h3c sr6600 Series Ds
h3c sr6600 Series Ds
h3c sr6600 Series Ds
H3C SR6600
Overview
The H3C SR6600 series of open multi-core routers are high-end processor, the SR6600 excels in high-performance, easy
multi-service routers developed by H3C for carrier, government, utilities, programmability, and flexible adaptation to L4-L7 services. The
finance, education, and enterprise environments. The SR6600 features multi-core multi-thread CPU provides the SR6600 with
superior forwarding performance, high service processing flexibility, and high-performance and high flexibility. Additionally, due to the CPU’s
high-density access capability. easy programmability and operation, the SR6600 is able to quickly
respond and adapt to new services, meeting the requirements of
Being the first router in the industry to adopt the multi-core multi-thread
managing application-layer services on routers. In the system
CPU architecture, the SR6600 employs a new hardware platform and
architecture design phase, the SR6600 emphasizes hardware
service-oriented design to offer new solutions for service
acceleration for applications and security services so that the multi-core
distribution/access and enterprise gateways, comprehensively meeting
CPU can use its precious resources for processing core L4-L7 services.
the challenges of future service expansion and application diversity. It
Following the development of traditional high-end and
conforms to both current and future models of enterprise IT construction.
business-oriented routers, multi-core multi-thread CPUs have become
The SR6604/SR6608/SR6616 employ two routing processing units
the most critical technology; the foundations for developing high-end
(RPUs), redundant power supply modules (PSUs), distributed modular
business-oriented routers in the future.
architecture, and a high-capacity high-speed backboard, guaranteeing
Advanced Fully Distributed Service Architecture
processing of distributed services at wirespeed. Additionally, the
SR6604/SR6608/SR6616 employ an advanced multi-core multi-thread With a multi-core multi-thread CPU and fully distributed architecture, the
CPU for data forwarding and service processing, inheriting high service SR6604/SR6608/SR6616 uses separate engines for routing and
flexibility from the CPU while ensuring high-performance service service processes. Moreover, the control plane and the data plane of an
processing. engine are separated from each other; they guarantee zero interference
between service and control applications when the system operates at
Currently, the SR6600 series consists of the SR6602, SR6604, SR6608,
high speed; no packet losses at an active/standby switchover; and no
and SR6616. The SR6602 is designed as a high-performance external
service interruption. Each service engine independently processes
gateway and a distribution/access device for carrier and industry
distributed services such as NAT, IPSec, and NetStream, enhancing the
networks. The SR6604 and the SR6608 can work at the
integrated service capability of the system and eliminating the high cost
distribution/access layer of carrier networks or large enterprise
of traditional high-end routers that employ specific service cards.
networks, at the distribution layer and core layer of medium-sized
OAA Design Concept
enterprise networks, and at the core layer of medium- and small-sized
enterprise networks. The SR6616 can work at the core layer of carrier The SR6600 inherits H3C’s Open Application Architecture (OAA) as its
networks or large enterprise networks, and as core routers for design concept, which satisfies the requirements of subsequent L4-L7
medium-sized MAN (Metropolitan Area Network) networks. service customization and upgrade, achieves the incremental increase
in service value required of high-end routers, and accelerates the
development of IP networks toward intelligent networks.
Features
High-Density Narrowband Convergence and Access Capabilities
Industry’s First Multi-Core High-End Router
The SR6604/SR6608/SR6616 provides high-density OC-3/STM-1
As the first high-end router that employs a multi-core multi-thread channelized POS interfaces that can be channelized into E1, T1 or DS0
2 H3C SR6600
SWITCHING
channels. With the high-density E1 and DS0 wire-speed convergence L2TP, GRE, and security features such as firewall, ASPF, and URPF. It
capability, the SR6604/SR6608/SR6616 has achieved industry-leading provides the NetStream traffic analysis function to collect statistics for
standards in terms of narrowband access capability, density, and different streams, allowing you to manage network traffic through a
performance. visualized interface and perform network planning, security supervision,
and traffic accounting.
With four OC-3/STM-1 channelized POS interfaces that can be
channelized into E1s, T1s or DS0s, the SR6602 supports convergence The SR6604/SR6608/SR6616 implements distributed processing of the
and access of high-density wire-speed E1 and DS0 links. services mentioned above, effectively enhancing service processing
capabilities and system reliability.
