H3C MSR 5600 Router
With the large-scale application of cloud services, wide area networks have undergone significant changes to support these applications. Users have put forward new demands for traditional routing devices, which are mainly reflected in the following aspects:
• Network performance requirements. On the basis of basic bandwidth, performance, and reliability requirements, pay more attention to network latency, jitter, and other network indicators to ensure the experience of business in cloud wide area networks
The security requirements of the network. With the further development of wireless communication access technology, the form of network access terminals has evolved from a single PC to diversified intelligent terminals PAD、 With the increasing popularity of various terminal access forms such as scanning guns and BYOD (Bring Your Own Devices), the security boundaries of the network have been broken, and customers have put forward higher requirements for the security of network devices
Network management requirements. Customers need simpler and more automated management methods to simplify the configuration, changes, management, and maintenance of network devices and applications, and to automate the deployment and management of network devices to improve efficiency and reduce management costs
Cloud support technology requirements. Network devices should have rich support technologies for cloud networks and cloud computing to meet the needs of cloud network applications and computing, such as virtualization, open architecture platforms, and other technologies
Faced with these opportunities and challenges, H3C has developed the MSR 5600 multi service router based on over a decade of in-depth understanding of enterprise and operator networks, as well as solid technical accumulation. The MSR 5600 can serve as an export router for small and medium-sized enterprises, as well as a branch access router for governments or enterprises. It can also be used as a business gateway for enterprise networks such as VPN, NAT, IPSec, etc. Together with other network devices from H3C, it provides comprehensive network solutions for users in industries such as government affairs, power, finance, taxation, railways, education, and large and medium-sized enterprises.
The MSR5600 router products include: MSR 56-80, MSR 56-60, and MSR 5620 models.
Product Features
Advanced technological support
Adopting H3C's mature Comware network operating system, it provides a more intelligent business scheduling and management mechanism, supports business modular loose coupling, and can dynamically load processes and patches
Excellent high-performance multi-core CPU processor, adopting non blocking switching architecture, greatly enhancing the concurrent processing capability of multiple businesses
• Support OAA open application architecture, cloud business platform CVK, VMWARE, wide area network optimization (WAN), Skype collaborative office, customer third-party business and other open applications
Dual master control, modular system architecture, achieving millisecond level switching of the main control board and process level backup
MSR56-60/56-80 supports redundant switching network boards
Integrate routing and switching matrix technology, separate routing and switching planes, and achieve 10 gigabit transmission rates
Multiple business collaboration engines, including data encryption engines and voice DSP processing engines, etc
Comprehensive SDN capabilities
Supports management and control protocols such as Telemetry and Netconf, which can be managed and controlled by H3C AD-WAN controllers and third-party controllers. Supports batch issuance of SRv6 Poilicy tunnels by SDN controllers.
• Supports segment routing, VxLAN, EVPN and other forwarding services, and can define multiple forwarding models to meet different business networking requirements
• Supports zero configuration deployment of URLs, USB drives, and DHCP to meet batch, low-cost, and fast start requirements
• Support DPI application recognition capability, accurately identify network traffic, achieve network traffic visualization, customization, and flexible scheduling
• Fully supports IPv6+&SRv6 functions, such as SRv6 BE、SRv6 TE Policy、EVPN L3VPN/L2VPN over SRv6/SRv6 TE Policy、SRv6 Policy Traffic statistics, SRv6 TI-LFA FRR, SRv6 TE Policy and SBFD linkage, EVPN E-tree over SRv6, SRv6 Policy bidirectional tunnel round-trip path consistency, SRv6 tail node protection, etc.
