The HPE FlexNetwork MSR3000 Router Series, the next generation of router from Hewlett Packard Enterprise (HPE), is a component
of the HPE FlexBranch solution, which is a part of the comprehensive HPE FlexNetwork architecture. These routers feature a modular
design that delivers unmatched application services for medium
sized branch offices. This gives your IT personnel the
benefit
The MSR3000 routers use the latest multicore CPUs, offer Gigabit switching, provide an enhanced PCI bus, and ship with the latest
version of HPE Comware software to help ensu
featured, resilient routing platform, including IPv6 and MPLS, with up to 5 Mpps forwarding capacity and 3.3 Gbps of IPSec VPN
encrypted throughput. These routers also support HPE Open Application Platform (OAP) modules to deliver integrated industryleading HPE AllianceOne partner applications such as virtualization, unified communications and collaboration (UC&C), and
application optimization capabilities.
The MSR3000 series provides an agile, flexible network infrastructure that enables you to quickly adapt to changing business
requirements while delivering integrated concurrent services on a single, easy-to-manage platform.
HPE FlexNetwork MSR3012 AC Router - Front
HPE FlexNetwork MSR3024 AC Router - Front
- to large-
of reduced complexity, and simplified configuration, deployment, and management.
re high performance with concurrent services. The MSR3000 series provides a full
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Overview
2
HPE FlexNetwork MSR3044 Router- Front
HPE FlexNetwork MSR3064 Router - Front
Models
Description
SKU
HPE MSR3012 AC Router
JG409B
HPE FlexNetwork MSR3024 AC Router
JG406A
HPE FlexNetwork MSR3044 Router
JG405A
HPE FlexNetwork MSR3064 Router
JG404A
Key features
• Up to 5 Mpps forwarding performance; support for multiple concurrent services
• Open Application Platform for HPE AllianceOne applications
• Embedded security features with hardware-based encryption, stateful firewall, NAT, and VPNs
• No additional licensing complexity; no cost for advanced features
•
Zero-touch solution, with single pane-of-glass managemen
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
3
Performance
full service performance (NAT + QoS + ACL Performance by Platform, IMIX Traffic), 1Gbps for MSR3012/3024,
ware encryption accelerator to improve
encryption performance; IPSec encryption throughput can be up to 3.3 Gb/s with a maximum of 4,000 IPSec VPN tunnels,
support up to 2000 VRF instances.
Connectivity
IP technology that provides Layer 2 connectivity between distant Layer 2 network sites across an IP routed
scale data center that requires Layer 2
based network, using the "MAC in UDP" package
ed physical site
ckbone
is transparent to the customer sites, which can communicate with each other as if they were on the same LAN. The following
-
Network mobility (NEMO) enables a node to retain the same IP address and maintain application connectivity when the node
board Gigabit Ethernet ports, 8 or 24 ports GE supported on
port Fast/Giga Ethernet,POE/POE+; mobility access with 3G (WCDMA/HSPA)/4G LTE SIC modules and
upports internal loopback testing for maintenance purposes and an increase in availability; loopback detection protects
n various
ses USB memory disk to download and upload configuration/OS image files; supports an external USB 3G/4G modem for a
-
speed detection plus auto duplex and MDI/MDI-X
• Excellent forwarding performance
• Powerful security capacity
• Ethernet Virtual Interconnect (EVI)
• VXLAN (Virtual eXtensible LAN)
• Virtual Private LAN Service (VPLS)
Excellent
1.5Gbps for MSR3044, 2Gbps for MSR3064.
The MSR3000 series is available with standard or high encryption, an embedded hard
EVI is a MAC-innetwork. It is used for connecting geographically dispersed sites of a virtualized largeadjacency.
VXLAN (Virtual eXtensible LAN, scalable virtual local area network) is an IPof Layer VPN technology. VXLAN can be based on an existing ISP or enterprise IP networks for decentraliz
provides Layer 2 communication, and can provide service isolation for different tenants.
Virtual Private LAN Service (VPLS) delivers a point-to-multipoint L2VPN service over an MPLS or IP backbone. The ba
protocols support on MSRs, RFC4447, RFC4761 and RFC4762, BFD detection in VPLS, Support hierarchical HOPE (H
VPLS), MAC address recovery in H-VPLS to speed up convergence.
