Router Cisco C8300-2N2S-4T2X Catalyst 8300 Series Edge Platform, 2 x 10GE SFP+ + 4 x 1GE (Layer 3), 18,8 Gbps IPsec
Cisco C8300-2N2S-4T2X là router biên thuộc dòng Catalyst 8300 Series Edge Platform, sản phẩm Cisco chỉ định để thay cho ISR 4351, ISR 4431, ISR 4451-X, ISR 4461, ASR 1001-X/1002-X đã ngừng bán. Máy dùng CPU 8 nhân, 8 GB DRAM (nâng tối đa 32 GB), có 2 x 10GE SFP+ + 4 x 1GE (Layer 3) tích hợp và 2 x SM, 2 x NIM, 1 x PIM (5G/LTE), mã hoá IPsec tới 18,8 Gbps. Phần mềm IOS XE cho phép chạy SD-WAN hoặc định tuyến truyền thống (SD-Routing) trên cùng một máy, quản trị tập trung bằng Catalyst SD-WAN Manager. Phù hợp trụ sở và trung tâm dữ liệu làm hub SD-WAN vài trăm chi nhánh, cần nhiều khe module thoại và WAN. Thiết Bị Mạng Cisco cung cấp hàng chính hãng, đủ CO/CQ, bảo hành theo chính sách Cisco Việt Nam.
So sánh các model Catalyst 8200 và 8300
| Model | Kích thước | Cổng WAN tích hợp | Khe mở rộng | IPsec (1400 B) | Đường hầm SD-WAN |
|---|---|---|---|---|---|
| C8200L-1N-4T | 1RU | 4 x 1GE | 1 NIM, 1 PIM | 500 Mbps | 1.500 |
| C8200-1N-4T | 1RU | 4 x 1GE | 1 NIM, 1 PIM | 1 Gbps | 2.500 |
| C8300-1N1S-6T | 1RU | 6 x 1GE | 1 SM, 1 NIM, 1 PIM | 2 Gbps | 6.000 |
| C8300-1N1S-4T2X | 1RU | 2 x 10GE + 4 x 1GE | 1 SM, 1 NIM, 1 PIM | 17 Gbps | 6.000 |
| C8300-2N2S-4T2X | 2RU | 2 x 10GE + 4 x 1GE | 2 SM, 2 NIM, 1 PIM | 18,8 Gbps | 6.000 |
Số liệu theo datasheet Cisco Catalyst 8200 và 8300; thông lượng IPsec đo với gói 1400 byte, có giấy phép DNA Advantage và HSEC.
Điểm nổi bật của Cisco C8300-2N2S-4T2X
- 2 x 10GE SFP+ + 4 x 1GE (Layer 3) tích hợp, thêm module NIM và SM khi cần cổng switch, thoại, serial hay 5G.
- IPsec 18,8 Gbps với bộ tăng tốc mã hoá phần cứng, 6.000 đường hầm SD-WAN.
- Một máy chạy được cả SD-WAN lẫn định tuyến cổ điển, chuyển đổi bằng phần mềm, không phải mua lại thiết bị.
- Tích hợp bảo mật tại chỗ: tường lửa ứng dụng, IPS Snort, lọc URL, AMP; nối SASE (Cisco Secure Access, Umbrella) khi cần.
- Dùng lại phần lớn module NIM của ISR 4000, giảm chi phí khi nâng cấp.
Sản phẩm dùng kèm
Khi triển khai Cisco C8300-2N2S-4T2X, khách hàng thường đặt cùng Cisco C8300-1N1S-4T2X, module Cisco SM-X-4X1G-1X10G, module Cisco NIM-2CE1T1-PRI, module quang Cisco SFP-10G-SR-S và switch core Cisco Catalyst C9500-24Y4C. Thiết Bị Mạng Cisco tư vấn cấu hình trọn bộ và báo giá chung trong một đơn hàng.
Giá bán và đặt hàng
Cisco C8300-2N2S-4T2X bán theo báo giá dự án. Gọi hotline hoặc gửi yêu cầu để nhận giá, thời gian giao hàng và cấu hình giấy phép phù hợp. Hàng chính hãng Cisco, đủ CO/CQ, xuất hoá đơn VAT, bảo hành theo chính sách Cisco Việt Nam.
