The same tension surfaces in nearly every campus networking conversation with customers: security teams need to move faster, but the network cannot afford to stop.
That tension isn’t new. What’s new is the speed of security threats. In a post-Mythos world, attackers are using AI-assisted tooling to find, adapt, and weaponize vulnerabilities faster than traditional infrastructure operating models were designed to handle. At the same time, campus networks carry more critical traffic than ever: clinicians and carts in hospitals, robots and sensors on factory floors, point-of-sale systems in stores, students and research on university campuses, and now, AI agents that can act continuously across applications and data.
The question is no longer only, “How do I remediate faster?” but also, “How do I reduce exposure immediately, preserve uptime, and still make permanent software updates in a controlled way?”
That’s the operating model this blog post is about. Live Protect and Extended Fast Software Upgrade (xFSU) are two different capabilities, but together they point to a future where campus infrastructure can defend, adapt, and update with minimal disruption.
Live Protect: Close the exposure window without rebooting the network
Live Protect changes the first part of the workflow.
It’s not a replacement for patching; a permanent software update is still the end state. Live Protect is a targeted runtime capability, validated by Cisco, that can help reduce exposure to a known vulnerability while the infrastructure continues to run.
Instead of forcing every vulnerability response into an emergency upgrade cycle, security and networking teams get a staged model:
- Start with an advisory that identifies exposure and the fixed software path.
- Use a validated vulnerability shield where platform, release, policy, and mode are supported.
- Monitor the shield to understand whether matching events are occurring before enforcement.
- Enforce the shield where supported and appropriate to block or mitigate the exploit path in real time.
- Disable or retire the shield after the permanent software fix is applied.
The value isn’t just speed. It’s confidence.
At Cisco, we create and validate Live Protect shield through the appropriate Cisco Product Security Incident Response Team (PSIRT), engineering, and support workflows before we publish customer guidance. They are each targeted to a specific vulnerability condition, observable by operators, reversible when needed, and temporary by design. That’s very different from asking every enterprise to invent custom runtime rules during a crisis.
Live Protect is for supported Cisco products and releases. While it’s not a universal protection for every vulnerability, a generic third-party workload control, or a substitute for permanent remediation, that boundary is a feature, not a weakness. The trust comes from knowing exactly what’s supported, how it’s governed, and when the temporary control should be retired.
For campus and branch networks, this is a major shift. Infrastructure is now part of the attack surface. The switch, router, or controller is no longer just something you remediate after the fact. It becomes an active protection point in the infrastructure itself.
Live Protect helps reduce risk before permanent remediation. A software maintenance upgrade (SMU) can be the patch-style path when that is available and appropriate. xFSU solves a different operational problem: it changes the economics of full software image upgrades.
xFSU: Make software image upgrades easier to deploy
Extended Fast Software Upgrade solves a different operational problem: many access-layer switches don’t have a redundant forwarding path for every endpoint. A traditional reload can take users offline for several minutes. In environments like healthcare, manufacturing, transportation, retail, and higher education, that’s not just an inconvenience—it can become a business continuity issue.
xFSU reduces that disruption by separating the control plane and data plane during the software transition. The control plane can restart and move to the new software while the data plane keeps forwarding using the state already programmed in hardware. Then the data plane is updated in a much shorter disruption window and forwarding resumes using the preserved forwarding state.
Put simply: the network keeps doing its job for most of the upgrade process.
For Cisco Catalyst 9300 Series Switch deployments, this can reduce traffic impact from minutes to seconds where supported. On stacks, xFSU staggers the process across members and uses stateful switchover to preserve continuity. Operators still need to run eligibility checks, meet platform and software prerequisites, and account for feature caveats, but the direction is important: upgrades become more predictable and repeatable, and less dependent on heroic overnight change windows.
That changes behavior.