Powerful security features
• Business security
○ Message filtering function, supporting status filtering, MAC address filtering, IP and port number filtering, time period filtering, etc
○ Support real-time analysis of business traffic, etc
• Cybersecurity
Diversified VPN technologies, including IPsec, L2TP, GRE, ADVPN, MPLS VPN, and the combined use of multiple VPN technologies
○ Support security protection for router protocols, support OSPF/RIP/IS-IS/BGP dynamic routing protocol authentication, support IPSec encryption for OSPFv3/RIPng/IS-ISv6/BGP, and support rich routing policy control functions
Terminal access security
○ Integrated terminal access binding authentication, including EAD security check authentication, 802.1x authentication, terminal MAC address authentication, web-based Portal authentication, terminal access static binding, MAC automatic learning binding
ARP attack prevention, supporting fixed source MAC address, ARP packet attack prevention, address conflict detection and protection, ARP port speed limit, ARP detection, ARP source MAC address consistency check, ARP source suppression, ARP active confirmation mechanism, etc
• Device management security
○ Support role-based permission management, capable of resource allocation, user role correspondence, and two-dimensional permission allocation based on roles
○ Support control plane traffic restriction, support flow control and filtering based on protocol type, different queues, known protocol messages, specified protocol messages, etc
○ Remote security management, supporting SNPv3, SSH, TR069 remote management, etc
○ Management behavior control audit, supporting centralized authentication of AAA servers, execution of command line authorization, real-time reporting of operation records, etc
National Cryptography Office encryption algorithm
○ Support the SM1, SM2, SM3, and SM4 encryption algorithms proposed by the National Cryptography Administration
Refined business control
Through refined identification and control, achieve speed limit, bandwidth guarantee, filtering and other functions for application layer business, and guide network optimization through refined statistics
Supports Equivalent Link Load Sharing (ECMP) and Non Equivalent Link Load Sharing (UCMP), with UCMP supporting load sharing based on link bandwidth ratios;
Business intelligent routing utilizes technologies such as asymmetric link load sharing, traffic intelligent load sharing, and multi topology dynamic routing to fully utilize network links in different scenarios, supporting load sharing across multiple links and load sharing based on business and applications
• Support elastic sharing of network bandwidth based on multiple methods, including business based elastic sharing, user and user group based elastic sharing, link based elastic bandwidth sharing, and user based bandwidth limitation
Support SDN solutions and fully support wide area network SDN related technologies such as SegmentRouting, SRv6, BGP-LS, etc
Intelligent network management
• A comprehensive network management approach that supports command-line, SNMP, TR069, and other methods
• Support zero configuration deployment, enabling batch device setup in zero configuration mode, achieving zero setup of devices through wireless SMS, and automatically implementing device configuration rollback in case of misconfigured
Comware's built-in EAA function monitors internal events and status of system software and hardware components, collects on-site information when problems occur, and attempts to automatically repair them. It can also send on-site information to designated email addresses
• Support automatic boot of USB system, automatic import of USB configuration, and USB Console interface
high reliability
• Support redundant main control, with a fault switching time in milliseconds
The power supply realizes redundant backup, and in the event of a single power input failure or a single power supply failure, the power supply of the whole machine is not affected, and the output current and power remain unchanged
• Supports hot swapping of main control, interface module, fan, and power supply, and supports dual CF card backup
The physical separation of the control plane and forwarding plane maximizes the system's fault isolation capability and reliability
• Independent hardware processing module monitoring system, programmable devices support online upgrades and automatic loading, enhancing product reliability
• Link millisecond level fast fault detection technology (BFD), which can achieve linkage with static routing, RIP/OSPF/BGP/ISIS dynamic routing, VRRP, and interface backup
Network Service Quality Intelligent Detection Technology (NQA), which can achieve linkage with static routing, VRRP, and interface backup
• Support redundant backup and load sharing for multiple devices (VRRP/VRRPE)
• Support reliability technologies such as fast re routing and GR/NSR
Network virtualization
To reduce the complexity of user networking and improve management efficiency, we have taken the lead in supporting IRF2 (Second Generation Intelligent Elastic Architecture) technology on wide area network devices, virtualizing two physical devices into one logical device, greatly reducing the operation and maintenance costs of user networks, improving link bandwidth utilization and device utilization.
Support cross device Ethernet link aggregation technology to achieve load sharing and mutual backup of multiple uplink links, thereby improving the reliability of the entire network architecture and the utilization of link resources;
Cloud interconnection
Support scalable virtual local area network VxLAN technology to meet the requirements of data center layer 2 interconnection. The VxLAN solution has simple networking and low cost, requiring only the deployment of one or more VxLAN enabled devices at the edge of the site, without any changes to the enterprise network or service provider network; At the same time, VxLAN solutions also provide a combined solution of encrypting data with IPsec technology to improve the security and environmental friendliness of data center data transmission on public networks
Fully comply with RoHS standards
Advanced air duct isolation design, power and system air duct isolation design, unique double L-shaped air duct design, and two L-shaped air ducts for power and system air ducts improve space utilization
Fan level redundant backup design, multi-level fan speed regulation scheme, the system will determine the required fan speed based on the internal temperature of the product, minimizing fan noise and energy consumption to the greatest extent possible
Intelligent power-saving management, flexible definition of HMIM/main control board/forwarding board power-saving strategies, minimizing device energy consumption to the greatest extent possible