The Cisco CSS 11500 Series Content Services Switch is a compact
platform, delivering the richest Layer 4–7 traffic management services for
e-business applications.
Data Sheet
Pictured above, from
top to bottom, the
Cisco CSS 11501, the
Cisco CSS11503, and
the Cisco CSS 11506.
The Cisco CSS 11500, with the
award-winning Cisco Web Network
Services(WebNS),isspecificallydesigned to
provide robust transport and application
(Layer 4–7) services for Internet and
intranet data centers. The Cisco CSS 11500
builds on the success of the Cisco CSS
11000 Series in five key areas:
• Introduces an intelligent, distributed
architecture to help organizations meet
the real-world scaling requirements of
today’s e-business infrastructure
• Improves site availability and
transaction integrity by introducing
Adaptive Session Redundancy (ASR)
—a new industry standard in
stateful failover
• Delivers the greatest flexibility of any
content switch in its class for
customizing combinations of ports,
performance, and services
• Scales secured transaction performance
through support of an integrated,
high-capacity Secure Sockets Layer
(SSL) module
• Protects investments by enabling
upgrades of performance, ports, and
services through modularity
The Cisco CSS 11500 Series Content
Services Switch enables businesses to
simultaneously reduce costs by optimizing
data center resources and boosting
productivity, as well as offering a superior
online experience for customers, business
partners, and employees. Through content
fast switching and forwarding, the Cisco
CSS 11500 Series switches improve
utilization, responsiveness, availability,
scalability, and security ofWeb sites, server
farms, cache clusters, and firewall systems.
Premier Traffic Management
for E-Business
In addition to the Cisco CSS 11500
switches, Cisco delivers a complete product
line, including the Cisco CSS 11050,
CSS 11150, andContent SwitchingModule
(CSM)—an integrated services module for
®
the Cisco Catalyst
6500 Series Switch and
Cisco7600 InternetRouter.TheCisco CSM
attains the highest performance and offers
transport and application (Layer 4–7)
features as rich as those in WebNS.
Through full integration with Cisco IOS
®
Software, the Cisco Catalyst 6500, and the
Cisco 7600 Internet Router—Cisco CSM
also supports the highest port density and
comprehensive internetworking features.
The Cisco CSS 11500 and CSM together
are, simply, the ideal choices forenterprises
and service providers deploying content
services.
Cisco Systems, Inc.
Page 1 of 10
Scalable Distributed Architecture for
Today and Tomorrow
In a typical deployment, the Cisco CSS 11500 intercepts a request
from a client browser, characterizes the flow by reading Hypertext
TransferProtocol(HTTP) headers, selectsa destination server based
on resource availability, and forwards the flow. Because it quickly
processes the entire HTTP header (full URL, cookie, and extensive
resource verification information), the Cisco CSS 11500 identifies
the user, what the user wants to do, and how best to service the
user’s request within a global Web infrastructure.
The Cisco CSS 11500 provides a fully distributed architecture—all
modules in the system contribute to the overall processing and
memory needs for policy-based flow setup and flow forwarding. In
this way, performance scales linearly as modules are added, and
heavy traffic that hits one module can be balanced to others within
a single system. Therefore, the Cisco CSS 11500 balances trafficnot
only within a data center but also across its own internal modules.
This innovative architecture addresses the primary limitations of
PC-and application-specific integrated circuit (ASIC)-based
solutions. Unlike PC-based systems, the network processors of the
Cisco CSS 11500 provide ample packet processing power and
bandwidth, avoiding the bottlenecks of the PC bus and a single
central processor. And unlike ASIC-based platforms, the powerful,
yet adaptable processors of the Cisco CSS 11500 enable easy
integration of new software features.
The Cisco CSS 11500 can apply all itsprocessing power to anyport
at any time, and it can grow with changing feature and scalability
requirements. The system is designed to readily adapt to changing
e-business needs—without complex and costly hardware upgrades.
New Standard in High Availability
The Cisco CSS 11500 delivers ASR—the industry’s first stateful
Layer 5 session redundancy feature that enables failover of
important flows while maximizing performance.
Some flows—such as a long-lived File Transfer Protocol (FTP) or a
database session—may be mission critical, but many flows are not.
Mostsolutions on themarket today requireall traffic—important or
not—to be backed up from one unit to another. If the majority of
flows is not critical, most of system performance is wasted on
unnecessary back ups.
