ASR 1000 Enterprise Sales Guide • Corrine Li • PSE, BN R&S Team • 2012.03 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 • 下一代广域网趋势 • ASR1000产品简介 • ASR 1000 企业销售场景及优势 • • • • • • 7200 Migration 技术分析 企业广域网汇聚 数据中心互联 L3VPN汇聚 Broadband 安全防护 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 Any Device Any Application Cloud Services NG WAN Capabilities Simplified Management User Aware Context Aware Cloud Connectors Application Awareness Security & Policy Multi-CoreTechnology Virtualization Modular I/O Building Blocks Powered Enabled Architecture Service Containers Platforms © 2010 Cisco and/or its affiliates. All rights reserved. Routers Appliances Virtualized Software Cisco Confidential 3 Performance, Scalability, Availability S-Series Router: 小企业路由服务 7600/ ASR9000 /C6500 ISR G1C: 高性价比ISR (为中国定制) ASR 1001/2/4/6/13 ISR G2: 高性能下一代ISR (ESP-2.5/5/10/20/40G) ASR 1K: Carrier-class Multi-service WAN Aggregation, Internet Edge, DC Interconnect Modular software, ISR Router S-Series VPN Router G2 Series: 800,1921/1941,2901/2911/2921/2951,3925/3945/392 5E/3945E G1C Series: 1841C, 2801C/2811C/2821C, 3825C/3845C WRV210/RV110W /120W/Wudang… Sep 2012 EOS ISR 3900E ASR 1K 7200/7300 Series 2.5–5 Gbps 5–20 Gbps 40+ Gbps High-Performance Embedded Services, Services Flexibility Hardware/Software Resiliency, Modular IOS XE Consistent services Highest Capacity, Highly Available, Modular Services Secure, Reliable, Concurrent WAN Services Aggregation Small Branch VPN Router Branch Head Office/WAN Aggregation © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4 Data Center HQ • H-QoS,BFD, • • • Email AVC LISP, OTV, VPLS, NPS SAP, Oracle,, ERP, CRM Video Conference File Sharing Collabora tions Enterprise Edge ASR1K WAN • • • • • • • ASR1K Cloud & Services WAN <专线, VPN, Internet> H-QoS,BFD,PfR, LISP High-End Branch / Remote Campus Standard Branch ASR1K client RWAN Aggregation NAM, DPI,AVC 视频会议/统一通信/视频 分发解决方案 ISR 3900/2900/1900 Small/ Mobile Branch/ Kiosk ISR 800/1900 WAAS Economic Branch ISR 819 ISR G1C ECDS 支持如下ISR模块: WAAS/ECDS /无线控制器 /交换机/服务器 3GHSPA+/EVDO,802.11 n 3G-HSPA+/EVDO,Hardened • Data,Routing& Security Design 有线无线移动一体化 广域网加速WAAS,ECDS 虚拟服务SRE 视频会议、 E-learning IP电话 © 2010 Cisco and/or its affiliates. All rights reserved. VDI Microsoft RemoteFX视频会议/IP电话 /Citric/Vmware View /E-learning Cisco Confidential 5 Unified Wan Services Solutions Secure WAN (FW/AVC) Internet Edge WAN Aggregation (FW/NAT/VPN/AVC) (FW/AVC/NAT) Data Center Interconnect (FW/NAT/AVC) © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 End-of-Sale Product WAN/Regional Agg DCI ASR7200 Sep,2012 ASR1006-10G (2*ESP10) ASR1004-10G ASR1001-2.5G ASR1002-5G ASR1006-10G (2*ESP10) 基础功能对比 7206 ASR1001-2.5G,ASR1002-5G,ASR1004/6-10G 槽位 6 1,2,4,6个业务槽位;1,3,8,12 SPA IOS CLI Yes Yes 转发平面 软件 硬件 集成服务(QoS, NBAR, Firewall, IPSec等) 需要PA卡 内置,无需额外硬件板卡 端口 -No 10GE and OC-48 POS , -Up to 6 PA - higher port density & speed - Up to 12 SPA with ASR1006 Oversubscription No (Bandwidth point limit) Allowed (with SIP ingress QoS) 转发/加密性能 1~2 Mpps/700Mbps加密 控制/转发平面分离 No Yes 软硬件冗余 Not available Yes Modular Soft&ISSU No Yes 4Mpps,7.5Mpps,15 Mpps / 1.8G,4Gbps加密 Migration tools Easy Migrate compares existing config to ASR 1000 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7 一、企业广域网汇聚 70 60 50 40 30 20 10 0 用户实际需要的pps ASR1000 Vendor Y 基本转发 基本业务 多业务叠加 • QoS:支持五级H-QoS(层次化服务质量),支持多达128,000个硬件QoS队列,保障关键业 务按时交付 • 性能:支持高性能的多业务并行处理,多服务转发延迟仅几十微秒(其他厂家在毫秒级 别) • 高可靠性: • 软硬件冗余(ASR 1006 & 