• NEMO (Network Mobility)
travels across networks. It allows location-independent routing of IP datagrams on the Internet.
•High-density port connectivity
Provides up to 10 interface module slots and up to three onone HMIM module.
• Multiple WAN interfaces
Provides traditional links with E1, T1, G.SHDSL, and ISDN links; high-density Ethernet access with WAN Gigabit Ethernet
and LAN 4- and 93G/4G USB modems, and high-speed T3 and 155 Mb/s OC3 access options
• Packet storm protection
Protects against broadcast, multicast, or unicast storms with user-defined thresholds
•Loopback
S
against incorrect cabling or network configurations and can be enabled on a per-port or per-VLAN basis for added flexibility
• 3G/4G LTE access support
Provides 3G/4G LTE wireless access for primary or backup connectivity via a 3G/4G LTE SIC module certified o
cellular networks; optional carrier 3G/4G LTE USB modems are available
• USB interface
U
3G/4G WAN uplink
• Flexible port selection
Provides a combination of fiber and copper interface modules, 100/1000BASE-X support, and 10/100/1000BASE-T auto
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
4
Layer 3 routing
ses a distance vector algorithm with UDP packets for route determination; supports RIPv1 and RIPv2 routing; includes loop
ior Gateway Protocol (IGP), which supports ECMP, NSSA, and
ing path vectors; uses TCP for enhanced reliability
IS routing and extended
only network design
only networks by encapsulating the IPv6 packet into a standard IPv4 packet; supports
Site Automatic Tunnel Addressing Protocol (ISATAP) tunnels; is an important element
ses BGP to advertise routes across Label Switched Paths (LSPs), but uses simple labels to forward packets from any Layer
aceful restart for reduced failure
d
istribution Protocol (LDP);
routable protocols;
ircuits (SVCs), Martini
llows custom filters for increased performance and security; supports ACLs, IP prefix, AS paths, community lists, and
aggregate policies
• Static IPv4 routing
• Routing Information Protocol (RIP)
• Open shortest path first (OSPF)
• Border Gateway Protocol 4 (BGP-4)
• Intermediate system to intermediate system (IS-IS)
• Static IPv6 routing
• Dual IP stack
• Routing Information Protocol next generation (RIPng)
Delivers faster convergence; uses this link-state routing Inter
MD5 authentication for increased security and graceful restart for faster failure recovery
Delivers an implementation of the Exterior Gateway Protocol (EGP) utiliz
for the route discovery process; reduces bandwidth consumption by advertising only incremental updates; supports extensive
policies for increased flexibility; scales to very large networks
Uses a path vector Interior Gateway Protocol (IGP), which is defined by the ISO organization for ISby IETF RFC 1195 to operate in both TCP/IP and the OSI reference model (Integrated IS-IS)
Provides simple manually configured IPv6 routing
Maintains separate stacks for IPv4 and IPv6 to ease the transition from an IPv4-only network to an IPv6-
Extends RIPv2 to support IPv6 addressing
Provides OSPF support for IPv6
Extends BGP-4 to support Multiprotocol BGP (MBGP), including support for IPv6 addressing
Extends IS-IS to support IPv6 addressing
Allows IPv6 packets to traverse IPv4manually configured, 6to4, and Intrafor the transition from IPv4 to IPv6
U
2 or Layer 3 protocol, which reduces complexity and increases performance; supports gr
impact; supports LSP tunneling and multilevel stacks
Allows Layer 3 VPNs across a provider network; uses Multiprotocol BGP (MP-BGP) to establish private routes for increase
security; supports RFC 2547bis multiple autonomous system VPNs for added flexibility; supports IPv6 MPLS VPN
Establishes simple Layer 2 point-to-point VPNs across a provider network using only MPLS Label D
requires no routing and therefore decreases complexity, increases performance, and allows VPNs of nonuses no routing information for increased security; supports Circuit Cross Connect (CCC), Static Virtual C
draft, and Kompella-draft technologies
A
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
5
Security
Prevention System (IPS) detects and protects the branch office from security threats. Optional HPE
based model. Interfaces are assigned to zones, and inspection policy is applied to traffic moving
es offer considerable flexibility and granularity, so different inspection policies can be
ugh the VPN Address Management (VAM) protocol, making
VPN establishment available between enterprise branches that use dynamic addresses to access the public network;
r features, such as NAT traversal
upports powerful ACLs for both IPv4 and IPv6; ACLs are used for filtering traffic to prevent unauthorized users from
accessing the network, or for controlling network traffic to save resources; rules can either deny or permit traffic to be
rules can be based on a Layer 2 header or a Layer 3 protocol header; rules can be set to operate on specific dates
llows normal packets to be forwarded correctly, but discards the attaching packet due to lack of reverse path route or
many NAT, and NAT control, enabling NAPT to support multiple connections; supports
device; with authentication and encryption, it protects against IP
spoofing and plain text password interception; increases the security of SFTP transfers
Convergence
Specific Multicast (SSM) to manage IPv4 multicast networks; supports
many transmission of information;
• IPS
Built-in Intrusion
integration filters for client-side, branch protection from exploits and vulnerabilities
• Enhanced stateful firewall
Application layer protocol inspection, Tr
Support more L4 and L7 protocols like TCP, UDP, UDPSIP, H.323, SCCP.