PPP Multi-link Bundling
Powerful Routing Capacity
The SR6600 provides high-speed CPOS modules to allow for hardware The SR6600 supports IPv4/IPv6 static routing and dynamic routing
MP. When the SR6600 serves as an aggregation node for a WAN, you protocols, including RIP/RIPng, OSPF/OSPFv3, IS-IS/IS-ISv6, and
can implement PPP multi-link bundling on the downlink E1 or T1 BGP/BGP4+.
through CPOS modules. You can also implement reassembly and
In addition, the SR6600 supports diversified policy-based routing and
fragmentation of MP packets without affecting traffic forwarding.
routing policies, allowing for flexible control and scheduling of network
The SR6602 can implement MP bundling of up to 10 12E1s or 14 12T1s traffic and thus meeting different routing requirements of enterprise
at wire speed; the SR6604 can implement MP bundling of up to 20 networks and carrier networks.
12E1s or 28 12T1s at wire speed; the SR6608 can implement MP
Powerful MPLS
bundling of up to 40 12E1s or 56 12T1s at wire speed; the SR6616 can
The SR6600 supports MPLS, including L2 VPN, L3 VPN services, and
implement MP bundling of up to 80 12E1s or 112 12T1s at wire speed.
MPLS TE. It is able to work together with other H3C network devices to
Consequently, the SR6600 is able to provide sufficient bandwidth for
construct a powerful MPLS network, providing a high-performance,
narrowband aggregation networks.
secure and hierarchical MPLS VPN solution.
Industry-Leading Encryption
Carrier-Class Reliability
The SR6604/SR6608/SR6616 has a built-in hardware encryption
u The SR6600 has inherited the distributed architecture of high-end
engine for FIP-100/200 to provide high-performance distributed IPSec
routers and uses a separate control plane and data plane to avoid
encryption, delivering powerful data encryption capability while requiring
interference between services and control applications when the
no additional investment. This ensures data security in both WANs and
system operates in high speed. This ensures no packet losses
intranets.
during active/standby switchover and no service interruption.
Similarly, the SR6602 also has a built-in hardware encryption engine to u The SR6600 employs 1+1 redundancy for its key components,
provide high-performance IPSec encryption, ensuring data security in such as the RPU, PSU, and management bus, to implement
both WANs and intranets. state-based switchover. In addition, the SR6600 supports
Secure and Flexible Device Management The SR6600 supports external CF card, host USB and device USB
The SR6600 supports hierarchical user management and password interfaces, meeting the demands for increased storage capacity and
protection, packet filtering, attack prevention, and control panel rate allowing device management through the interfaces as required.
Specifications
Chassis Standard 19-inch rack with a centralized architecture Standard 19-inch rack with a distributed architecture
LPU slots -- 2 4 8
HIM 2 4 8 16
Interface module
slot
MIM 2 8 16 32
Console interface 1
AUX interface 1
USB interface 2
l Static routing
l Dynamic routing protocols: RIPv1/v2, OSPFv2, BGP, IS-IS
IP routing
l Route recursion
l Routing policy
l DHCP Server/Relay/Client
l DNS Client
l NTP Server/Client
Network protocols l Telnet Server/Client
l TFTP Client
l FTP Server/Client
l UDP Helper
l Basic functions: IPv6 ND, IPv6 PMTU, dual-stack forwarding, IPv6 ACL
l IPv6 tunnel: manually configured IPv6 tunnel, configured IPv6 over IPv4 tunnel, automatic IPv6 over IPv4 tunnel, 6to4 tunnel, ISATAP
tunnel
IPv6
l Static routing
l Dynamic routing protocols: RIPng, OSPFv3, IS-ISv6, BGP4+
l IPv6 multicast:MLDv1/v2,PIM-DM,PIM-SM,PIM-SSM
4 H3C SR6600
SWITCHING
l Traffic classification: based on port, MAC address, IP address, IP priority, DSCP priority, TCP/UDP port number, and protocol type
l Traffic policing: CAR rate limiting, granularity configurable
l Rate limiting based on source/destination address (supporting subnet-based rate limiting)
l GTS
l Priority Mark/Remark
QoS
l Queue scheduling mechanism: FIFO, PQ, CQ, WFQ, RTPQ, CBWFQ
