Brkarc 2881
Brkarc 2881
BRKARC-2881
About Me
BS in Electrical and Electronics Engineering
TAC Engineer - 2006 – 2013
CCIE Security #35505
# 35505
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Agenda
• ISR 1000 and 1100 Hardware Overview
• Features, Technologies & Use Cases
• Demo
• References
• Performance & Scale
• FAQs
• Resources
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
ISR 1000 Hardware Overview
What makes up a great branch router?
Performance
VPN
Management
Wi-Fi6 5G
LTE
Firewall Cisco
Secure Branch
vManage
Connectivity
Security Voice
Easy to use
Hybrid Work Automation Flexibility
Wireless ThousandEyes
Throughput
Speed SD-WAN
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco 1000 Series Integrated Services Routers
Foundation for a cloud first branch Routing Yes
SD-WAN Yes
C1161X-8PLTEP C1131X-8PLTEPW
C1121X-8PLTEPW C1127X-8PLTEP
C1109-4PLTE2P
C1111-8PLTE C1101-4PLTEP
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
All the ISR 1000s!
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
… almost all ☺
C1111X-8P
C1101-4P
C1117-4PLTE
C1109-2PLTE
C1109-4PLTEP2P
C1128-8PLTEP
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Router PID Breakdown - http://cs.co/isr1k-ds
Name of
the Series
WAN Interface
Combination
Feature Description
Power over Ethernet
4PoE/2PoE+
(PoE/PoE+)
C 1 1 3 1 X – 8P L T E P WE
WAN Interface Combination 2xRJ45/SFP Combo
8 port 5G PIM
Cisco CAT 4|6|18 PIM
Ethernet LAN LTE Technologies
Name of the CAT 4 LTE Dongle
sub-series CG418, CG522
Wi-Fi Domains A, B, E, Q, Z
Pluggable
8 GB DRAM / LTE Module
16 GB Flash
Wireless E
domain
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
What is your requirement?
New!!!
Feature ISR 116x ISR 113x ISR 112x ISR 111x ISR 110x
CAT6 / CAT4
LTE / 5G 5G Sub6 / CAT18 / CAT6 / CAT4 Integrated CAT6
1109-2P – CAT4
1101-4P – Yes*
Wi-Fi No Yes – Wi-Fi6 Yes* 1109-2P – Yes*
1109-4P – No
DSL No Yes No
* All Wi-Fi 5 based SKUs are announced End of Sale BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Hardware Features
New!!!
Feature ISR 116x ISR 113x ISR 112x ISR 111x ISR 110x
CPU 4 cores
1101-4P 0 to 45°C
Operating Temperature 0 to 40°C 0 to 40°C 1109-2P 0 to 50°C
1109-4P -20 to 55°C
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Interface Combinations
All Wi-Fi 5 based SKUs are announced End of Sale
Feature ISR 116x ISR 113x ISR 112x ISR 111x ISR 110x
2 LAN Ports - - - -
4 LAN Ports - -
8 LAN Ports -
Wi-Fi only - - -
DSL only - - -
LTE only - -
Wi-Fi + LTE -
DSL + LTE - - -
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Interface Combinations (contd.)
All Wi-Fi 5 based SKUs are announced End of Sale
Feature ISR 116x ISR 113x ISR 112x ISR 111x ISR 110x
“X” + Wi-Fi - - - -
“X” + LTE - - -
Voice
CG418-E / CG 522-E
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Router# controller-mode ?