1013引擎硬件冗余,RP引擎切换零丢包;ASR 1001&1002&1004软件冗余) • ISSU(不中断服务软件升级):模块化的IOS XE • 高性能BFD(双向转发检测) • MLPPP可跨板卡绑定端口 • 高性能RR路由反射及FRR • 链路优化:PfR,LISP • SLA诊断及流量监控功能; 视频监控排错 (Medianet) • 应用可视、控制及优化:NBAR2;高性能流量监控Netflow v9 • 高性能Stateful NAT64 • VPN建网及链路备份: L2TPv3,GET VPN, DMVPN等 • 其他:丰富的可重用的高密度板卡(from 7600)等 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 ——Ethernet / Serial / POS /ATM / Channelized… 对应SPA 1001 1002 1004 1006 1013 1 3 8 12 24 1 3 8 12 24 1-port 10GE GE 12 28 64 96 192 8-port GE SPA; 1RU and 2RU has 4 built-in GE ports FE 8 24 64 96 192 8-port FE STM-4 1 3 8 12 24 1-port STM4 POS STM-1 4+2* 12 32 48 96 4-port STM1 POS T3/E3 4+4T3* 12 32 48 96 4-port T3/E3 112 336 896 1344 2688 4-port Channelized T3 1024 3069 8184 12276 24552 4-port Channelized T3 2304/3072 4608/6144 8-port Channelized T1/E1 1-port Channelized STM1 # SPAs (singleheight) 10GE ChT3 @T1 Cisco ASR 1001 Router also introduces the concept of integrated daughter cards (IDCs). ChT3 @DS0 version without ChT1•/ ASR1001: ChE1 @DS0Base192/256 576/768an IDC 1536/2048 • ASR1001-2XOC3POS: Delivered with an IDC that provides 2 OC-3 Packet-over-SONET/SDH (PoS) 4 12 32 48 96 4-port Serial (12in1) • ASR1001-4XT3: Delivered with an IDC that provides 4 T3 ports (no E3 circuitry) ChSTM1 @ T3 / E3 3/3 24/24 36/364 GE ports 72/72多扩展至16个GE 1-port Channelized STM1 • ASR1001-4X1GE: Delivered9/9 with an IDC that provides • ASR1001-8CHT1E1: Delivered with an IDC that provides 8 channelized T1/E1 ports 2016 / ChSTM1 @ T1 / E1 84/63 252/189 672/504 1008 / 756 1-port Channelized STM1 • ASR1001-HDD: Delivered with an integrated hard disk drive (HDD) 1512 V.35/X.21/EIA-232… ChSTM1 @ DS0 1023 3069 8184 12276 24552 STM-64 1 3 8 12 24 1-port OC192 (single-height) STM-16 4 12 32 48 96 4-port OC48 * On ASR1001 with corresponding daughter card module Physical interface termination capacities only Assumes all SPA slots are filled with the respective SPA © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 二、数据中心互联 -云计算/虚拟化Ready • 二层互联:覆盖传输虚拟化 OTV (Overlay Transport Virtualization) • 保障银行业务平台的实时迁移/负载均衡:名址分离网络协议 LISP(LocationID Separation Protocol) • 数据中心/云服务动态资源调度:NPS (Network Positioning System) • 业界领先的芯片QFP技术高性能且节能 • 小RU节省机架空间 • 五级H-QoS(层次化服务质量),多达128,000个硬件QoS队列 • 多业务并行处理,转发延迟仅几十微秒 • 支持多种VPN建网及链路备份: L2TPv3,GET VPN, DMVPN等 • 高性能流量监控Netflow v9,应用可视化NBAR2 • Zone based 高性能防火墙 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 10 三、广域网L3VPN汇聚 -场景:企业、零售连锁、网点 • 支持L2TPv3,GET VPN, DMVPN,-》简化为Flex WAN • QoS per VPN:支持五级H-QoS(层次化服务质量),支持多达128,000 个硬件QoS队列,基于VPN Tunnel的QoS策略控制,差分化服务 • 高性能加密:1.8G~11Gbps VPN © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11 四、Broadband接入 -ASR1000 as Intelligent Service Gateway (ISG) -行业:学校,彩票,医疗,其他PS,SP • 支持PPPOE,IPOE,L2TP • QoS for Broadband:支持五级H-QoS(层次化服务质量),支持多达128,000个硬件QoS队 列,基于用户的QoS策略控制,差分化服务 • 支持Radius及RADIUS Extensions (RFC 5176) and XML based (SGI(*)) Open Interfaces用于策略推送 • IPv6 PPP & IP • 支持用户身份识别(认证和地址分配),用户策略,用户内容/时长/流量计费 • CPU保护:COPP,Subscriber Aware CoPP; 支持DHCP server及DHCP relay功能 • 应用可视、控制及优化:NBAR2; 高性能流量监控Netflow v9(4000会话/秒,硬件处理) © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 12 五、安全防护 ——保护广域网出口/数据中心/Internet出口 • 2.5G~40Gbps 小RU 防火墙+NAT,高性能低延迟的多业务叠加 • 1.8G~11Gbps VPN:GETVPN/DMVPN/EZVPN -> Flex VPN简化配置 • 入侵检测IPS • 应用流量控制AVC(NBAR, Netflow9) • 数据包从二层起完全可见,可实现多种DPI及其它业务 • 支持TruseSec架构 AVC应用举例:对文件共享进行限速 Policing © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 13 Thank you. © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 14