With ASR, the Cisco CSS 11500 may be configured so that critical
flows are marked asreplication worthy, whereas others need not be
markedas such. ASR focuses traffic management resourcesprecisely
where needed.
SSL Integration for Security and Performance
Cisco offers the most scalable integratedSSL solutionsof anyLayer
4–7 switches.
SSL, the industry standard for securetransport oftraffic fromclient
browsers to Webservers, presents two critical challenges for today’s
e-business infrastructure. First, because SSL encrypts data and
headers, it obscures the request-specific information that Layer 4–7
switching decisions are made on.Second, SSLauthentication places
a high processing load for each SSL flow setup.
The Cisco CSS 11500 with integrated SSL modules meets both of
these challenges by combining leading SSL acceleration technology
with the Cisco WebNS technology. In addition to superior price
performance, the SSL module simplifies the management of digital
certificates and offers new possibilities in optimizing the
switch-to-serverarchitecture for security andperformance. And SSL
transaction performance may be scaled by adding multiple SSL
modules to a chassis.
Modularity for Investment Protection
Through its modular design, the Cisco CSS 11500 will meet your
functional requirements today while providing for expansion for
tomorrow’s needs. The Cisco CSS 11500 Session Accelerator
Module is a cost-effective way to add performance for flow setup
and flow forwarding. Aselection ofinput/output (I/O) modules not
only offers the choice of port densities of Fast or Gigabit Ethernet,
but also boosts flow performance. Optional memory upgrades
increase the number of simultaneous flows supported. PCMCIA
Flash memory and hard disks are supported.
Local and Global Load Balancing
Bysupporting the latest advancesin local and global load balancing,
the Cisco CSS 11500 Series Switch not only dramatically increases
site availability—greatly improving user response time and
retention—but also optimally utilizes site resources, thereby
decreasing the cost to serve end users.
The Cisco CSS 11500 learns where specific content resides, either
locally or remotely, and dynamically selects the best Web server or
cache for specific content requests.
Local server selection is based on server load and application
response time, as well as traditional least connection and
round-robin algorithms. Any application that uses standard TCP or
UserDatagram Protocol (UDP) protocols can also be load balanced,
including firewalls, mail, news, chat, and Lightweight Directory
Access Protocol (LDAP).
The Cisco CSS 11500 also provides a complete solution for building
and provisioning Internet-scale global content distribution and
delivery. Whereas local load-balancing features determine the best
device within a data center, global load-balancing functions choose
the best data center in the Internet to service requests.
The Cisco CSS 11500 performs comprehensive resource verification
before routing user requests, ensuring that they are directed to the
location that has the best response time and the least load for the
requested content. Cisco supports global load balancing through
redirection based on both DomainName System(DNS) andHTTP.
The DNS mechanism is fast and scalable; the HTTP method
provides the highest degree of control.
Cisco CSS 11500 Series Content Services Switch:
Chassis and Modules
The Cisco CSS 11500 Series Content Services Switch includes four
models:
• A one-rack unit, fixed-configuration Cisco CSS 11501 (6-Gbps
aggregate throughput)
• A one-rack unit, fixed-configuration Cisco CSS 11501 with SSL
termination (6-Gbps aggregate throughput)
• A two-rackunit, three-slot Cisco CSS 11503(20-Gbps aggregate
throughput)
• A five-rack unit, six-slot Cisco CSS 11506 (40-Gbps aggregate
throughput)
Site and System Security
The Cisco CSS 11500 with Cisco WebNS Software ensures high
levels of security without compromising site performance. The
Cisco CSS 11500 provides stateful, content-based access control,
and supports security policies based on any combination of source
address, destination address, protocol, TCP port, or URL.
Wire-speedNetwork Address Translation(NAT)protectsreal server
IP addresses.
For additional security, the Cisco CSS 11500 intelligently directs
traffic across multiple firewalls. By load balancing firewalls, the
Cisco CSS 11500 eliminates performance bottlenecks and single
points of failure that result in system downtime, a situation thatcan
close off the connection to the network and disrupt e-commerce
purchases or other mission-critical transactions.