XE
IOS XE Single
SD-WAN
IMAGE Image IMAGE
universalk9 universalk9 ucmk9
Routing SD-WAN
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
“DP Heavy” SoC Architecture
Key Datapath Innovations
ISR1000 ISR1000
DP SP DP DP
Dynamic Core
DP CP Allocation DP CP
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Cisco ISR 1000 Series Routers Block Diagram
DRAM TAM
USB 3.0
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
DRAM/FLASH*
C1161X-8PLTEP 8GB/8GB
SD-WAN Ready
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
DRAM/FLASH
C1131X-8PLTEPWx 8GB/16GB
SD-WAN Ready
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
DRAM/FLASH*
C1121X-8PLTEPWx 8GB/8GB
SD-WAN Ready
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
DRAM/FLASH*
C1127X-8PLTEP 8GB/8GB
SD-WAN Ready
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
C1127X-8PLTEP
▪ VDSL 2 Profiles 8a, 8b, 8c, 8d, 12a, 12b, 17a ADSL/VDSL2
Interface
▪ Theoretical speeds: 22Mbps – 150 Mbps*
▪ Supported Platforms
▪ C1126-8PLTEP / C1126X-8PLTEP
▪ C1127-8PLTEP / C1127X-8PLTEP
▪ C1127-8PMLTEP / C1127X-8PMLTEP
▪ C1116-4P / C1117-4P / C1117-4PM
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
DRAM/FLASH*
C1128-8PLTEP 4GB/4GB
SD-WAN Ready
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
DRAM/FLASH*
C1111X-8P 8GB/8GB
SD-WAN Ready
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
C1111-8PLTEW SD-WAN Ready
External PSU
DRAM/FLASH*
8GB/8GB
USB 3.0
PoE Capable 802.11ac
Ethernet LAN Wave 2
RJ-45/Micro USB
Console port
Integrated
GPS Connector
CAT6 Modem
External PSU
DRAM/FLASH*
8GB/8GB
USB 3.0
Integrated
GPS Connector CAT6 Modem
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
DRAM/FLASH
C1101-4P 4GB/4GB
SD-WAN Ready
Management/USB Storage
Status and physical
security • RJ45 Console
• USB 3.0, Type A
• Status LED
• Power button
• Reset button
• Power connector
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
C1101-4PLTEP SD-WAN Ready
External PSU
Management/USB Storage
• RJ45 Console Pluggable LTE Technology
• USB 3.0, Type A • CAT 4
• CAT 6
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
C1109-4PLTE2PWx SD-WAN Ready
External PSU
DRAM/FLASH
4GB/4GB
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
C1109-2PLTE / C1109-4PLTE2P SD-WAN Ready
DRAM/FLASH
4GB/4GB
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
ISR 1100 Hardware
Overview
XE SD-WAN 17.4.1a or
Viptela OS 20.4.1 onwards
Superior Hardware
Branch Security
Viptela OS, Upgradable to XE Viptela OS or XE
Operating System Viptela OS
SD-WAN SD-WAN
Basic SD-WAN with Viptela OS, Basic SD-WAN with Viptela OS,
Feature Support Basic SD-WAN Feature rich with full Security with XE SD-WAN
Feature rich with XE SD-WAN
Up-to 1500 IPSEC and Up-to 1500 IPSEC and Up-to 3000 IPSEC and
Scale GRE Tunnels GRE Tunnels
GRE Tunnels
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Cisco ISR1100 and ISR1100X Series Routers for
SD-WAN Branch Routing
SD-WAN
No
Yes
* IOS-XE SD-WAN
ISR1100-4G
4GB DRAM
8GB Flash
ISR1100-6G
4x1GE Ethernet
2x1GE SFP
(ISR1100-6G) ISR1100-4GLTE
Integrated LTE
(ISR1100-4GLTE)
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Cisco ISR1100X Series Routers
Bridge to Feature Rich SD-WAN from Viptela OS
ISR1100X-4G ISR1100X-6G
4x1GE Ethernet
4x1GE Ethernet
2x1GE SFP
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
x86 Multi-core SoC Architecture
Key Datapath Innovations X86 Multi-core CPU
ISR1100X-6G ISR1100X-6G
DP SP DP DP
Dynamic Core
DP CP Allocation DP CP
DRAM TAM
USB 3.0
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
vEdge EoS/EoL and Migration Details
vEdge Cloud EoS/EoL: https://www.cisco.com/c/en/us/products/collateral/routers/vedge-router/vedge-cloud-
eol.html
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
XE SD-WAN vs Viptela OS Comparison
ISR1100X - Bridge to Feature Rich SD-WAN from Viptela OS
XE SD-WAN Benefits
Comprehensive
Security now available
on ISR1100X Series
Routers with
XE SD-WAN
BBR- Bottleneck Bandwidth & Round trip propogation time
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
ISR1100-4G vs ISR1100X-4G
Product Comparison
