Cisco Integrated Services Routers Platform Technical Breakout Architectural & Services Review Vienna, October 19, 2004 James Weathersby Session Number 1
Agenda Architectural Innovations of ISR Review of ISR Platforms Applications and Services Management Tools 2
NEW Architecture Core/Memory Current NEW Flash DRAM WIC Flash DRAM CPU WIC CPU PCI ASIC AIM External In-line Power NM DRAM/Flash Processor Custom ASIC Current 256M EDO/48M Up to 40Mb/s N/A NEW 1G DDR ECC/256 CF Up to 250Mb/s Non- Blocking PCI transfers-module to module communication 3
NEW Architecture WICs/Network Modules Current NEW Flash DRAM WIC Flash DRAM CPU WIC CPU PCI ASIC AIM External NM In-line Power Current NEW In-line Power NME NMs NM (400Mbps) NME (1.0 Gbps) Internal in-line Power (up to 360W) WICs WICs(8Mb/s) Up to 4 s- 400Mb/s POE, DW support 4
New Interfaces: Slot vs. WIC Slot WIC Slot Slot Performance per Interface Slot Flexibility Up to 8Mbps Shared* WICs, VWICs** Up to 400Mbps Dedicated*** s, WICs, VWICs, VICs Density POE (Inline Power Support) Operating Power Single-Wide Only No 3W Single-wide or Double-wide format available Yes, including 802.3af 3W or 5W *Note: In WICs the 8Mbps was the maximum available across all available WIC slots, with s there is no such limitation **Note: VICs are also supported on 1751 / 1760 in WIC/VIC slots ***400Mbps Full Duplex 5
New Interface: NME Slot vs NM Slot Performance Flexibility Density POE (Inline Power Support) Power Ability to use GE interconnect NM Slot Up to 400Mbps NMs Single or Double-Wide Only Yes (note: not 802.3af compliant) Single Wide: 15-25W Double Wide: 40W No NME Slot Up to 1.0 Gbps NMs, NMEs, EVMs* Single, Double-wide, Extended Single and Extended Doublewide formats available Yes, including 802.3af Single Wide: 40W Extra Double Wide: 50W Yes* 6
NEW Architecture AIMs/USB/LAN Interfaces Current NEW Flash DRAM WIC Flash DRAM USB USB CPU WIC CPU AIM PCI ASIC GE GE External In-line Power Current NM NEW AIM AIM In-line Power NME SLOTS/Interface Single/Dual Dual /GE GE SFP Option AIMs 1-2 AIMs 1-2 AIMs Higher speed USB N/A 2 USB ports per chassis 7
NEW Architecture Security Current NEW Flash DRAM WIC Flash DRAM USB USB CPU WIC CPU AIM PCI VPN ASIC GE GE External In-line Power Current NM NEW AIM AIM In-line Power NME Security Requires AIM Built-in or AIM 5-10x faster 3DES/AES SDM included 8
NEW Architecture Voice Current NEW Flash DRAM WIC Flash DRAM USB USB CPU WIC CPU AIM PCI DSP VPN ASIC GE GE External In-line Power Current NM NEW AIM AIM In-line Power EVM NME Voice Requires Voice NM s support VICs DSP slots on MB DSPs shared between modules TDM switching Special EVM Slot 9
Cisco 3825 and 3845 Routers Flagship for Concurrent Services In Enterprise Branch Offices Highest-Density, Maximum Performance Services Integration USB USB GE GE SFP Highest performance for maximum concurrent services at up to T3/E3 rates Integrated GE ports with copper/fiber support NME NME NME NME Maximum Modularity and Investment Protection Up to 4 NME, DSP slots to run unprecedented number of services concurrently 3825 3845 Supports existing NM, WIC/VIC/VWIC, AIMs NME Slots 2 4 Superior Availability Onboard DSP Slots Dual Internal Power Supplies Default/Max. Memory 4 N/A 256MB / 1G 4 Yes 256MB / 1G Hot swappable network modules Integrated redundant power supply Field replaceable motherboard, fan trays and power supplies 10
Cisco 2801, 2811, 2821, 2851 Routers Performance and Density for Small to Medium Enterprise Branch Offices USB GE GE Form Factor NME / EVM Slot Onboard LAN Onboard DSP Slots Default/Max. Memory NME VWIC EVM 2801 0/0 2 2 1RU 128MB/ 384MB VWIC 2811 1/0 2 2 1RU 256MB / 760MB USB USB 2821 1/1 3 2 GE 2RU 256MB / 1G 2851 1/1 3 2 GE 2RU 256MB / 1G Mid/High-Density, High Performance Services High-performance concurrent security, voice and advanced services to multiple T1/E1 WAN rates Integrated or GE ports with copper support Integrated L2 switching with PoE Enhanced Modularity and Investment Protection Flexible expansion ( NME, EVM), additional concurrent services Existing NM, WIC/VIC/VWIC, AIM support Scalability and Availability Built-in connector with external RPS (except 2801) 11
