuration locally, the standby can take over in a few seconds during an active failure, and even a power cycle of a single member is transparent to the rest of the stack.

StackWise Virtual: Logical Pairing for Core and Distribution

StackWise Virtual (SVL) combines exactly two switches into one logical switch over standard 10G/40G/100G Ethernet links, which means the two members can be kilometers apart. SVL is the modern successor to the legacy Virtual Switching System (VSS) and runs natively on IOS-XE. Crucially, it is supported on the Catalyst 9400, 9500 and 9600 - the Catalyst 9300 and 9200 families do not support StackWise Virtual, a common source of confusion in the field.

Architecturally, an SVL pair exists to remove a blocked link. In a classic distribution design, two independent chassis connected by a Layer 2 trunk create a loop that Spanning Tree must block, which strands half of the available bandwidth. When the two chassis become one logical switch, the downstream access stacks can dual-home to both chassis and the switch forwards traffic across both links simultaneously - no blocked port, no wasted capacity, and much faster convergence when a link fails.

The link you use to build the SVL is an ordinary Ethernet port configured as a stackwise-virtual link. You can bundle up to four ports per chassis, and the switch treats them as an internal port channel, so a single failed optic does not break the SVL. Because those ports are standard optics, the two chassis can sit in the same rack, in adjacent racks, or in different buildings connected by single-mode fiber. That geographic flexibility is the entire point: SVL lets you build a single logical distribution node that spans a campus.

Only two members are allowed, and they are not peers in the physical-stacking sense. One chassis is active, the other is standby, and both forward data-plane traffic. The practical rule is simple: SVL belongs where you need loop-free Layer 2 between two aggregation or core nodes - the exact role the legacy VSS played on the Catalyst 4500 and 6500 - while physical StackWise belongs where you need many ports in one closet.

Key Differences at a Glance

  • Deployment tier: StackWise targets the access layer; StackWise Virtual targets core and distribution.
  • Member count: up to 8 (some platforms 9) with StackWise; exactly 2 with StackWise Virtual.
  • Cabling: proprietary copper stack cables (3 m limit) vs standard fiber optics (kilometers).
  • Bandwidth: 160G/320G/480G/1T depending on model vs the port speed of the SVL links you provision.
  • Failure domain: one rack vs geographically separated buildings or data centers.

The table below summarises the same comparison in the form most engineers carry to a design review:

Feature              StackWise (9300)        StackWise Virtual (9400/9500/9600)
-------------------  ----------------------  ----------------------------------
Max members          8 (some platforms 9)    2
Media                proprietary stack cable  standard 10G/40G/100G Ethernet
Max distance         ~3 meters               kilometers (fiber)
Typical tier         access closet           core / distribution
Data plane           ring, all members       active + standby, both forward
Redundancy           active/standby switch   active/standby chassis + DAD
Split-brain risk     split stack             dual-active (needs DAD)
Power sharing        StackPower (up to 4)    not applicable

Bandwidth Variants: StackWise-320, 480 and 1T

Stack bandwidth is often misread as "the speed between two switches." It is actually the aggregate of the ring, and it determines how much inter-member traffic the stack can carry before it becomes a bottleneck. The variants map cleanly onto the Catalyst 9300 models:

  • StackWise-160 - the Catalyst 9200 family; one 160 Gbps ring.
  • StackWise-320 - the Catalyst 9300L; lower-cost fixed-uplink models.
  • StackWise-480 - the standard Catalyst 9300; the most common access choice.
  • StackWise-1T - the Catalyst 9300X; the high-bandwidth variant for multi-gigabit and mGig access.

The design implication is that a single member must never be forced to carry the traffic of the whole stack; scale the ring bandwidth with the number of members and their uplink speed. If the uplinks are 10G and there are eight members, StackWise-480 is comfortable. If you are deploying mGig access points, Wi-Fi 6E or 25G uplinks, StackWise-1T on the 9300X is the safe choice.

For a full breakdown of how each variant is cabled, see our Catalyst 9300 StackWise bandwidth: 320/480/1T explained.

Configuring StackWise Virtual and Dual-Active Detection

On Catalyst 9500/9600 pairs, SVL configuration follows three steps: enable stackwise-virtual, define the SVL links, and add dual-active detection on separate ports.

