ASR 1000 Enterprise Sales Guide Corrine Li PSE, BN R&S Team 2012.03
目录 下一代广域网趋势 ASR1000产品简介 ASR 1000 企业销售场景及优势 7200 Migration 技术分析 企业广域网汇聚 数据中心互联 L3VPN汇聚 Broadband 安全防护
Next-Gen Enterprise WAN Architecture CPE as a Control Point in the NG Enterprise & MS Architecture Cloud Services Any Device Any Application NG WAN Capabilities Simplified Management Context Aware Cloud Connectors User Aware Application Awareness Security & Policy Technology Building Blocks Multi-Core Powered Virtualization Enabled Modular I/O Architecture Service Containers Platforms Routers Appliances Virtualized Software
Cisco Enterprise Routing Positioning S-Series Router: 小企业路由服务 ISR G1C: 高性价比ISR (为中国定制) 7600/ ASR9000 /C6500 Highest Capacity, Highly Available, Modular Services Modular software, Consistent services ISR G2: 高性能下一代ISR ASR 1001/2/4/6/13 (ESP-2.5/5/10/20/40G) ASR 1K: Carrier-class Multi-service WAN Aggregation, Internet Edge, DC Interconnect Performance, Scalability, Availability 40+ Gbps Sep 2012 EOS 5–20 Gbps 2.5–5 Gbps ISR Router G2 Series: 800,1921/1941,2901/2911/2921/2951,3925/3945/3925E/3945E G1C Series: 1841C, 2801C/2811C/2821C, 3825C/3845C ISR 3900E ASR 1K 7200/7300 Series High-Performance Embedded Services, Services Flexibility Hardware/Software Resiliency, Modular IOS XE S-Series VPN Router WRV210/RV110W/120W/Wudang… Small Branch VPN Router Secure, Reliable, Concurrent WAN Services Aggregation Branch Head Office/WAN Aggregation Routing System with Integrated Services—Security, Voice, Video, Wireless, WAN Optimization
BN路由销售场景及思科优势一览 WAN Data Center HQ Cloud & Services WAN SAP, Oracle,, ERP, CRM File Sharing Collaborations Video Conference Email Data Center HQ ASR1000 - 广域网汇聚、数据中心互联 H-QoS,BFD,Soft/Hard HA, WCCP, SBC/CUBE 安全功能:FW/NAT, GETVPN/DM VPN, AVC 数据中心互联特色功能:LISP, OTV, VPLS, NPS BN 服务: Medianet,EnergyWise,TrustSec Cloud & Services Enterprise Edge RWAN Aggregation ASR1K ASR1K WAN <专线, VPN, Internet> WAN High-End Branch / Remote Campus ISR G2 – 分支机构接入 H-QoS,BFD,PfR, LISP 全面的安全解决方案: FW,IPSec/SSL VPN(web/client),IPS, NAM, DPI,AVC 视频会议/统一通信/视频分发解决方案:语音网关,Video MCU,远程应急通信,视频转码/跟踪/监控 有线无线移动一体化 广域网加速WAAS,ECDS 虚拟服务SRE BN 服务-Medianet,EnergyWise,TrustSec Standard Branch Small/ Mobile Branch/ Kiosk Economic Branch ASR1K ISR 3900/2900/1900 ISR 800/1900 ISR 819 ISR G1C Key Programs & Technologies: One Firewall ISE WaaS AVC 2.0 SIP Gateway Video MCU DPI Cloud Connector eCDS vRouter MC5728V evdo 电信 HSPA+ 3G模块MC8700联通高速21.6M WCDMA WAAS ECDS 支持如下ISR模块: WAAS/ECDS /无线控制器 /交换机/服务器 3G-HSPA+/EVDO,802.11n 3G-HSPA+/EVDO, Hardened Design Data, Routing & Security 视频会议、 IP电话 E-learning VDI Microsoft RemoteFX /Citric/Vmware View 视频会议/IP电话/E-learning
ASR1K WAN应用场景 Unified Wan Services Solutions Secure WAN (FW/AVC) Internet Edge (FW/NAT/VPN/AVC) WAN Aggregation (FW/AVC/NAT) Data Center Interconnect (FW/NAT/AVC)
7200 to ASR1000 Migration 基础功能对比 7206 Migration tools End-of-Sale Product WAN/Regional Agg DCI ASR7200 Sep,2012 ASR1006-10G (2*ESP10) ASR1004-10G ASR1001-2.5G ASR1002-5G 基础功能对比 7206 ASR1001-2.5G,ASR1002-5G,ASR1004/6-10G 槽位 6 1,2,4,6个业务槽位;1,3,8,12 SPA IOS CLI Yes 转发平面 软件 硬件 集成服务(QoS, NBAR, Firewall, IPSec等) 需要PA卡 内置,无需额外硬件板卡 端口 -No 10GE and OC-48 POS , -Up to 6 PA - higher port density & speed - Up to 12 SPA with ASR1006 Oversubscription No (Bandwidth point limit) Allowed (with SIP ingress QoS) 转发/加密性能 1~2 Mpps/700Mbps加密 4Mpps,7.5Mpps,15 Mpps / 1.8G,4Gbps加密 控制/转发平面分离 No 软硬件冗余 Not available Modular Soft&ISSU Migration tools Easy Migrate compares existing config to ASR 1000