ISR1100-4G ISR1100X-4G
CPU: Intel 2.2GHz 4-core CPU: Intel 2.2GHz 4-core
Memory: 4GB DDR4, ECC Memory: 8GB DDR4, ECC
Bulk Flash: 8GB eMMC pSLC Bulk Flash: 8GB eMMC pSLC
Routed Ports (WAN/LAN): 4x GE Routed Ports (WAN/LAN): 4x GE
Integrated LTE US and Global): No Integrated LTE (US and Global): No
USB Dongle support (Viptela OS only) USB Dongle support (Viptela OS only)
Console: 1x RJ45 Console: 1x RJ45
USB Type A: USB3.0, 4.5W USB Type A: USB3.0, 4.5W
Power supply: External Adapter, 30W Power supply: External Adapter, 30W
Form Factor: 10.2” x 7” x 1.1” Form Factor: 10.2” x 7” x 1.1”
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
ISR1100-6G vs ISR1100X-6G
Product Comparison
ISR1100-6G ISR1100X-6G
4-core x86 CPU 4-core x86 CPU
Memory: 4GB DDR4, ECC Memory: 8GB DDR4, ECC
Bulk Flash: 8GB eMMC pSLC Bulk Flash: 16GB eMMC pSLC
Routed Ports (WAN/LAN): 4x GE + 2x SFP (6 individual ports) Routed Ports (WAN/LAN): 4x GE + 2x SFP (6 individual ports)
Integrated LTE (US and Global): No Integrated LTE (US and Global): No
USB Dongle support (Viptela OS only) USB Dongle support (Viptela OS only)
Console: 1x RJ45 Console: 1x RJ45
USB Type A: USB3.0, 4.5W USB Type A: USB3.0, 4.5W
Power supply: External Adapter, 30W Power supply: External Adapter, 30W
Form Factor: 10.2” x 7” x 1.1” Form Factor: 10.2” x 7” x 1.1”
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Upgrading ISR1100 and ISR1100X Series Routers
Pre 20.4/17.4 vManage
Until 20.4/17.4 release:
• ISR1100-4G, ISR1100-4G-LTE, ISR1100-6G can be deployed
with Viptela OS for the pure play SD-WAN use cases
• Minimum software release supported on these platforms is
Viptela OS 19.2
With 20.4/17.4
Starting with 20.4/17.4:
• We have option to run the XE SD-WAN code on ISR1100 and SD-WAN
ISR1100X series routers and leverage all services such as Security,
AppQoE, SD-AVC which are supported on XE SD-WAN software
• Minimum software release supported on ISR1100X series routers is
Viptela OS 20.4 or XE SD-WAN 17.4
Prerequisites
Viptela OS XE SD-WAN
ISR1100 router should be first upgraded to 20.4 Viptela OS code to
upgrade the firmware and then we can migrate to XE SD-WAN
17.4 code
1. Detach
IOS-XE Template Template
ISR1100 (Viptela)
vEdge Template ISR1100 (Viptela) Automated
Configuration Change
2. Upgrade to XE SD-WAN with Minimum
Configuration
IOS-XE Template
ISR1100 (XE SD-WAN )
vEdge Template ISR1100 (Viptela)
3. Switch to IOS-XE
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Features, Technologies &
Use Cases
Wi-Fi Technologies
Routing Yes
SD-WAN Yes
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Routing Yes
SD-WAN Yes
Ethernet Client
Maximal Ratio
OFDMA BSS Coloring Target Wake Time
Combining
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Embedded Wireless Controller Configuration
Baseline Configuration
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Baseline Configuration
1. Configure DHCP Pool for EWC to receive IP address 2. Configure SVI
ip dhcp pool Wireless interface Vlan199
network 10.10.10.0 255.255.255.0 description Wireless
default-router 10.10.10.1 ip address 10.10.10.1 255.255.255.0
dns-server 8.8.8.8 ip nat inside
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Over-The-Air Provisioning (OTAP)
Get your wireless network up and running in less than 10 minutes
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Option: 1 Cisco Catalyst Wireless Mobile App
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Option: 1 Cisco Catalyst Wireless Mobile App
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Option: 2 Connect to the default SSID
CiscoAirProvision-XXXX Go to mywifi.cisco.com
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Option: 2 Connect to the default SSID
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Cellular Technologies
Routing Yes
SD-WAN Yes
CG418-E
CAT 4|6 LTE CG522-E
PIM Module Cellular
Gateway
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Starting from
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Why Cellular Gateway is needed for high quality
Wireless WAN
Offices Inc.
