Affordable, secure, easy-to-use broadband access for small offices
Cisco® SOHO 90 Series secure broadband routers provide secure connectivity to small and remote offices with up to five users and teleworkers.
The Cisco SOHO 90 Series router supports integrated security features of Cisco IOS® Software such as stateful-inspection firewall protection,
strong encryption for virtual private networks (VPNs), easy setup for nontechnical users with a Web-based setup tool, and advanced management
capabilities to lower operational costs.
Figure 1. Cisco SOHO 90 Series Secure Broadband Routers
The Cisco SOHO 90 Series is comprised of the Cisco SOHO 91 Ethernet Broadband Router, the Cisco SOHO 96 ADSL over ISDN Broadband
Router, and the Cisco SOHO 97 ADSL Broadband Router. The Cisco SOHO 91 router has an Ethernet WAN port for use with an external DSL or
cable modem. An asymmetric digital subscriber line (ADSL) modem is integrated into the Cisco SOHO 96 and SOHO 97 routers, with the Cisco
SOHO 96 ADSL over ISDN router supports remote management via a built-in ISDN port, and the Cisco SOHO 97 router supporting ADSL over
POTS. All three models offer a four-port 10/100 Ethernet LAN switch for connecting multiple PCs or network devices in a small-office network.
SECURE INTERNET ACCESS
Cisco SOHO 90 Series routers, recommended for up to five users, allow all users in a small office to share a secure broadband connection with an
integrated stateful-inspection firewall. Corporate teleworkers or small office users can also take advantage of Cisco SOHO 90 Series routers for VPN
connections to the corporate network. The routers can set up secure Triple Data Encryption Standard (3DES) encrypted connections using Cisco IOS
Software or users can initiate VPN tunnels from PC-based VPN clients on the LAN.
EASY SETUP AND DEPLOYMENT
Cisco SOHO 90 Series routers include the Cisco Router Web SetUp Tool (CRWS), a Web-based configuration tool that allows users to quickly selfinstall the router. Because the tool CRWS is Web-based, no additional software is required on the PC for configuration. Users simply point a
browser to the router and follow a few easy steps to quickly get the router up and running. Additionally, the Cisco Configuration Express service
allows enterprise or service provider customers who order products direct from Cisco to have preconfigured Cisco SOHO 90 Series routers shipped
from the manufacturer directly to the end users.
ADVANCED MANAGEMENT FEATURES FOR LOW COST OF OWNERSHIP
To simplify management and reduce ongoing operational costs, Cisco SOHO 90 Series routers take advantage of many local and remote debug and
troubleshooting features in Cisco IOS Software. The routers support centralized management and configuration updates with the Cisco CNS 2100
Intelligence Engine management appliance, further reducing operational costs.
Cisco SOHO 90 Series routers provide the right combination of integrated security features, a four-port 10/100 Ethernet LAN switch, and advanced
management features to secure broadband connections for small-office and home-office users. Cisco SOHO 90 Series routers use the same Cisco
IOS Software that is used in large service provider and enterprise networks, allowing small office users to take advantage of the proven reliability of
Cisco IOS Software. The SOHO 96 router has an integrated ISDN S/T port for out-of-band management.
FEATURES AND BENEFITS
Table 1. Key Product Features and Benefits of the Cisco SOHO 90 Series
Features Benefits
Shared Broadband Access Allows multiple users to share connections with a single IP address
Network Security Features with Cisco IOS
Software, Including Access Control Lists
(ACLs), Dynamic And Static Network and
Port Address Translation (NAT/PAT),
Lock & Key, Dynamic ACLs, and Router
and Route Authentication
• Offers internal users secure, per-application dynamic access control (stateful inspection) for all
traffic across perimeters
• Defends and protects router resources against denial-of-service (DOS) attacks
• Checks packet headers and drops suspicious packets
• Protects against unidentified, malicious Java applets
• Details transactions for reporting on a per-application, per-feature basis
Provides perimeter network security to prevent unauthorized network access
Software-Based IP Security (IPSec) 3DES
Encryption
Multiuser IPSec Pass-Through Supports teleworkers or multiple agents using VPN client software on their PCs, allowing IPSec
IPSec NAT Pass-Through Allows IPSec tunnels to be established from PC VPN clients in a LAN environment that uses NAT
Full-Function NAT (One-to-Many and
Many-to-Many)
Static-NAT-Based DMZ, Defining a Static
Mapping Between a Public IP Address/Port
and a Host on the LAN
Important notices, privacy statements, and trademarks of Cisco Systems, Inc. can be found on cisco.com.