ASR 1000 企业应用场景及优势 一、企业广域网汇聚 用户实际需要的pps 一、企业广域网汇聚 QoS:支持五级H-QoS(层次化服务质量),支持多达128,000个硬件QoS队列,保障关键业 务按时交付 性能:支持高性能的多业务并行处理,多服务转发延迟仅几十微秒(其他厂家在毫秒级别) 高可靠性: 软硬件冗余(ASR 1006 & 1013引擎硬件冗余,RP引擎切换零丢包;ASR 1001&1002&1004软件冗余) ISSU(不中断服务软件升级):模块化的IOS XE 高性能BFD(双向转发检测) MLPPP可跨板卡绑定端口 高性能RR路由反射及FRR 链路优化:PfR,LISP SLA诊断及流量监控功能; 视频监控排错 (Medianet) 应用可视、控制及优化:NBAR2;高性能流量监控Netflow v9 高性能Stateful NAT64 VPN建网及链路备份: L2TPv3,GET VPN, DMVPN等 其他:丰富的可重用的高密度板卡(from 7600)等
ASR1000丰富的接口种类和数量 ——Ethernet / Serial / POS /ATM / Channelized… 1001 1002 1004 1006 1013 对应SPA # SPAs (single-height) 1 3 8 12 24 10GE 1-port 10GE GE 28 64 96 192 8-port GE SPA; 1RU and 2RU has 4 built-in GE ports FE 8-port FE STM-4 1-port STM4 POS STM-1 4+2* 32 48 4-port STM1 POS T3/E3 4+4T3* 4-port T3/E3 ChT3 @T1 112 336 896 1344 2688 4-port Channelized T3 ChT3 @DS0 1024 3069 8184 12276 24552 ChT1 / ChE1 @DS0 192/256 576/768 1536/2048 2304/3072 4608/6144 8-port Channelized T1/E1 V.35/X.21/EIA-232… 4 4-port Serial (12in1) ChSTM1 @ T3 / E3 3/3 9/9 24/24 36/36 72/72 1-port Channelized STM1 ChSTM1 @ T1 / E1 84/63 252/189 672/504 1008 / 756 2016 / 1512 ChSTM1 @ DS0 1023 STM-64 1-port OC192 (single-height) STM-16 4-port OC48 Cisco ASR 1001 Router also introduces the concept of integrated daughter cards (IDCs). • ASR1001: Base version without an IDC • ASR1001-2XOC3POS: Delivered with an IDC that provides 2 OC-3 Packet-over-SONET/SDH (PoS) • ASR1001-4XT3: Delivered with an IDC that provides 4 T3 ports (no E3 circuitry) • ASR1001-4X1GE: Delivered with an IDC that provides 4 GE ports 多扩展至16个GE • ASR1001-8CHT1E1: Delivered with an IDC that provides 8 channelized T1/E1 ports • ASR1001-HDD: Delivered with an integrated hard disk drive (HDD) * On ASR1001 with corresponding daughter card module Physical interface termination capacities only Assumes all SPA slots are filled with the respective SPA
ASR 1000 企业应用场景及优势 二、数据中心互联 -云计算/虚拟化Ready 二层互联:覆盖传输虚拟化 OTV (Overlay Transport Virtualization) 保障银行业务平台的实时迁移/负载均衡:名址分离网络协议 LISP(Location- ID Separation Protocol) 数据中心/云服务动态资源调度:NPS (Network Positioning System) 业界领先的芯片QFP技术高性能且节能 小RU节省机架空间 五级H-QoS(层次化服务质量),多达128,000个硬件QoS队列 多业务并行处理,转发延迟仅几十微秒 支持多种VPN建网及链路备份: L2TPv3,GET VPN, DMVPN等 高性能流量监控Netflow v9,应用可视化NBAR2 Zone based 高性能防火墙
ASR 1000 应用场景及优势 三、广域网L3VPN汇聚 -场景:企业、零售连锁、网点 支持L2TPv3,GET VPN, DMVPN,-》简化为Flex WAN QoS per VPN:支持五级H-QoS(层次化服务质量),支持多达128,000 个硬件QoS队列,基于VPN Tunnel的QoS策略控制,差分化服务 高性能加密:1.8G~11Gbps VPN
ASR 1000 企业应用场景及优势 四、Broadband接入 -ASR1000 as Intelligent Service Gateway (ISG) -行业:学校,彩票,医疗,其他PS,SP 支持PPPOE,IPOE,L2TP QoS for Broadband:支持五级H-QoS(层次化服务质量),支持多达128,000个硬件QoS队 列,基于用户的QoS策略控制,差分化服务 支持Radius及RADIUS Extensions (RFC 5176) and XML based (SGI(*)) Open Interfaces用于策略推送 IPv6 PPP & IP 支持用户身份识别(认证和地址分配),用户策略,用户内容/时长/流量计费 CPU保护:COPP,Subscriber Aware CoPP; 支持DHCP server及DHCP relay功能 应用可视、控制及优化:NBAR2; 高性能流量监控Netflow v9(4000会话/秒,硬件处理)
ASR 1000 应用场景及优势 五、安全防护 ——保护广域网出口/数据中心/Internet出口 2.5G~40Gbps 小RU 防火墙+NAT,高性能低延迟的多业务叠加 1.8G~11Gbps VPN:GETVPN/DMVPN/EZVPN -> Flex VPN简化配置 入侵检测IPS 应用流量控制AVC(NBAR, Netflow9) 数据包从二层起完全可见,可实现多种DPI及其它业务 支持TruseSec架构 AVC应用举例:对文件共享进行限速 Policing