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Why Cellular Gateway is needed for high quality
Wireless WAN
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
LTE Dongle D-LTE-xx
USB Based LTE Dongle
✓ Sierra Wireless WP76xx modem
✓ Single micro-SIM, single radio
SMA Antenna
Length: 2.46 in ✓ 75 Mbps DL / 50 Mbps UL
Weight: 0.3 oz
✓ USB Powered
✓ Sub-miniature version - A (SMA) Antenna
Compact Form
Dimensions: 3.69 in x 1.30 in x 0.39 in
Weight: 1.1 oz
✓ Field Replaceable / Hot-Swappable
Supported Bands :
D-LTE-NA: 2,4,5,12,13,14,17
D-LTE-GB: 1,3,7,8,20,28
D-LTE-AS: 1,3,5,8,40,41
Micro-SIM Card Slot
Zero-Touch
Budget LTE Dongle LTE Category 4 Routing
Provisioning
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
LTE Advanced Pro P-LTEAP18-GL
CAT 18 LTE PIM Module
✓ Telit LM960A18 modem
✓ Dual micro-SIM, single radio
✓ 1.2 Gbps DL / 200 Mbps UL
✓ FirstNet Certified
SMA Antenna
SMA Antenna ✓ SMA Antenna support
Connector
Connector ✓ Field Replaceable / Hot-Swappable
Diversity Antenna
Connector Supported Bands:
Diversity Antenna
Connector P-LTEAP18-GL: 1, 2, 3, 4, 5, 7, 8, 12, 13, 14*,
17, 18, 19, 20, 25, 26, 28, 29,
Micro USB Debug Port 30, 32, 38, 39, 40, 41, 42, 43,
46, 48, 66, 71
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
LTE Advanced P-LTE(A)-xx
CAT 4|6 LTE PIM Module
✓ Telit LM960A18 modem
✓ Dual micro-SIM, single radio
✓ 300 Mbps DL / 50 Mbps UL
✓ GPS Enabled
✓ SMA Antenna support
SMA Antenna
Connector SMA Antenna ✓ Field Replaceable / Hot-Swappable
Connector
Supported Bands:
Dual Micro-SIM Port CAT4: CAT6:
GPS Antenna P-LTE-US: 2, 4, 5, 12 P-LTEA-LA:
P-LTE-GB: 1, 3, 7, 8, 20, 28 1, 3, 5, 7, 8, 18, 19, 21,
P-LTE-VZ: 4, 13 28, 38, 39, 40, 41
Micro USB Debug Port
P-LTE-MNA: P-LTEA-EA:
2, 4, 5, 12, 13, 14, 17, 66 1-5, 7, 12, 13, 20, 25, 26,
29, 30, 41
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Pathway to 5G CG418-E / CG522-E
Cisco Cellular Gateway ✓ Flexible Fail-Over Cellular Gateway
✓ 3.3 Gbps DL / 420 Mbps UL
✓ PoE Powered (or externally powered)
✓ IP Passthrough
✓ External Antenna Support
✓ Integrated security with ACT2 for SUDI
✓ Console Port for Out-of-Band management
Supported Bands :
5G: n1, n2, n3, n5, n28, n41, n66, n71, n77, n78, n79
LTE:1, 2, 3, 4, 5, 7, 8, 12, 13, 14, 17,18,19, 20, 25, 26,
28, 29, 30, 32, 34, 38, 39, 40, 41, 42, 43, 46, 48,
66, 71
HSPA+: 1, 9, 19
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Thousand Eyes
* Routing No
SD-WAN Yes
Seattle, Wireless
WA Network Cloud
Proxy
DNS
Branch ISP Transit
Office Providers SaaS
Local
ISP Onramp
Paris,
France
Internal
Apps
Mobile
Chicago, IL Networks CDN Datacenter Web Apps
Infrastructure
SaaS Apps
High End
Branch
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
* Routing No
* Currently only supported on x86 platforms SD-WAN Yes
ISR1100X-6G
Customers
Private MPLS
Enterprise Data Center
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Application Quality of
Experience
Routing No
SD-WAN Yes
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Routing No
SD-WAN Yes
SD-WAN
Fabric
Users Client End Server End Servers
Proxy Proxy
• WAN Edge routers terminate TCP • Optimized TCP connection uses selective
sessions and provide local acknowledgement to prevent unnecessary