Enables VPN tunnels to terminate in the router allowing all users connected to the router a secure
connection from the remote site to a corporate network
tunnels to pass through the router when VPN PC software clients are used
Support for PPTP tunnels, encrypted or unencrypted, initiated from the PC
to optimize use of IP addresses
Allows several applications and devices, including NetMeeting and H.323 phones, to be used
transparently from a LAN that deploys NAT
Allows access to applications (such as Web and Simple Network Management Protocol [SMTP]
servers) on the LAN from the WAN via a pinhole on the NAT firewall
Asynchronous Transfer Mode (ATM)
QoS (for Cisco SOHO 96 and SOHO 97
routers), Including ATM Traffic
Helps ensures QoS with ability to send traffic over the appropriate virtual circuit to provide ATMlevel shaping and help ensure that no head-of-line blocking can happen between circuits of different
or equal traffic classes
Universal Broadband Router (UBR),
nonreal-time Variable Bit Rate (VBRnrt),
and Constant Bit Rate (CBR) with per-VC
Queuing and Traffic Shaping
Easy Setup and Deployment
Plug and Play with Default Settings and
Allows nontechnical users to easily set up the router and customize advanced features
Web-Based Setup Tool
CRWS Allows nontechnical users to complete installation by simply by pointing a browser at the router and
providing user information
Cisco Configuration Express Lowers cost of deployment by shipping preconfigured units directly to end users without staging or
storing
Advanced Management Features for Low Cost of Ownership
Router Status Page in CRWS Tool Provides a Web-based visual representation of router configuration and feature status (firewall
Processor
Default DRAM* Memory
Maximum DRAM Memory
Default Flash* Memory
Maximum Flash Memory
WAN
Motorola RISC
64 MB
64 MB
8 MB
8 MB
• 10Base-T Ethernet (Cisco SOHO 91)
• ADSL over ISDN (Cisco SOHO 96)
• ADSL over basic telephone service (Cisco SOHO 97)
LAN
RJ-45 (Cisco SOHO 96)
LEDs
External Power Supply
* DRAM and Flash memory must be obtained from Cisco Systems
Four-port 10/100-Base-T with autosensing MDI/MDX for sensing cable type (straight-through or crossover)
ISDN BRI S/T port which can be configured for out-of-band management (Cisco SOHO 96 only)
10
Universal 100-240 VAC
Table 3. Memory Requirements and Software Feature Sets for Cisco SOHO 91, SOHO 96, and SOHO 97 Routers
Cisco SOHO 90 Series IOS Software Images
Flash DRAM
Cisco SOHO 90 Series Memory Requirements
IP Firewall/IPSec 3DES
Table 4. Protocols and Features Supported by Cisco SOHO 90 Series Routers
Cisco SOHO 90 Series Routers
Routing/Bridging
Point-to-Point Protocol over Ethernet (PPPoE), including TCP MSS adjust X
PPP over ATM (PPPoA); Cisco SOHO 96 and SOHO 97 only X
RFC 2684 routed and bridged (formerly RFC 1483) X
Transparent bridging X
IP routing X
Routing Information Protocol (RIP), RIPv2 X
QoS
ATM QoS (Cisco SOHO 96 and SOHO 97 only)—ATM traffic UBR, VBRnrt, and CBR with per-VC
queuing and traffic shaping
Per-VC queuing and shaping (8PVCs) (Cisco SOHO 96 and SOHO 97 only)
Important notices, privacy statements, and trademarks of Cisco Systems, Inc. can be found on cisco.com.