Thông số kỹ thuật Cisco C8300-2N2S-4T2X
| Mã sản phẩm | C8300-2N2S-4T2X |
|---|---|
| Dòng | Cisco Catalyst 8300 Series Edge Platform |
| Kích thước | 2RU |
| CPU | CPU 8 nhân |
| Bộ nhớ DRAM | 8 GB DRAM (nâng tối đa 32 GB) |
| Lưu trữ | M.2 SSD 16 GB (nâng tới 600 GB NVMe) |
| Cổng WAN/LAN tích hợp | 2 x 10GE SFP+ + 4 x 1GE (Layer 3) |
| Khe mở rộng | 2 x SM, 2 x NIM, 1 x PIM (5G/LTE) |
| Thông lượng IPsec (SD-WAN) | 18,8 Gbps (gói 1400 B) |
| Thông lượng IPsec gói IMIX | 7,6 Gbps |
| Số đường hầm SD-WAN tối đa | 6.000 |
| Phần mềm | Cisco IOS XE, SD-WAN / SD-Routing, giấy phép DNA Essentials hoặc Advantage |
| Nguồn | AC, tuỳ chọn nguồn dự phòng |
| Thay thế cho | ISR 4351, ISR 4431, ISR 4451-X, ISR 4461, ASR 1001-X/1002-X |
| 10G port density | 2 |
|---|---|
| 1G port density | 4 |
| Slots | 2 SM 2 NIM 1 PIM |
| Memory (DRAM) default | 8 GB |
| Storage (M.2 SSD) default | 16 GB |
| Number of IPsec SVTI Tunnels | 4000 |
|---|---|
| Number of ACLs per system | 4000 |
| Number of IPv4 ACEs per system | 72K |
| Number of IPv4 Routes | 1.6M w/ default 8GB, up to 4M w/ 32GB |
| Number of IPv6 Routes | 1.5M w/ default 8GB, up to 4M w/ 32GB |
| Number of NAT Sessions | 1.2M w/ default 8GB, up to 2M w/ 32GB |
| Number of Firewall Sessions | 512K |
| Number of VRFs | 4000 |
| C-NIM-8M* | 8-port 100M/1/2.5Gbps switch NIM, UPoE, LAN/WAN MACSec & Optional L3 |
|---|---|
| P-5GS6-R16SA-GL* | 5G Sub-6 GHz Pluggable – 5G SA Global |
| P-LTEA7-NA* | CAT7 LTE Advanced Pluggable - North America |
| P-LTEA7-EAL* | CAT7 LTE Advanced Pluggable - EMEA, APAC, and LATAM |
| P-LTEA7-JP* | CAT7 LTE Advanced Pluggable - Japan |
| Power consumption, no modules, single PSU | C8300-1N1S-4T2X |
|---|---|
| Power consumption, no modules, single PSU | C8300-2N2S-6T |
| Power consumption, no modules, single PSU | C8300-1N1S-6T |
| Protocols | IPv4, IPv6, static routes, Routing Information Protocol Versions 1 and 2 (RIP and RIPv2), Open Shortest Path First (OSPF), Enhanced Interior Gateway Routing Protocol (EIGRP), Border Gateway Protocol (BGP), BGP Router Reflector, Intermediate System-to-Intermediate System (IS-IS), Multicast Internet Group Management Protocol Version 3 (IGMPv3), Protocol Independent Multicast Sparse Mode (PIM SM), PIM Source-Specific Multicast (SSM), Resource Reservation Protocol (RSVP), Cisco Discovery Protocol, Encapsulated Remote Switched Port Analyzer (ERSPAN), Cisco IOS IP Service-Level Agreements (IPSLA), Call Home, Cisco IOS Embedded Event Manager (EEM), Internet Key Exchange (IKE), Access Control Lists (ACL), Ethernet Virtual Connections (EVC), Dynamic Host Configuration Protocol (DHCP), Frame Relay, DNS, Locator ID Separation Protocol (LISP), Hot Standby Router Protocol (HSRP), RADIUS, Authentication, Authorization, and Accounting (AAA), Application Visibility and Control (AVC), Distance Vector Multicast Routing Protocol (DVMRP), IPv4-to-IPv6 Multicast, Multiprotocol Label Switching (MPLS), Layer 2 and Layer 3 VPN, IPsec, Layer 2 Tunneling Protocol Version 3 (L2TPv3), Bidirectional Forwarding Detection (BFD), IEEE 802.1ag, and IEEE 802.3ah |
|---|---|
| Encapsulations | Generic Routing Encapsulation (GRE), Ethernet, 802.1q VLAN, Point-to-Point Protocol (PPP), Multilink Point-to-Point Protocol (MLPPP), Frame Relay, Multilink Frame Relay (MLFR) (FR.15 and FR.16), High-Level Data Link Control (HDLC), Serial (RS-232, RS-449, X.21, V.35, and EIA-530), and PPP over Ethernet (PPPoE) |
| Traffic management | Quality of Service (QoS), Class-Based Weighted Fair Queuing (CBWFQ), Weighted Random Early Detection (WRED), Hierarchical QoS, Policy-Based Routing (PBR), and Network-Based Application Recognition (NBAR) |
| Cryptographic algorithms | Encryption: DES, 3DES, AES-128 or AES-256 (in CBC and GCM modes) Authentication: RSA (748/1024/2048 bit), ECDSA (256/384 bit) Integrity: MD5, SHA, SHA-256, SHA-384, SHA-512 |
