NetEngin Products and Solution
NetEngin Products and Solution
+ High forwarding
+ Single functions + Routing, switching, Wi-Fi, performance, easily coping
+ Routing and and LTE with traffic surges
forwarding + WOC, VPN, firewall, etc. + Application identification
and optimization
+ Service convergence and
simple management
50,000+ global
customers
Unit: million USD From: Gartner
NetEngine AR: 20 years of dedication and expertise, paving the way for more success
NetEngine AR 6 1 2 1
Generation: 0 (first generation), n (n+1
Brand: NetEngine (product brand)
generation)
Type: AR (brand for global markets) and SRG Number of slots: 1 to 9 (number of slots); 0:
(brand for carrier markets) (slot 10, for 2U or above)
Series: 1/2/3 (G3 series); 6 (6000 series) Height: 1 (1 U), 2 (2 U), and 3 (3 U)
Fixed-configuration routers
NetEngine AR 6 1 1 W – LTE4CN
Additional information: LTE (LTE); 4 (Cat4); 6
Series: 1/2 (G3 series); 6 (600 series) (Cat6); CN (China)
SRU-400H/SRU-600H SRU-400H/SRU-600H
Small enterprise
AR651C AR651 AR651W AR657W
NetEngine
AR650 series
SOHO
NetEngine
AR610 series NetEngine AR617VW
NetEngine AR611W NetEngine AR617VW -LTE4EA
AR AR2220E AR6140-9G-2AC
modular routers AR2204E/AR2204-27GE/27GE-P
The AR2204 can be delivered.
AR2204-51GE/51GE-P
AR1220E/AR1220/AR1220C AR6120/AR6121
AR161/AR161F AR651C
AR161G-L/AR161FG-L AR651
AR161EW AR651W
AR169EW/AR169EGW-L AR657W
AR
fixed-configuration router AR109/AR109W/AR129CV/AR129CVW/AR16
AR617VW
9/AR169W/AR169F/AR169FVW
AR109G-L/AR129CGVW-L/AR169G-
AR617VW-LTE4EA
L/AR169FGW-L
AR161W/AR161FW AR611W
AR6300 AR3260
vs.
1.8 Gbps (SRU-100E)
10 Gbps (SRU-400H) Forwarding performance
9 Gbps (SRU-200)
12 Gbps (SRU-600H)
10%+↑ 11 Gbps (SRU-400)
Reliabilit
Dual SRUs and dual power supplies y par Dual SRUs and dual power supplies
On a
AR6280 AR2240
vs.
10 Gbps (SRU-400H) Forwarding performance 1.8 Gbps (SRU-100E)
12 Gbps (SRU-600H) 30%+↑ 9 Gbps (SRU-200)
New
WAN: 2 x GE optical + 2 x
WAN: 1 x 10GE optical + 1 x WAN: 1 x 10GE optical + 2 x WAN: 4 x GE + 4 x
GE
GE combo + 1 x GE GE combo 10GE optical
Ports LAN: 2 x GE optical + 3 x
LAN: 8 x GE LAN: 8 x GE + 1 x GE combo LAN: 12 x GE electrical
GE
Note: 10GE optical ports can be configured as GE optical ports, and LAN ports can be configured as WAN ports.
SIC slots 2 2 4 4
WSIC slots
0/1 0/1 0/2 0/2
(default/maximum)
XSIC slots
- - - -
(default/maximum)
Memory 2 GB 2 GB 2 GB 2 GB
Flash 1 GB 1 GB 1 GB 1 GB
Operating temperature 0°C to 45°C 0°C to 45°C 0°C to 45°C 0°C to 45°C
AR6120 AR1220E
vs.
2 Gbps
Forwarding performance 800 Mbps
2.5x
8 x GE
Fixed LAN 8 x GE
On a par
Number of slots
2 x SIC 2 x SIC
On a par
AR6121 AR1220E
vs.