Device(config)# stackwise-virtual
Device(config-stackwise-virtual)# domain 2

Device(config)# interface range FortyGigabitEthernet1/0/23, FortyGigabitEthernet1/0/24
Device(config-if-range)# stackwise-virtual link 1

Device(config)# interface FortyGigabitEthernet1/0/12
Device(config-if)# stackwise-virtual dual-active-detection

Order matters. You must configure the domain and the SVL links on both chassis with a matching domain number before the pair will come up, and the configuration requires a reload for the members to elect active and standby roles. Start with the SVL links down, bring the pair up, and only then connect the production links - bringing up a half-configured SVL pair is how dual-active incidents are born.

The switch automatically bundles SVL link members into an internal port channel. If the SVL fails, both switches would otherwise believe they are active - a split-brain condition that causes duplicate bridge IDs and MAC flapping.

How Dual-Active Detection Prevents Split-Brain

StackWise Virtual provides two detection mechanisms:

  • Fast Hello: dedicated Layer 2 links (up to four per chassis) exchange heartbeat messages; when the SVL fails, the standby promotes itself to active and sends a recovery message that forces the old active into recovery mode, error-disabling its data ports.
  • Enhanced PAgP (PAgP+): the standby sends PAgP messages with its active ID on port channels; the downstream switch detects the new active ID and propagates it, so the old active enters recovery mode.

Both mechanisms can run together for higher resiliency, and in production you should run both - Fast Hello covers the case where the SVL itself dies, while PAgP+ covers the case where the SVL is intact but the two chassis disagree about which one is active. Before deploying, always confirm that the DAD ports are cabled to distinct line cards or at least distinct ASICs on the two chassis, so a single line-card failure cannot take out both the SVL and the detection path at once.

Verify the pair with show stackwise-virtual and show stackwise-virtual dual-active-detection. The active and standby roles should be stable, the SVL link should show up on both members, and the DAD state should be enabled on the ports you configured. If a DAD port shows down, fix that before a maintenance window turns into an outage.

Common Design Mistakes to Avoid

  • Expecting SVL on a Catalyst 9300. It is not supported. If you need a loop-free pair of access switches, use a StackWise ring plus dual-homed uplinks, or move up to the 9500/9600 for SVL.
  • Running SVL without dual-active detection. Two chassis that each believe they are active will both answer for the same MAC addresses; the result looks like a massive MAC-flap and a network-wide outage.
  • Cabling the SVL across a shared failure domain. If both SVL links run through the same conduit or the same intermediate switch, you have dressed up a single point of failure as redundancy.
  • Forgetting StackPower. Choosing a high-density PoE member with only one PSU per switch wastes the power-sharing benefit that justifies stacking in the first place.
  • Mixing stack cable types. A stack ring with mismatched bandwidth adapters will not reach the advertised throughput, and mixing 9300L and 9300X adapters in one ring is a hardware-consistency problem waiting to happen.

Which Technology Should You Choose?

Use this short decision path:

  1. If the requirement is more ports in one closet, use StackWise on the Catalyst 9300 (or 9200 for smaller closets) and size the bandwidth variant to the uplinks.
  2. If the requirement is a loop-free Layer 2 pair of chassis at distribution or core, use StackWise Virtual on the Catalyst 9400, 9500 or 9600.
  3. If you need both, the standard design is a 9500/9600 SVL pair at distribution with 9300 StackWise rings at access, dual-homed to the pair.
  4. If the two chassis must be kilometers apart, only StackWise Virtual is possible; StackWise cabling cannot do it.

Get that layering right and the rest of the design - VLANs, Spanning Tree roots, gateway redundancy - falls into place. Get it wrong and you spend the next quarter explaining why a feature the datasheet mentioned will not configure.

For the wider family comparison, including how SVL relates to the legacy VSS deployed on older Catalyst platforms, see Cisco StackWise vs VSS vs StackWise Virtual. If a ring member has already fallen out of the stack, the recovery procedure is in Catalyst 9300 StackWise troubleshooting: split stacks. And because SVL pairs are routinely dual-homed to downstream access stacks, the port-channel side of the design is covered in Cisco EtherChannel: PAgP vs LACP configuration.

Original article: Catalyst 9300 StackWise System Architecture White Paper | Cisco Catalyst 9000 StackWise Virtual White Paper