| Unified Communication | Call Admission Control (CAC), Cisco Unified Border Element (CUBE) Session Border Controller(SBC), Cisco Unified Communications Manager Express (CUCME), ISDN, RADIUS, RFC4040 based Clear Channel codec signaling with SIP, Resource Reservation Protocol (RSVP), RTP Control Protocol (RTCP), Session Initiation Protocol for VoIP(SIP), Survivable Remote Site Telephony (SRST), Secure Real-time Transport Protocol(SRTP), and Voice modules |
| Core Features | IPv4, IPv6, static routes, Open Shortest Path First (OSPF), Enhanced Interior Gateway Routing Protocol (EIGRP), BoGateway Protocol (BGP), Overlay Management Protocol (OMP), Application Aware Routing (AAR), Traffic EngineerinService Insertion, zero-trust, whitelisting, tamper-proof module, DTLS/TLS, IPsec, classification, prioritization, low latequeuing, remarking, shaping, scheduling, policing, mirroring, Multicast IPv4 Support, Service advertisement and inserpolicy, SNMP, NTP, DNS client, Dynamic Host Configuration Protocol (DHCP), DHCP client, DHCP server, DHCP relaarchival, syslog, SSH, SCP, Cflowd v10 IPFIX export, IPv6 for transport-side, VRRP, MPLS, NAT (DIA, Service-side, soverload/PAT, NAT64, etc), NAT pools, split DNS, Access Control Lists (ACL), Bidirectional Forwarding Detection (BFNetconf over SSH, CLI, NTP server support, BFD with service-side BGP, BGP community propagation to OMP, 6 SLA for AAR, Trustsec/SDA (Inline SGT propagation), custom app with SD-AVC, multicast AAR, dynamic on-demand tunnSM, OSPFv3, route policies, Multi-VRF support |
|---|---|
| Encapsulations | Generic Routing Encapsulation (GRE), Ethernet, 802.1q VLAN |
| Application Experience | Quality of service (QoS), Forward Error Correction (FEC), COS Marking, Weighted Random Early Detection (WRED)Hierarchical QoS, Policy-Based Routing (PBR), Network-Based Application Recognition (NBAR), Software Defined A Visibility and Control (SD-AVC), per tunnel QoS, Cloud onRamp for SaaS, Enhanced Office 365 traffic steering, DirecAccess, Flexible Netflow (FnF) |
| Cryptographic Algorithms | Encryption: AES-256 (in CBC and GCM modes), Internet Key Exchange (IKE), Cisco PKI Authentication: AAA, RSA (2048 bit), ESP-256-CBC, HMAC-SHA1, ECDSA (256/384 bit) Integrity: SHA-1, SHA-2 |
| Security | Built-in end-to-end segmentation (VPNs), ZBFW, PKI, Cisco DNA Layer Security, Snort IPS/IDS, URL Filtering, Advanced Protection (AMP), ThreatGrid (TG), ALG for ZBFW |
| Unified Communication | Cisco Unified Border Element (CUBE), Survivable Remote Site Telephony (SRST), Cisco Unified Communications Manager Express (CUCME) and Voice Modules |
| Safety certifications | UL 60950-1 CAN/CSA-C22.2 No. 60950-1 EN 60950-1 IEC 60950-1 AS/NZS 60950-1 IEC/EN 60825 Laser Safety FDA: Code of Federal Regulations Laser Safety |
|---|---|
| EMC (Emissions) | 47 CFR Part 15 Class A ICES 003 Class A AS/NZS CISPR 32 Class A CISPR 32 Class A EN55032 Class A VCCI-CISPR 32 Class A CNS-13438 Class A KN32 Class A IEC/EN 61000-3-2: Power Line Harmonics IEC/EN 61000-3-3: Voltage Fluctuations and Flicker |
| EMC (Immunity) | IEC/EN-61000-4-2: Electrostatic Discharge Immunity IEC/EN-61000-4-3: Radiated Immunity IEC/EN-61000-4-4: Electrical Fast Transient Immunity IEC/EN-61000-4-5: Surge AC, DC, and Signal Ports IEC/EN-61000-4-6: Immunity to Conducted Disturbances IEC/EN-61000-4-8: Power Frequency Magnetic Field Immunity IEC/EN-61000-4-11: Voltage DIPS, Short Interruptions, and Voltage Variations KN35 |
| EMC (ETSI/EN) | EN300 386: Telecommunications Network Equipment (EMC) EN55032: Multimedia Equipment (Emissions) EN55024: Information Technology Equipment (Immunity) EN55035: Multimedia Equipment (Immunity) EN61000-6-1: Generic Immunity Standard |