Forwarding performance
2 Gbps 800 Mbps
2.5x
Fixed WAN
1 x 10GE optical + 2 x GE combo 2 x GE combo
One more 10GE optical
port
Fixed LAN
8 x GE + 1 x GE combo 8 x GE
One more GE combo port
Number of slots
2 x SIC 2 x SIC
On a par
AR2220E
AR6140-9G-2AC
vs.
Forwarding performance
2 Gbps 1.6 Gbps
25%↑
Number of slots
4 x SIC 4 x SIC + 2 x WSIC
Two fewer slots
Reliability
Dual power supplies Single power supply
Enhanced
AR651C AR161
vs.
Forwarding performance
1.5 Gbps 300 Mbps
5x
2 x GE optical + 2 x GE
Fixed WAN
1 x GE
4x
Fixed LAN
8 x GE 4 x GE
2x
Memory
1 GB 512 MB
2x
AR651C AR161F
vs.
1.5 Gbps
Forwarding performance 300 Mbps
5x
Fixed WAN
2 x GE optical + 2 x GE 1 x GE combo
4x
Fixed LAN
8 x GE 4 x GE
2x
Memory
1 GB 512 MB
4x
AR161W
AR651W
vs.
Forwarding performance
2 Gbps 300 Mbps
6x
Fixed WAN
2 x GE combo 1 x GE combo
4x
Fixed LAN
8 x GE 4 x GE
2x
Dual-band, 2x2 MIMO, Wi-Fi 802.11 b/g/n
802.11b/g/n/ac 2x
2 GB
Memory 512 MB
4x
1 x MIC (LTE MIC Number of
None
supported) extension slots
SOHO and SMB router
Page 21 Copyright © 2020 Huawei Technologies Co., Ltd.
NetEngine AR651W vs. AR161EW: 2x Performance, 2x Fixed Ports and Memory
AR651W AR161EW
vs.
Forwarding performance
2 Gbps 1 Gbps
2x
Fixed WAN
2 x GE combo 1 x GE combo
2x
Fixed LAN
8 x GE 4 x GE
2x
Dual-band, 2x2 MIMO, Wi-Fi Dual-band, 4x4 MIMO,
802.11b/g/n/ac Slightly lower performance 802.11b/g/n/ac WAVE 2
Memory
2 GB 1 GB
2x
1 x MIC (LTE MIC Number of
None
supported) extension slots
SOHO and SMB router
Page 22 Copyright © 2020 Huawei Technologies Co., Ltd.
NetEngine AR657W vs. AR169EW/169EGW-L: 2x Performance, and 2x Fixed Ports
and Memory
AR657W AR169EW/169EGW-L
vs.
Forwarding performance
2 Gbps 1 Gbps
2x
Fixed LAN
8 x GE 4 x GE
2x
Dual-band, 2x2 MIMO, Wi-Fi Dual-band, 4x4 MIMO,
802.11b/g/n/ac Slightly lower performance 802.11b/g/n/ac WAVE 2
Memory
2 GB 1 GB
2x
1 x MIC (LTE MIC Number of None
supported) extension slots The AR169EGW-L supports LTE.
Forwarding
300 Mbps 300 Mbps 300 Mbps
performance
WAN: 1 x GE combo + 1 x WAN: 1 x GE combo + 1 x
WAN: 1 x GE combo
VDSL VDSL 35b
Ports LAN: 4 x GE (can be configured
LAN: 4 x GE (can be configured LAN: 4 x GE (can be
as WAN)
as WAN) configured as WAN)
Card - - -
Wi-Fi 802.11ac/b/g/n 802.11ac/b/g/n 802.11ac/b/g/n
LTE - - Supported
Memory 1 GB 1 GB 1 GB
Flash 1 GB 1 GB 1 GB
Operating
0°C to 45°C 0°C to 45°C 0°C to 45°C
temperature
AR617VW AR129CVW
vs.