acknowledgements retransmissions and large initial TCP
window size to maximize throughput
• Hosts don’t have to wait for end-to-end
• Hosts using older TCP/IP stacks will see
TCP ACKs and pause TCP transmission
the most benefit
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Routing No
SD-WAN Yes
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
TrustSec
Routing Yes
SD-WAN Yes
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Routing Yes
SD-WAN Yes
groupings to provide
consistent policy and
access independent of
network topology Devices
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Routing Yes
SD-WAN Yes
Network
Devices
Servers
Branch Data Center
Guest
Database
VoIP
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Umbrella Secure Internet
Gateway
Routing Yes
SD-WAN Yes
Problem
• Lean branch – no on-prem security
• Applications hosted on the internet
vulnerable to attacks
• Internet bound traffic must be subjected
to policy enforcement
• Enforce secure web usage & control
Solution
• Leverage cloud hosted security with SIG
• User traffic redirected to Umbrella via
Cisco Umbrella SIG
Transport side IPSec tunnel
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Securing the Access Layer
Remote Workforce Access and Aggregation Direct Internet Access
Cloud Convergence
Ent. FW
App Aware
RR
IPS
VPN
Micro-Branch AMP
P
DNS/web Content Farm
layer
security
PE
URL
Filtering
Gateway VOD TV SIP
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Demo
• Zone Based Firewall -
https://cs.co/zbf-config
• Snort IPS -
https://cs.co/snortips-config
• DNS Layer Security -
http://cs.co/dns-layer-config
• Umbrella SIG –
http://cs.co/isr-sig-config
• Troubleshooting -
https://cs.co/ios-xe-packet-
trace
Demo Topology
Container
Data Centre
eth1 eth2
Applications 192.168.103.2 192.0.2.2
VPG0 VPG1
Internet 192.168.103.1 192.0.2.1
192.168.128.5 .1
G0/0/0 G0/0/0
G0/1/0 192.168.128.5
Vlan 101
Wireless 192.168.101.2
192.168.102.2 C1131X-LTEPW
Vlan 102 .1
VPN Tunnel HQ Destined Traffic
192.168.101.1 Vlan 101 Wireless Guest users traffic getting DNS-layer Security
Wired Wired Employees IKEv2 IPsec Tunnel to Umbrella SIG
192.168.101.2
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
References
Performance & Scale
Cisco ISR 1000 - CEF Throughput
ISR1161X-8P
ISR1131X-8P
ISR1121X-8P
ISR111x-4P
ISR1101-4P
CEF Performance
1.89 Gbps
ISR1109-4P
ISR1109-2P 1.6 Gbps
1.6 Gbps
1.1 Gbps
1.1 Gbps
1 Gbps
900 Mbps
Profile: Cisco IMIX traffic (Avg. 352 Bytes)
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Routing and SD-WAN
ISR 1109-2P
* VDSL2, ADSL2+ only
Up to 340 Mbps
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Routing and SD-WAN
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
SD-WAN
SD-WAN Security
SD-WAN IPsec Performance (IMIX) CAT4 USB Dongle (Viptela)
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Cisco ISR1000 Series Routers
Routing Scale
XE SD-WAN C1161X-8P C1131X-8P C1121-4P C1111X-8P C1111-8P C1111-4P C1101-4P C1109-4P C1109-2P
DRAM/Flash 8GB/8GB 8GB/16GB 4GB/4GB 8GB/8GB 4GB/4GB 4GB/4GB 4GB/4GB 4GB/4GB 4GB/4GB
No. of IPv4 Routes 800K 280K 280K 800K 280K 280K 280K 280K 280K
No. of IPv6 Routes 700K 260K 260K 700K 260K 260K 260K 260K 260K