Manage Through Simple GUIs or
Sophisticated Tools
Effective management tools reduce the ongoing cost of operating a
business-critical Web site. The Cisco CSS 11500 with WebNS
supports a wide range of management tools that offer simplicity,
security, and flexibility. For configuration, administrators have a
®
choice of a Cisco IOS
Software-like command-line interface (CLI)
or an intuitive, embedded graphical user interface (GUI). For large
networks,the Cisco CSS 11500 may be managed through enterprise
management systems such as CiscoWorks CiscoView and
tiered-access tools such as the Cisco Hosting Solutions Engine. For
integration with customized management systems or even user
applications requiring network interaction, the Cisco CSS 11500
offers an Extensible Markup Language (XML)-based,
programmatic management application programming interface
(API), Simple Network Management Protocol (SNMP), Remote
Monitoring (RMON), and log files. Effective management tools
reduce the ongoing cost of operating a business-critical Web site.
The Cisco CSS 11501 and the Cisco CSS 11501 with SSL
termination supports eight 10/100 Ethernet ports and one Gigabit
Ethernet port though an optional small-form factor, pluggable
gigabit interface converter (SFP GBIC). Both Cisco CSS 11501
modelsfeature a consoleport, an Ethernet portfor management and
two PCMCIA slots that hold up to two 256-MB Flash memory
disks, up to two512-MB hard disks, or one of each. TheCisco CSS
11501 with SSL termination delivers 1,000 SSL transactions per
second and 250 Mbps of bulk encryption (ARC4) by exploiting an
internal card with state-of-the-art cryptology chips.
The Cisco CSS 11503 and Cisco CSS 11506 are both modular
platforms with interchangeable modules. The Cisco CSS 11503 and
Cisco CSS 11506 may also share memory, disks and GBICs. The
CiscoCSS 11501 has fixed memoryand does support the same disks
and SFP GBICs as the other two models.
The Cisco CSS 11506 requires at least one switch control module
(SCM) and may be configured with a second in standby mode. With
the required SCM in one slot, the Cisco CSS 11506 has five
additional slots supporting any combination of I/O, SSL, or session
accelerator modules. The Cisco CSS 11503 requires a SCM and
accommodates any two of the other optional modules.
The Cisco CSS 11506 supports not only redundancy in switch
control modules but also redundant power supplies and redundant
switch modules (20 Gbps each). All SCMs support redundant
disk drives.
All modules participate in flow setup, but they differ primarily in
control functions, performance, SSL capabilities, and I/O. Each
Cisco CSS 11500 Module consists of one high-speed MIPS RISC
processor for flow setup, one network processor for flow
forwarding, one classification engine for accelerated lookups in
bridge/access control list (ACL) tables, and up to 288 MB of
RDRAM.
Switch Control Module for the Cisco CSS 11500 Content Services Switch
The Cisco CSS 11500 Switch Control Module not only governs the entire system, it also contributes to I/O density
and flow performance. The SCM comes standard with 2-Gigabit Ethernet ports—supporting small-form factor,
pluggable gigabit interface converters (SFPGBICs)—and hasa consoleport andEthernet port for management. The
SCM also features two PCMCIA slots that hold up to two 256-MB Flash memory disks, up to two 512-MB hard
disks, or one of each.
SSL Module for the Cisco CSS 11500 Content Services Switch
The Cisco CSS 11500 SSL Module is the ideal solution for handling high volumes of SSL transactions that occupy
today’s e-business data centers. The module integrates state-of-the-art SSL processors into the leading content
switching technology of Cisco WebNS. In addition to superior price performance, the SSL module simplifies the
management of digital certificates and offers new possibilities in optimizing the switch-to-server architecture for
security and performance. The SSL module delivers 1,000 SSL transactions per second and 250 Mbps of bulk
encryption (ARC4).
I/O Modules for the Cisco CSS 11500 Content Services Switch
The Cisco CSS 11500 I/O modules deliver port density and flow performance. The product line supports three types
of I/O modules:
• Two-port Gigabit Ethernet
• Sixteen-port Fast Ethernet
• Eight-port Fast Ethernet
The Fast Ethernet ports are 10/100BASE-TX with standard RJ-45 connectors, whereas the Gigabit Ethernet ports
require small-form factor GBICs (1000BASE-SX or 1000BASE-LX).
Session Accelerator Module for the Cisco CSS 11500 Content Services Switch
The session accelerator module is a cost-effective way to add flow performance when additional connectivity is not
required. Using the same flow setup and forwarding processors as the I/O modules, it provides the flexibility to
optimize the system for port density and performance. Table 1 gives the features of the Cisco CSS 11500 models.