Forwarding performance
300 Mbps 100 Mbps
3x
Fixed WAN: 1 x GE combo, 1 x Fixed ports Fixed WAN: 1 x GE, 1 x VDSL2
VDSL2 35B
Better Fixed LAN: 4 x GE
Fixed LAN: 4 x GE
Memory
1 GB 256 MB
4x
SOHO and SMB router
Page 25 Copyright © 2020 Huawei Technologies Co., Ltd.
NetEngine AR617VW-LTE4EA vs. AR129CGVW-L: 3x Performance and 4x Memory
AR617VW-LTE4EA AR129CGVW-L
vs.
Forwarding performance
300 Mbps 100 Mbps
3x
Fixed WAN: 1 x GE combo, 1 x Fixed ports Fixed WAN: 1 x GE, 1 x VDSL2, LTE
VDSL2 35B, LTE
Better Fixed LAN: 4 x GE
Fixed LAN: 4 x GE
Wi-Fi
802.11b/g/n/ac 802.11b/g/n/ac
On a par
Voice
2 x FXS 2 x FXS
On a par
Memory
1 GB 256 MB
4x
SOHO and SMB router
Page 26 Copyright © 2020 Huawei Technologies Co., Ltd.
Contents
• Overview of Huawei NetEngine AR Routers
Processor Ultra-fast
L4-L7 services by 50%.
accelerator
optimization
forwarding
accelerator
QoS
SA accelerator
Next-Generation NetEngine AR
• Multiple embedded hardware acceleration engines
• 3x the industry average SD-WAN performance
USA-based international
authoritative test organization
Wired-wireless
convergence
High-density interfaces,
10GE interconnection, and
5G/LTE uplink
Next-generation NetEngine AR routers
High-Density Interfaces
IaaS/SaaS Internet HQ/DC • 10GE uplink, multi-link redundancy, WAN-side
wide pipes for interconnection
High-density 10GE ports: The SRU-400H/SRU-600H provides 14 x 10GE
optical ports, and the NetEngine AR6000 (except the AR6140-9G-2AC)
GE (optical Flexible switching: LAN ports can be configured as WAN ports using
10GE
or electrical 5G/LTE E1/SA... commands.
(optical)
port)
Branch
10GE Interconnection and High-Density Access, Building Wide Pipes for Branch Interconnection
LTE VPN LTE link backup Major LTE cards and devices
HQ HQ
Internet
Internet
LTE MIC
scenarios such as bank ATM interconnection and World's highest speed @ Sub-6G 200 MHz
series, excluding AR651C), and device with LTE
mobile office *Downlink rate: 3.6 Gbit/s
modems (AR610 series)
*Uplink rate: 230 Mbit/s
LTE link backup: Wireless links are used as
backup links for branch interconnection, enhancing 4G full-frequency, flexibly adapting to Supported by the AR6000 series
A-FEC
NetEngine AR NetEngine AR
Real-time detection of application packet loss and WAN
2. Real-time detection of
adaptive redundancy for compensation application packet loss
Data encryption
Built-in firewall App access control
Mainstream VPN
Stateful inspection and Identification of 6000+ well-known encryption protocols
packet filtering firewalls and customized applications SM1/SM2/SM3/SM4
Identification of popular encrypted
P2P applications
IPS
URL filtering
IPS engine update
130+ categories, Detection of 5500+ attacks, at
accuracy > 96% a 90%+ detection rate
Refined Internet access
control
Application Access Control: Most Extensive Application Signature Database and Flexible Upgrade
Massive remote URL category database Extensive signature databases and high
Query of 100+ million remote URL categories, 130+ predefined categories, detection rate
and customized categories; timely update and efficient query based on
Extensive signature database with 1600+ application records; detection
Huawei security system
rate: > 90%
URL matching modes Contains signatures based on network behaviors such as Trojan horses,
Prefix matching, suffix matching, keyword matching, exact matching, and worms, botnets, spyware, vulnerability attacks, and web attacks.
fast matching
Flexible upgrade
Refined blacklist and whitelist Supports online update of the signature database and real-time update of
As an effective supplement, the blacklist and whitelist can precisely define the IPS engine to defend against latest intrusion behaviors.
and control access to a website.