Cisco 1841 Router Secure, Concurrent Services for SMB and Small Branch Offices Entry Services and Performance Integration Integrated Ports USB Optional modular layer 2 switching Slots Onboard DSP Slots AIM Slots Form Factor Default/Max. Memory 1841 2 N/A 1 Desk 128MB / 384MB AIM,, and VWIC Modularity Wide range of connectivity options Supports existing WIC/VIC/VWIC interfaces; investment protection Flexibility and Availability Flexible and adaptable services deployment; entry-level availability features 12
What Are Concurrent Services? Security Services - IPSec VPN, Firewall, IPS, NAC Routing Services QOS, Control Plane Policing, Routing Protocols, ACLs Voice & IPC Services - H.323/MGCP Gateway, Call Manager Express, SRST, CUE Additional Services Content Networking, URL Filtering, Network Analysis, Switching 13
Platform Positioning With Services Enabled for IMIX traffic Platform 1841 2801 2811 2821 2851 3825 3845 Positioning with Services Enabled (IMIX traffic) Up to 1 T1/E1/xDSL Up to 1 T1/E1/xDSL Up to 2 T1/E1s/xDSL Up to 4 T1/E1s/xDSL Up to 6 T1/E1s/xDSL Up to ½ T3/E3 Up to 1 T3/E3 14
4 and 9 Port Etherswitch New Low density L2 switching Standards based POE (802.3af) support for IP phones, wireless access points and any 802.3af devices delivers 48V DC Power over a standard copper Ethernet cable Requires AC-IP system power supply Supports 802.1Q and 802.1P up to 15 VLANs Ports based authentication and access control by 802.1x Auto MDIX to automatically detect cable type Can stack with 16 and 36 ports Etherswitch NM 15
IP Phone Power Support and Etherswitch Stacking IP Phone Power AC or AC+IP power options Supports Cisco and.af Standards Chassis SKUs With/Without Up to 15W per switch port Chassis 1841 2801 CIP Support n/a 802.af Support n/a Etherswitch Density Up to 2 Etherswitches of any form factor per platform Need to be stacked through external cable for VLAN database consistency Power (W) n/a 120 Max. num switch ports 6 16 2811 /NM 160 24 2821 /NM 240 24 2851 /NM 360 44 3825 /NM 360 52 3845 /NM 360 72 16
Gigabit Ethernet New Offers Optical and Copper connectivity without NM occupancy Support in 2811, 2821, 2851 & 3800 Supports SX, LX/LH, ZX, CWDM and Copper Cisco SFPs for different distance, cost, existing infrastructure and future expansion requirements Gigabit EtherChannel for layer 3 link redundancy Jumbo frame up to 9576 bytes Hot insertion and removal of SFP for field replacement 1 supported on 2800 and up to 2 on 3800 Hi-Speed WAN Interface Card () Small Form Factor Pluggable (SFP) GE Transceiver 17
CEoIP Network Module Circuit Emulation = imitation of a physical communication link CEoIP imitates a physical communication link across an IP network Allows the transport of any type of communication over IP Ideal for TDM or Leased Line replacement and legacy network consolidation Headquarter Legacy CPE Two versions available: NM-CEM-4TE1 4 T1/E1 ports NM-CEM-4SER 4 serial ports Packet Network Leased Line Network Legacy CPE Branch Office Supports X.21, V.35, RS232/449/530/530A Ingress data accepted with no expectation of packet structure, cell format, etc. Data bits encapsulated into IP packets and routed to a similar port elsewhere in the network. This is a bit-transparent service. Data bits are not examined, interpreted, or manipulated at all. 18
Router-Integrated Services LAN Switching with Transparent Firewall Providing LAN segmentation with security in multiple branch sites can be costly and time consuming to deploy Solution: EtherSwitch (NM-ESW or -ESW) and IOS Transparent Firewall VLAN and transparent IOS FW enables segmented networks with secure access control Simplify subnets, no changing IP addresses on a device by device basis Configure the router and integrated switch without visiting the remote site Branch Office NM-ESW 16 and 36 ports of 10/100 Ethernet -ESW 4 and 9 port Hi-Speed WAN Interface Card WAN IOS FW How do you allow only some devices in? Wireless data base Cisco Integrated Services Router 16 Port NM-16ESW Head Quarters 19
Router-Integrated Services Application & Content Networking (NM-CE) Web applications, intranet portals, and business video consume expensive wide-area-network (WAN) bandwidth As companies extend Web applications and Internet access to employees, they need to manage what the Internet is used for and potential threats from un-trusted sites/content Solution: Cisco ACNS Web application acceleration: Siebel, SAP, intranet portals, file/software distribution Business video: Pre-load rich media; deliver RN, WMT, QT, MPEG, ASF, PDF, etc. Web content security: Internet and application access control and use policy enforcement URL filtering with Internet traffic logging and reporting NM-CE Internet Branch Users Data Center Cisco Integrated Services Router (IOS IPS option) 20