l Congestion avoidance algorithm: Tail-Drop, WRED
l LR
l MPLS QoS
l IPv6 QoS
l ACL
l ACL acceleration
l Time-based access control
l Packet filter firewall
l Stateful firewall ASPF
l TCP attack prevention on local host
l Control panel rate limiting
l Virtual fragment reassembly
l URPF
l Web filtering
Security
l Hierarchical user management and password protection
l AAA
l RADIUS
l HWTACACS
l Portal
l PKI Certification
l SSH v1.5/2.0
l RSA
l IPSec, IPSec multi-instance, IKE
l P2P rate limiting (only supported on the SR6602)
l L3VPN: Inter-domain MPLS VPN (OptionA/B/C), nested MPLS VPN, Hierarchy PE (HoPE), CE dual homing, MCE, multi-role host, GRE
tunnel
MPLS l L2VPN: Martini, Kompella, CCC, and SVC
l MPLS TE, RSVP TE
l Multicast VPN
l VRRP/VRRPv3
l MPLS TE FRR
l IGP fast routing convergence
l BFD: supporting collaboration with Static route/ RIP/OSPF/ISIS/ BGP/ VRRP/TE FRR
Reliability l GR: OSFP/BGP/IS-IS/ LDP/RSVP
l Software hotfix
Supporting hot-swapping of
Supporting active/standby switchover and hot-swapping of RPU, LPU, Power module, and fan tray
interface cards
l FAT format
l CF card
File systems
l USB storage device
l Dual image
l UL 60950-1
l CAN/CSA C22.2 No 60950-1
l IEC 60950-1
l EN 60950-1/A11
Safety Compliance l AS/NZS 60950
l EN 60825-1
l EN 60825-2
l FDA 21 CFR Subchapter J
l GB 4943
Networking Applications
On such layered networks as the level-2 network in the finance industry, the power dispatching and provincial backbone networks, and provincial
finance and taxation backbone networks, the prefectural convergence router adopts cPOS to perform convergence. Such applications are popular.
The SR6608 is highly suitable for prefectural router on those types of networks, thanks to its powerful cPOS convergence capability. In addition to the
powerful cPOS convergence capability, the SR6608 can also provide carrier-class reliable features at the hardware, software and other layers,
ensuring high networking reliability. In the current networking scheme:
u The SR6608 connects to the core layer equipment with the 155M POS and N*E1 links. At the same time, it connects to the two routers in the
6 H3C SR6600
SWITCHING
working/protection mode at the core layer in the dual uplink mode, ensuring connection reliability.
u The cPOS interface of the SR6608 can be channelized to the interfaces of the E1, T1, DS0 and other rates. In that regard, it can access routers
or connect to the equipment in the uplink direction with the interfaces of different rates mentioned above. The access routers with high
requirements on uplink bandwidth can adopt the n*E1 mode (that is, MP binding).
u Software features can be flexibly selected according to the actual needs. The static route, RIP, OSPF and other routing protocols can be applied
between the access router and the SR6608. Usually, OSPF or BGP is deployed between the SR6608 and the core router. The MPLS VPN can
be directly deployed on the networking. The SR6608 supports ideal MPLS features and can work as PE or P equipment.
u The convergence router requires high hardware and software reliability. In terms of hardware, the SR6608 provides dual main control systems,
dual power supplies and fan redundancy. In terms of software, it can provide VRRP, BFD, GR at various protocol levels, IGP fast convergence,
FRR and other software reliability technologies. The reliability technologies mentioned above can be selected in the networking schemes
according to the actual needs.
u Concerning QoS deployment, the Diffserv mode is usually adopted. The access router differentiates different services carried, and marks
different DSCP priorities on different services. The convergence router performs flow classification according to the DSCP value, providing
different bandwidth guarantees to packets of different priorities. In the case that MPLS VPN is applied in the networking scheme, the mapping
between DSCP of the IP packets and the EXP of the MPLS packets is implemented on the PE router. At the time of MPLS forwarding, different
EXPs perform different bandwidth guarantees.