Converged deployment
Flexible response modes The AR has built-in IPS and does not require dedicated fault detection
Various URL filtering actions can be flexibly configured to push different points, which reduces overheads and operation costs.
URL response pages.
Branch A DC
IPSec DSVPN
Branch B Internet
Branch C
HQ
Mobile employee
Branch D
• Enterprise branch: Different VPN access modes can be applied to branches based on their scales. In a single network topology, GRE over IPSec VPN is
recommended for secure access. In a hub-spoke topology, VPNs need to be dynamically established between branches for secure access, and IPSec DSVPN is
recommended. For small branches, IPSec VPN is recommended. For terminals connected to the Internet through 4G, IPSec over L2TP VPN is recommended.
• Mobile employee: Clients are used to connect mobile employees to the internal network. L2TP over IPSec VPN is recommended.
• HQ: VPN gateways are used to construct VPN data channels between gateways and between gateways and clients.
DSVPN DSVPN
Spoke Spoke
Application scenarios: This solution applies to enterprises with multiple branches. If the HQ uses a static public IP address to access the Internet, branches use dynamic public IP addresses to
access the Internet, and the traditional VPN is used to construct a network, branches cannot directly communicate with each other. (The source branch cannot obtain the public IP address of the
destination branch and a tunnel cannot be established between these branches.) Traffic between all branches can only be forwarded through the HQ. In this case, devices in the HQ may be overloaded.
Highlights:
• DSVPN uses NHRP to dynamically collect, maintain, and advertise public network addresses of nodes. This solves the problem that the source branch cannot obtain the public IP address of the
destination branch. In this mode, dynamic VPN tunnels are established between the branches to implement direct communication, reducing the burden of the HQ and minimizing the network
latency. The tunnel is established on demand based on inter-branch traffic. If no traffic is transmitted, the tunnel is automatically torn down.
• DSVPN uses the mGRE technology to enable a tunnel interface to establish VPN tunnels with multiple peers, reducing the workload of VPN configuration. When a branch is created or the public IP
address of a branch changes, the tunnels between the HQ and branches can be automatically maintained without the need to adjust the tunnel configuration at the HQ, making network
maintenance more intelligent.
PE CE
CE
PE MPLS network OSPF/RIP/
OSPF/RIP/
Static Static
route/BGP PE route/BGP
Branch A
PE
HQ
PE
OSPF/RIP/ MPLS private line
CE
Static/BGP
MP-EBGP
Branch B
Interconnection between branches of a large or High security and reliability, flexible bandwidth
midsize enterprise
BFD: service switching within milliseconds
Layer 3 interconnection realizes full-mesh connections
between branches and between the HQ and branches. LDP FRR and TE FRR backup: enhanced service reliability
Branch network DC
AP
RADIUS
server
WAN
iMaster
AP
NCE
AR (built-in AC)
• Device overview, configuration • E2E visualized SLA evaluation of • GIS map-based network monitoring
wizard, system management, user delay, packet loss rate, and jitter for and visualized application, link, site,
management, LAN access, WAN network data packets and network status
interconnection, IP services, security, • E2E visualized MPLS VPN • Automatic network inspection and
QoS, and VPN management precise alarm notification by email
MSP/HQ Branch
1. Plan sites, device types, and 4. The NetEngine AR registers
network configurations. with NCE.
1. Plan sites and device types. 1. The device obtains an IP address and NCE IP
2. Configure network information for the WAN address and registers with NCE.
interface. 2. NCE searches for the site based on the token and
delivers service configurations.
Network administrator
1. Plan the network. 4. Register with NCE.
3. Click the URL
to start the
deployment.