Router-Integrated Services Land Mobile Radio over IP Services (LMR) Radio-over-IP Transport IP transport eliminates leased-line or repeater costs for remote dispatch (e.g., Herndon to Raleigh, NC) Radio Interoperability with Phones, PCs, Phone/PC users can listen & talk with radio users across IP network no longer a closed user-group. Dispatchers can create user groups & interoperability in real time. (e.g., Mayor listens to police radio on mobile phone in an emergency) Interoperability between different Radio Systems Allows communication between multiple radio systems or agencies with push-to-talk conferencing (e.g., police, fire, medical, corporate security) Site 1 Radio System Land Mobile Radio Handsets (push-to-talk) LMR GW PSTN IVR & Conferencing Servers Dispatch App IP IP Phone with PTT application Mgmt / Admin PC Client with PTT LMR GW Site 2 Radio System Dispatcher PSTN 21
New IOS Software Architecture in 12.3 Simplified Image Selection SSH SSH SSH Advanced Security NAC Advanced Enterprise Services Advanced IP Services NAC SP Services IP Voice Enterprise Services SSH Enterprise Base NAC SSH SSH Simplifies feature set options (from 44 to 8) Advanced Security replaces: IP/FW/IDS IP FW IP Plus IPSec IP/FW/IDS/IPSec SSH are now in 6 of the 8 feature sets As you step up, all features below are inherited Additionally, 3 specialized feature sets Advanced Enterprise Services with SNA switching Integrated Voice/Video gateway, IP/IP gateway Integrated Voice/Video gateway with AES IP Base 22
System Level Resiliency: Warm Upgrade Extending High Availability Reduces downtime for planned upgrades for single RP platforms Warm Upgrade process Builds upon Warm Reload The new image does not have to support Warm Upgrade Normal Reloading without Cisco IOS Warm Upgrade Router loses packet forwarding for about 3.5 minutes With Cisco IOS Warm Upgrade Router loses packet forwarding for about 30 seconds 23
Netflow Enhancement Manageability NetFlow MIB with Top Talkers Provides critical information about Top N talkers and top conversations (NetFlow cache) Retrieves NetFlow information when traditional UDP export is impractical Users can configure and modify NetFlow using an SNMP interface Egress Netflow Extends Netflow tracking to flows exiting a Cisco IOS device Enables tracking of flows after features (ie: QoS, NAT) have made changes to the IP packet Netflow Egress New SNMP MIB Interface With Top Talkers IP PE IP or MPLS PE Servers IP Netflow Ingress Netflow Egress Netflow Egress 24
Traffic Monitoring Network Analysis (NM-NAM, NAM Application Software 3.2) NM-NAM network module for Integrated Services Routers Quick to deploy and easy to use with embedded web based Traffic Analyzer GUI Analyzes traffic flows for applications, hosts, conversations, and IP-based services such as QoS and VoIP Collects NetFlow Data Export to provide broad application-level visibility Tracks response times using the ART MIB to isolate application performance problems related to the network or to the server NM-NAM 25
Cisco Router and Security Device Manager (SDM 2.0) for Simplified Management New! Built-in GUI available for all 1800, 2800, 3800 series SDM 2.0 now includes QoS policy configuration Router and network resource monitoring Role-based access Implements NSA guidelines, ICSA, and TAC recommendations Industry leading router and security management tool for: VPN Firewall Routing LAN/WAN Interfaces WAN 26
Summary Higher Performance New ASIC, Bus design and processor boost performance for services Double services density Double memory defaults Increased Modularity Increased high speed slots up to 1.2 Gbps High density and larger form factor network modules Resiliency Redundant power option with online insertion and removal Increased environmental thresholds Enhanced Management Services Security Voice Content L2 Switching CEM Wireless Extended Services, Headroom and Investment Protection Integrated Services Routers 27