Route and router authentication X
Password Authentication Protocol (PAP), Challenge Handshake Authentication Protocol (CHAP),
X
Local Password
Generic routing encapsulation (GRE) tunneling X
IP basic and extended access lists X
Stateful inspection firewall X
IPSec 56-bit encryption X
IPSec 3DES encryption X
Multiuser IPSec pass-through (TCP and unencapsulated) X
Multiuser PPTP pass-through X
Terminal Access Controller Access Control System Plus (TACACS+) (Cisco SOHO 91 only)
Standards-based encryption (STAC) compression X
Ease of Use and Deployment
CRWS X
Cisco Configuration Express X
Management
Out-of-band Management via ISDN port SOHO 96 only X
SNMP, Telnet, console port X
Syslog X
SNTP client and server [SNMP] X
Trivial File Transfer Protocol (TFTP) client and server X
Service assurance agent for service monitoring X
ATM fault management Operation, Administration and Maintenance (OAM) (F5)—Segment continuity
check, segment and end-to-end loopback and Interim Local Management Interface (ILMI) support
Dying Gasp (Cisco SOHO 96 and SOHO 97 only)
Address Conservation and Allocation
NAT many to one (PAT) X
NAT many to many (multi-NAT) X
IP Control Protocol (IPCP) address negotiation and subnet delivery X
Dynamic Host Control Protocol (DHCP) client address negotiation X
DHCP client and server X
DHCP relay X
DHCP client host name (option 12) for certain cable services (Cisco SOHO 91 only)
Important notices, privacy statements, and trademarks of Cisco Systems, Inc. can be found on cisco.com.
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed on
Argentina • Australia • Austria • Belgium • Brazil • Bulgaria • Canada • Chile • China PRC • Colombia • Costa Rica • Croatia • Cyprus
Czech Republic • Denmark • Dubai, UAE • Finland • France • Germany • Greece • Hong Kong SAR • Hungary • India • Indonesia • Ireland • Israel
Italy • Japan • Korea • Luxembourg • Malaysia • Mexico • The Netherlands • New Zealand • Norway • Peru • Philippines • Poland • Portugal
Puerto Rico • Romania • Russia • Saudi Arabia • Scotland • Singapore • Slovakia • Slovenia • South Africa • Spain • Sweden • Switzerland • Taiwan
Thailand • Turkey • Ukraine • United Kingdom • United States • Venezuela • Vietnam • Zimbabwe
Copyright 2005 Cisco Systems, Inc. All rights reserved. CCSP, CCVP, the Cisco Square Bridge logo, Follow Me Browsing, and StackWise are trademarks of Cisco Systems, Inc.;
Changing the Way We Work, Live, Play, and Learn, and iQuick Study are service marks of Cisco Systems, Inc.; and Access Registrar, Aironet, ASIST, BPX, Catalyst, CCDA, CCDP,
CCIE, CCIP, CCNA, CCNP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity,
Empowering the Internet Generation, Enterprise/Solver, EtherChannel, EtherFast, EtherSwitch, Fast Step, FormShare, GigaDrive, GigaStack, HomeLink, Internet Quotient, IOS, IP/TV, iQ
Expertise, the iQ logo, iQ Net Readiness Scorecard, LightStream, Linksys, MeetingPlace, MGX, the Networkers logo, Networking Academy, Network Registrar, Packet, PIX, PostRouting, Pre-Routing, ProConnect, RateMUX, ScriptShare, SlideCast, SMARTnet, StrataView Plus, TeleRouter, The Fastest Way to Increase Your Internet Quotient, and TransPath are
registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between
Cisco and any other company. (0502R) 205276.BR_ETMG_JR_5.05