Adaption to Ethernet, DSL, LTE, and other interfaces; no need for professional personnel to visit sites;
deployment within minutes
2. Select a site and generate a 1. The device administrator imports the initial 1. Connect to the WAN and LAN, and
deployment file. configuration using a USB flash drive. power on the device.
2. Observe the initial configuration result 2. Register with NCE.
1. Select the site to be deployed and use through the indicator.
NCE to generate a ZTP file, including the
site, device, installation guide, and Network administrator
deployment URL.
2. Download the ZTP file and send it to the
Device management personnel
device administrator. 3. Import configuration
files in batches.
MSP/HQ Branch
SD-WAN controller
2. Register with NCE.
Scenario with the DHCP server: zero onsite configuration, and plug-and-play
AR6300
MPLS
SOHO/SMB HQ
SOHO/SMB HQ
AR651C
Internet
Small and
midsize Large
branch branch
Small and midsize MPLS AR6280/A Large branch
branch
AR6140-9G-2AC R6300
Easy O&M
Internet/LTE MPLS VPN • USB-based deployment: After a device is powered on and a USB flash drive is
inserted into the device, the device is automatically configured without manual
intervention. This reduces the configuration error rate, technical requirements, and
labor costs.
Large branch Common branch Egress of large High performance, and dual power
AR6280
branches supplies
AR6280 AR6121 Egress of common
AR6121 10+ GE Inerfaces
branches
AR6300 inserted into the device, the device is automatically configured without manual
Bank intervention. This reduces the configuration error rate, technical requirements, and
branch
labor costs.
MPLS VPN
Location Model Highlights
Network reliability:
• SPR: The e-Government network has two planes. SPR is configured to
Private line
ensure smooth link switchover of key services and improve user
Provincial core node
experience.
Easy O&M
AR6280
• USB-based deployment: After a device is powered on and a USB flash
drive is inserted into the device, the device is automatically configured
without manual intervention. This reduces the configuration error rate,
City aggregation node
Private line technical requirements, and labor costs.
Recommended
Location Highlights
Model
AR651C AR6140- Egress device of the
9G2-2AC high performance, and
city aggregation AR6280
extensive slots
node
Gas station
Gas station egress AR6140-9G- High-density Ethernet, flexible
site device 2AC/AR651C access, and integrated device
Gas station 1 Gas station 2
• Integrated device at the egress of midsize or large stores: The AC directly manages
HQ
downstream APs, offering Wi-Fi services. LTE links can be used as backup links,
enhancing link reliability.
AR6300
High reliability:
• IPSec: Remote stores can use the Internet for access. Data is encrypted to ensure service
security.
• Flexible access to DSL, optical fibers, and LTE links, enriching ZTP (USB, email...) plug-and-play, making full
use of link resources to quickly provision networks
• The next-generation NetEngine AR series provides the 3x performance in the industry, supports 20+
networking model, and supports flexible expansion of enterprise customer base .
• Provides a unified control platform for enterprise customers to manage their networks and optimizes the
entire process of network provisioning, service provisioning, and fault locating
• 10 Mbit/s to 30 Mbit/s Internet links replace 2 Mbit/s to 10 Mbit/s MPLS links to carry AI customer service,
reducing the private line cost by 40%. Application-based intelligent traffic steering ensures AI experience.
• A branch network can be provisioned within minutes, and devices are plug-and-play. Onsite deployment
by specialists is not required.
• Status visibility based on the entire network, branch nodes, users, and applications simplifies O&M,
implements E2E automation, and reduces the number of outsourcing personnel.
Hybrid links: MPLS, MSTP, Internet, and LTE links, which are selected based on site
requirements; bandwidth expansion at low costs
Optimal application interaction experience: differentiated communication quality assurance
based on application types
Lower O&M workload and standard and automated branch interconnection: plug-and-play
devices and ZTP
AR6280 (2U, 10 to
Huawei 12 Gbps)
ISR 4431
ISR 4351
ISR 800
Web
http://enterprise.huawei.com/en