This networking scheme is a typical networking application in which the SR6608 works as the core equipment of the enterprise network. Internally, the
SR6608 connects to the LAN and servers of the enterprise with its high-density GE interface. Externally, it connects to the branch networks at different
layers with its diverse WAN interfaces (from DS0 to 155Mbps interfaces). At the same time, it can select one of the multiple security access modes
(L2tp, GRE, IPSec, etc.) to ensure the security of the access to the branch networks. In the current networking scheme:
u Inside the enterprise network, the SR6608 connects to the LAN and server farms with its high-density GE interface, ensuring the high-speed
interconnection of the intranet. Outside the enterprise network, the SR6608 connects to the branch networks at different layers with its diverse
WAN interfaces. The interface rates range from DS0 (64Kbps) up to 155M POS.
u The branch networks that adopt non dedicated line can apply L2tp, GRE, IPSec and other secure access modes. On the precondition of
high-speed interconnection, such modes guarantee that the branch networks provide higher security guarantee.
u On the precondition of the secure access to the branch networks, the SR6608 can also operate dynamic or static routing protocols between the
access routers of the branch networks, ensuring the interworking of the services of different branch networks.
7 H3C SR6600
SWITCHING
This networking scheme is a typical network application that the SR6608 or the SR6602 routers work as the egress routers on the campus network. To
ensure the high reliability of the egress routers, two SR6608 or SR6602 routers are applied in the working/protection mode. Or the load sharing is
implemented between the two SR6608 or SR6602 routers through the configuration of policy routing. Inside the campus network, two SR6608 or
SR6602 routers and two S9500 core routers connect to each other in the Full-Mesh mode, implementing load sharing and link backup between the
core switch and the egress router. In the current networking scheme:
u Two SR6608 or SR6602 routers connect to the egresses of the education network and the carrier. The load sharing or link backup function can
be implemented between the two egresses according to the actual needs.
u Two SR6608 or SR6602 routers and two S9500 core routers of the campus network connect to each other in the Full-Mesh mode, implementing
load sharing and link backup between the core switch and the egress router.
u The SR6608 or SR6602 router can first improve the performance of the NAT. In addition, it can support diverse NAT ALG features, ensuring that
different applications inside the campus network can penetrate the egress router without any blocking. As a result, the ideal NAT application
solution is implemented.
This networking scheme is the typical networking application in which the SR6602 router works the IPSEC VPN gateway. The SR6602 provides
powerful hardware encryption capability. At the same time, it also provides powerful forwarding capability. It is highly suitable for IPSEC VPN gateway.
With the more and more extensive applications of the MPLS VPN and the traditional IP VPN on enterprise networks, the user poses stronger
requirements on the fusion of the two VPNs. The VPE technology comes into being in this context. The SR66 router supports the VPE to perfectly fuse
the IP VPN and the MPLS VPN. In the current networking scheme:
u The SR6602 connects to the branch access network points through the Internet. To ensure the security of the access at the branch network
points, it is necessary to establish IPSec tunnel connection with each branch network points.
u The IPSec tunnel connection in the uplink direction of the branch network point is terminated on the SR6602. Usually, IP interconnection is
implemented between the SR6602 and the backbone network. Or MPLS VPN can also be operated between the SR6602 and the backbone
network.
u To connect the IPSec VPN and the MPLS VPN directly, the VPE technology can be applied. In that case, the SR6602 can access the branch
network points directly to the relevant VPNs, implementing the seamless integration of the two VPNs.
This networking scheme is a typical networking application in which the SR6608 is applied to present the MPLS VPN network solution. The SR6608
provides L2VPN, L3VPN, MPLS TE and other ideal MPLS functions, maximally satisfying the networking requirements on PE equipment on the MPLS
network by the enterprises or operators. In the current networking scheme:
Global Services offers the resources and talents of a major corporation Global support with a personalized, local focus in the local language
plus more than two decades of experience in resolving network helps drive productivity and minimize expenses. Because we understand
challenges and delivering business benefits to enterprises around the both the technology and the business, we’re the partner you need to
world. remain strong and competitive.
This service provides comprehensive on-site support and includes advance hardware replacement, expedited telephone
GuardianSM Maintenance Service technical support and software upgrades
Note: May not be available in some countries
This service provides speedy access to H3C shipment of advance hardware replacements (including a four-hour option),
ExpressSM Maintenance Service
expedited telephone technical support and software upgrades
Network Health Check Includes traffic monitoring, utilization analysis, problem identification, and asset deployment recommendations
Experts set up and configure equipment and integrate technologies to maximize functionality and minimize business disruption
Network Installation and Implementation Services
For large and complex sites, implementation services include personalized configuration, project management, extended
testing and coaching on network administration
Education and Training Self-paced and instructor-led technology and product courses, plus certification programs
Product Warranty
The H3C SR6600 series have a 1-year hardware warranty that includes the power supply and fan assembly.