No. of NAT Sessions 100K 100K 100K 100K 100K 100K 100K 100K 100K
No. of VRFs 4K 1K 1K 1K 1K 1K 1K 1K 1K
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Cisco ISR1000 Series Routers
SD-WAN Scale
XE SD-WAN C1161X-8P C1131X-8P C1121X-8P C1121-4P C1111X-8P C1111-4P C1101-4P C1109-4P C1109-2P
IPSec Overlay Tunnels 200 200 200 200 200 200 200 200 200
GRE Overlay Tunnels 200 200 200 200 200 200 200 200 200
DPI Flows 32K 32K 32K 32K 32K 32K 32K 32K 32K
cFlows Entries 32K 32K 32K 32K 32K 32K 32K 32K 32K
OMP Routes (overlay) 120K 120K 120K 120K 120K 120K 120K 120K 120K
IPv4 Routes 120K 120K 120K 120K 120K 120K 120K 120K 120K
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Cisco ISR1100 and ISR1100X Series Routers
SD-WAN Scale Viptela OS vs XE SD-WAN
Viptela OS XE SD-WAN
IPSec Overlay
247 250 1500 1500 250 500 1500 3000
Tunnels
GRE Overlay Tunnels 247 250 1500 1500 250 500 1500 3000
DPI Flows 14K 14K 14K 14K 50K 256K 50K 256K
OMP Routes
30K 30K 128K 128K 200K 512K 200K 512K
(overlay)
IPv4 Routes 30K 250K 128K 250K 256K 512K 256K 512K
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Frequently Asked
Questions
Does ISR1K support….?
▪ SGT ▪ Embedded Security
▪ SGT Inline tagging is supported. Static SGACL is ▪ Supports entire SD-WAN security stack – ZBFW, IPS/IDS,
supported. SGACL enforcement is available only on WAN URL-Filtering, AMP/TG, DNS/Web Layer Security
interface
▪ From 17.5, static SGACL can be enforced on SVI as well ▪ WiFi in SD-WAN
▪ From 17.5, dynamic SGT assignment and SGACL on WAN ▪ Yes for CAPWAP mode. Starting 17.6, ME can be
and SVI from ISE will be supported. configured via SD-WAN feature templates
▪ CME and SRST support is supported in Routing ▪ FirstNet (Band 14) for CAT18 LTE PIMs
▪ VPN ▪ Currently on-track
▪ EzVPN server only, IPSec VPN, DMVPN, GETVPN & ▪ Active-Active LTE
FlexVPN
▪ C1109 variants support 2 LTE PIMs each operating in
▪ VDSL2 35b active-standby mode, providing 2 active LTE connections
simultaneously
▪ Only on G.FAST DSL platforms – C1112, C1113 variants
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Resources
Cisco ISR1000 Series Routers
• ISR1000 Wi-Fi SKUs EoS:
https://www.cisco.com/c/en/us/products/collateral/routers/1000-series-integrated-services-
routers-isr/select-isr1100-product-eol.html#Productmigrationoptions
• Blogs:
• Remote Worker: https://community.cisco.com/t5/networking-blogs/simplify-your-remote-
worker-network-with-cisco-sd-wan/ba-p/4308306
• Everything ISR1000: https://community.cisco.com/t5/networking-blogs/your-one-stop-shop-
for-soho-routing/ba-p/4270343
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Cisco ISR1100 and ISR1100X Series Routers for
SD-WAN Branch
• Datasheet: https://www.cisco.com/c/en/us/products/collateral/routers/1000-series-
integrated-services-routers-isr/datasheet-c78-742893.html
• OS Migration Guide:
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/isr1100series-
migration/sw-install-and-upgrade-guide-isr1100-series.html
• Hardware Installation Guide:
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/hardware/isr1100-4g-
6g/cisco-isr-1100-4g-6g-hig.html
• Blog:
https://community.cisco.com/t5/networking-blogs/cisco-isr1100-and-isr1100x-