Table 1 Cisco CSS 11500 Models: Quick Look
Cisco CSS11501Cisco CSS11503Cisco CSS11506
Module Slots0 (Fixed Configuration)36
Included in Base
Configuration
Maximum Gigabit
Ethernet Ports
Maximum 10/100
Ethernet Ports
SSL TerminationNoYesYes
2-port Gigabit Ethernet
I/O Module
16-port 10/100 Ethernet I/OMaximum of 2Maximum of 5
8-port 10/100 Ethernet I/OMaximum of 2Maximum of 5
SSL ModulesMaximum of 2Maximum of 4
Session Accelerator
• Integrated global load balancing with HTTP and DNS-based redirection
• Routing Information Protocol (RIP) versions 1 and 2, Open Shortest Path First
(OSPF)
• Server/node operating system compatibility: Any TCP/IP OS, including Windows
XP, Windows 2000, Windows NT, Windows 98, Windows 95, all UNIX platforms,
LINUX, and Mac OS
• Dynamic content support: Active Server Pages (ASP), Visual Basic Script, ActiveX,
Java, Virtual Reality Markup Language (VRML), Common Gateway Interface (CGI),
CoolTalk, NetMeeting, RealAudio, RealVideo, NetShow, QuickTime, PointCast, Any
HTTP Encapsulated Data
ACA TS001
EN60950/IEC60950
AS/NZS 3260
EN60825/IEC60825
CSA-22.2 No. 950-UL1950
Electromagnetic compliance (emissions)
FCC CFR 47 Part 15 Class A
FCC CFR 47 Part 15.109 Class B
ICES-003 Class A
CISPR 22 EN55022 Class B (to 1 GHz)
CISPR 22 EN55022 Class A
EN61000-3-2/IEC-1000-3-2 (power line harmonics)
EN61000-3-2/IEC-1000-3-2 (power line harmonics)
Electromagnetic compliance (emissions)
VCCI V-3/01.4 Class B (to 1GHz)
VCCI Class A
ICES-003 Class B
AS/NZS 3548 Class A
AS/NZS3548 Class B
ImmunityEN300386 (EMC for network equipment)
1. Nonoperating (trapezoidal pulse): 20G 1, 52 in./sec (1.32 m/sec) 1 G is a value of acceleration, where G equals 32.17 ft/sec** (9.81 m/sec**)
EN61000-4-8/IEC-1000-4-8 (Power frequency magnetic field immunity)
EN61000-4-3/IEC-1000-4-2 (electrostatic discharge [ESD])
EN61000-4-11/IEC-1000-4-11 (voltage dips and sags)
EN61000-4-3/IEC-1000-4-3 (radiated immunity)
ETS-300386
EN61000-4/IEC-1000-4-4 (EFT)
FCC Class A Compliance Notice (United States)
EN61000-4-5/IEC-1000-4-5 (surge)
ICES-003 Class A Compliance Notice (Canada)
EN61000-4-6/IEC-1000-4-6 (low-frequency conducted immunity)
VCCI Class A Compliance Notice (Japan)
Cisco Systems, Inc.
Page 9 of 10
Corporate Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
European Headquarters
Cisco Systems Europe
11 Rue Camille Desmoulins
92782 Issy-les-Moulineaux
Cedex 9
France
www-europe.cisco.com
Tel: 33 1 58 04 60 00
Fax: 33 1 58 04 61 00
Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed on the
Cisco Web site at www.cisco.com/go/offices
Argentina • Australia • Austria • Belgium • Brazil • Bulgaria • Canada • Chile • China PRC • Colombia • Costa Rica • Croatia
Czech Republic • Denmark • Dubai, UAE • Finland • France • Germany • Greece • Hong Kong SAR • Hungary • India • Indonesia • Ireland
Israel • Italy • Japan • Korea • Luxembourg • Malaysia • Mexico • The Netherlands • New Zealand • Norway • Peru • Philippines • Poland
Portugal • Puerto Rico • Romania • Russia • Saudi Arabia • Scotland • Singapore • Slovakia • Slovenia • South Africa • Spain • Sweden
Switzerland • Taiwan • Thailand • Turkey • Ukraine • United Kingdom • United States • Venezuela • Vietnam • Zimbabwe