Traditional upgrades cause three to five minutes or more of downtime. When image upgrades are painful, they get deferred. When they are low impact and validated up front, teams can move toward a more regular software lifecycle. That’s the real security outcome. xFSU isn’t just an availability feature; it’s a security enabler because it helps close the gap between “fixed image is available” and “fixed image is deployed” when an image upgrade is the right remediation path—reducing traffic downtime to less than five seconds on Catalyst 9300 switches running IOS XXE 17.15.2 or later.
Synchronizing security and operations
Live Protect and xFSU should not be viewed as competing solutions. They are two parts of the same operating model. By pairing these capabilities, organizations can move beyond the binary choice between urgent remediation and uptime.
When a vulnerability is disclosed, this pairing allows for a staged, collaborative response. Security operations (SecOps) teams gain a faster path to exposure reduction through Live Protect, while network operations (NetOps) teams maintain the stability of the production environment. Once the immediate exposure is shielded, teams can transition to permanent remediation—whether via SMU or full image upgrade—using xFSU to help make the process is repeatable and predictable.
This model replaces the high-pressure maintenance window with a calculated, transparent workflow. Security teams spend less time pushing for emergency changes that risk business continuity. Network teams gain the operational headroom to execute updates as part of a standard lifecycle. The business gets resilience without pretending uptime and security are separate goals.
Architecting for a connected campus
It’s tempting to borrow operating models from the data center and assume they apply everywhere, but the campus has a different set of operational constraints.
It’s where the physical world connects: users, cameras, badges, building systems, access points, medical devices, industrial endpoints, and AI-enabled workflows. Many of those endpoints are not easy to patch. Many are operationally sensitive, mobile, unmanaged, or single-homed. Increasingly, their traffic is encrypted, machine-generated, and lateral.
That makes the access layer both a security challenge and a security opportunity.
The challenge is that downtime is visible immediately. The opportunity is that the network is already present at the point of connection. If security can be fused into that network layer, then protection doesn’t have to wait for a centralized inspection point or a bolt-on appliance path. It can happen where the user, device, application, or agent enters the environment.
This evolution is the cornerstone of a secure network architecture: moving beyond perimeter-based defense to build trust directly into the platforms that forward data. A network that can protect itself at runtime and update with less disruption serves as a stronger foundation for segmentation, Encrypted Traffic Analytics, zero-trust access, and closed-loop operations.
Achieving continuous network resilience
The era of AI-driven threats demands a move away from static infrastructure management. Attackers are accelerating their tooling, and your networks carry increasingly critical data. To keep up with this pace, the answer cannot be a network that only evolves during rare, high-stakes windows.
Instead, aim for a model that can absorb change safely.
For network teams, this requires several practical shifts in how you manage campus environments:
- Lifecycle management: Treat every vulnerability response as an ongoing cycle rather than a single, isolated event.
- Visibility-driven planning: Make software upgrade eligibility a constant metric, so your teams know which segments are ready for updates before the maintenance window opens.
- Agility prioritization: Focus investments on platforms and topologies that inherently support lower-disruption updates, making long-term agility a standard requirement.
- Operational alignment: Align NetOps and SecOps around shared evidence and unified metrics to reduce the friction between exposure reduction and infrastructure stability.
- Small-batch change adoption: Shift the organizational culture toward smaller, frequent, and safer updates, which can lower the overall risk profile compared with rare, large-scale events.
The ultimate goal is infrastructure that defends and evolves while it’s running. By using runtime protections like Live Protect and streamlining the path to full upgrades with xFSU, you can turn campus security from a maintenance-window problem into a pillar of business continuity. This is the promise of secure networking: controls that operate in the right place, at the right speed, without trading uptime for protection.
Explore how Extended Fast Software Upgrade (xFSU) enables campus switch upgrades and reloads with minimal disruption
Get More from Cisco Networking
Customer stories, technical demos and more await!
Check out our Networking video channel
Multidomain Architecture
Learn how to integrate your networking domains and get more out of an enterprise-wide, intent-based network.
Discover multidomain integration