series-routers-for-sd-wan-branch/ba-p/4280554
• YouTube: https://cs.co/CatalystTV
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Our New Hardware at
World of Solution
Cisco Cellular Gateway – CG522-E
CG522-E
Cisco Cellular Gateway
✓ Flexible Fail-Over Cellular Gateway
✓ 3.3Gbps DL / 420Mbps UL
✓ PoE+ Powered (or externally powered)
✓ IP Passthrough
✓ External Antenna Support
✓ Integrated security with ACT2 for SUDI
✓ Console Port for Out of band management
✓ Modem Sierra Wireless EM9190
Supported Bands :
5G: n1, n2, n3, n5, n28, n41, n66, n71, n77, n78, n79
LTE: 1, 2, 3, 4, 5, 7, 8, 12, 13, 14, 17,18,19, 20, 25, 26, 28, 29, 30, 32, 34,
38, 39, 40, 41, 42, 43, 46, 48, 66, 71
HSPA+: 1, 9, 19
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
FCS in November 2022
IOS CG 17.9.1a
Cisco Catalyst Wireless Gateway vManage 20.9.1
minimum software
6 QSFP,20 SFP+
100G, High SD-WAN
10/1G Performance
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Breakout Sessions – Routing Platforms
Session ID Title Presenter Name Date Time in PDT Location
Architecture, Deployments and
8:30 AM - 1:00 PM
TECARC-2407 Troubleshooting Deep Dive for Catalyst Jason Yang Feb 6 Elicium 2
CET
8000 Series Edge Platforms
Fixed Platform ISR1000 and ISR1100 2:00 PM - 3:00 PM
BRKARC-2881 Kureli Sankar Feb 7 Elicium 2
Series Deep Dive CET
BRKENT-2139 How to Choose the Correct Branch Router Stefan Mansson Feb 7 3:30 PM – 4:30 PM Elicium 3
Extending Enterprise Network into Public
10:30 AM - 11:30 AM
BRKXAR-2003 Cloud with Cisco Catalyst 8000V Edge Jason Yang Feb 8 D203
CET
Software
All You Need to Know about Forwarding 8:30 AM - 10:00 AM
BRKENT-2653 David Roten Feb 8 E105
on the Catalyst 8500 and 8500L Platforms CET
Cisco Catalyst 8200/8300 Series Access
BRKARC-2882 Stefan Mansson Feb 8 12:00 PM – 1:30 PM Elicium 4
Edge Platforms Deep Dive
What QoS can do for your network with 4:45 PM - 5:45 PM
BRKENT-2731 David Roten Feb 8 G106
Catalyst 8000 and other IOS XE routers CET
Cisco Catalyst 8500 Series Edge Platform
BRKARC-2885 Sumant Mali Feb 9 8:30 AM – 10:00 AM A3
Deep Dive
Untangle Enterprise Direct Cloud
BRKENT-2809 Connectivity with Powerful Catalyst 8500 Sumant Mali Feb 9 12:00 PM – 1:00 PM` D203
Series Edge Platforms
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Tectorials and Labs – Routing Platforms
Presenter
Session ID Title Date Time in PDT Location
Name(s)
Architecture, Deployments, and
Troubleshooting Deep Dive for Jason Yang &
TECARC-2407 Feb 6 8:30 AM - 1:00 PM CET Elicium 2
Catalyst 8000 Series Edge Sumant Mali
Platforms
Catalyst 8000 Series Tour &
Kureli Sankar
LTRENT-2440 Deployment - Branch, Agg, Wired, Feb 9 8:30 AM - 12:30 PM CET Labs2
Wireless WAN - SD-WAN version
& David Roten
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Complete your Session Survey
• Please complete your session survey
after each session. Your feedback
is important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (open from Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events Mobile App or
by logging in to the Session Catalog and clicking the
"Attendee Dashboard” at
https://www.ciscolive.com/emea/learn/sessions/session-catalog.html
BRKARC-2881 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Thank you