Order Information
Hosts
RT-SR6608-OVS+2 RPE-X1+2 SR6608 Router Host(Overseas Version) Bundled with two RPE-X1 and two LSQM2AC650
0150A12A AC-H3 modules(0235A32X+2*0231A761+2*0231A81J)
RT-SR6604-OVS+2 RPE-X1+2 SR6604 Router Host(Overseas Version) Bundled with two RPE-X1 and two LSQM2AC650
0150A12C AC-H3 modules(0235A37X+2*0231A761+2*0231A81J)
Power supply
0213A02R AC-RPS800-A Redundant Power Supply RPS800-A,-90Vac-264Vac input-12V,17.25A;-54V,12A output (only for SR6602)
Software Options
Service Engine
0231A762 RT-FIP-100-H3 Flexible Interface Platform 100,4 MIM Slot,2 10/100/1000M WAN Port(RJ45 and SFP Combo)
0231A763 RT-FIP-200-H3 Flexible Interface Platform 200,2 HIM Slot,2 10/100/1000M WAN Port(RJ45 and SFP Combo)
HIM sub-card
Service Modules
Cable
04026813 CAB-E1/75-120 Convert Refiner Converter Cable (With BNC Connector Jack)
Optical Modules
0231A03X SFP-2.5G-LX-SM1310 OC-48c (2.5G) POS SFP Module, Single Mode (1310nm, 2km, LC)
0231A03Y SFP-2.5G-LH15-SM1310 OC-48c (2.5G) POS SFP Module, Single Mode (1310nm, 15km, LC)
0231A04A SFP-2.5G-LH40-SM1310 OC-48c (2.5G) POS SFP Module, Single Mode (1310nm, 40km, LC)
0231A04B SFP-2.5G-LH80-SM1550 OC-48c (2.5G) POS SFP Module, Single Mode (1550nm, 80km, LC)
0231A563 SFP-GE-LX-SM1310-A 1000BASE-LX SFP Transceiver, Single Mode (1310nm, 10km, LC)
02312170 SFP-GE-LH40-SM1310 1000BASE-LH40 SFP Transceiver, Single Mode (1310nm, 40km, LC)
02312172 SFP-GE-LH40-SM1550 1000BASE-LH40 SFP Transceiver, Single Mode (1550nm, 40km, LC)
02312173 SFP-GE-LH70-SM1550 1000BASE-LH70 SFP Transceiver, Single Mode (1550nm, 70km, LC)
0231A321 SFP-GE-LH100-SM1550 1000BASE-LH100 SFP Transceiver, Single Mode (1550nm, 100km, LC)
0231A564 SFP-FE-LX-SM1310-A 100BASE-LX SFP Transceiver, Single Mode (1310nm, 15km, LC)
0231A089 SFP-FE-LH40-SM1310 100BASE-LH40 SFP Transceiver, Single Mode (1310nm, 40km, LC)
0231A090 SFP-FE-LH80-SM1550 100BASE-LH80 SFP Transceiver, Single Mode (1550nm, 80km, LC)
0231A11U SFP-GE-LX-SM1310-BIDI 1000BASE-LX BIDI SFP Transceiver, Single Mode (TX1310/RX1490, 10km, LC)
0231A11V SFP-GE-LX-SM1490-BIDI 1000BASE-LX BIDI SFP Transceiver, Single Mode (TX1490/RX1310, 10km, LC)
Copyright © 2009 H3C Technologies, Co., Ltd. All rights reserved.H3Cand the H3C logo are in various countries worldwide registered trademarks of H3C
Technologies Co., Ltd., a subsidiary of 3Com Corporation. TippingPoint is in various countries worldwide a registered trademark of TippingPoint
Technologies, Inc., a subsidiary of 3Com Corporation. All other company and product names may be trademarks of their respective companies. While every
effort is made to ensure the information given is accurate, neither H3C or 3Com accepts liability for any errors or mistakes which may arise. All specifications
are subject to change without notice. 10/2009