• Zone based firewall
Zone-Based Policy Firewall changes the firewall configuration from the older interfaceeasily understood zonebetween the zones. Inter-zone polici
applied to multiple host groups connected to the same router interface.
• Auto Discover VPN (ADVPN):
Collects, maintains, and distributes dynamic public addresses thro
compared to traditional VPN technologies, ADVPN technology is more flexible and has riche
of ADVPN packets, AAA identity authentication, IPSec protection of data packets, and multiple VPN domains
• IPSec VPN
Supports DES, 3DES, and AES 128/192/256 encryption, and MD5 and SHA-1 authentication
• Access control list (ACL)
S
forwarded;
or times
•Terminal Access Controller Access-Control System (TACACS+)
Delivers an authentication tool using TCP with encryption of the full authentication request, providing additional security
• Unicast Reverse Path Forwarding (URPF)
A
incorrect inbound interface; prevents source spoofing and distributed attacks
• Network login
Allows authentication of multiple users per port
• RADIUS
Eases security access administration by using a user/password authentication server
• Network address translation (NAT)
Supports one-to-one NAT, many-toblacklist in NAT, a limit on the number of connections, session logs, and multi-instances
• Secure Shell (SSHv2)
Uses external servers to securely log in into a remote
• Internet Group Management Protocol (IGMP)
Utilizes Any-Source Multicast (ASM) or SourceIGMPv1, v2, and v3
• Protocol Independent Multicast (PIM)
Defines modes of Internet IPv4 and IPv6 multicasting to allow one-to-many and many-tosupports PIM Dense Mode (DM), Sparse Mode (SM), and Source-Specific Multicast(SSM)
• Multicast Source Discovery Protocol (MSDP)
Allows multiple PIM-SM domains to interoperate; is used for inter-domain multicast applications
• Multicast Border Gateway Protocol (MBGP)
Allows multicast traffic to be forwarded across BGP networks and kept separate from unicast traffic
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
6
Layer 3 services
bandwidth
optimization for file service and web applications. The policy engine module determines which traffic can be optimized and
which optimization action should be taken. A pair of WAN optimization equipment can discover each other automatically and
PT) enables communication between IPv4 andIPv6 nodes by
lation, and according to different protocols, performs
semantic translation for packets. This technology is only suitable for communication between a pure IPv4 node and a pure
er IP host in the same subnet; supports static ARPs; gratuitous ARP allows detection
of duplicate IP addresses; proxy ARP allows normal ARP operation between subnets or when subnets are separated by a
implifies the management of large IP networks and supports client and server; DHCP Relay enables DHCP operation across
Product architecture
Defined
based
Flow matches packets against one or
core processors, gigabit switching, and PCIE bus; external RPS or dual internal power supplies, and internal and
rovides unmatched application and services flexibility, with the potential to deliver the functionality of multiple devices,
mproves the bandwidth of I/O module slots from 100 Mb/s to 1000 Mb/s, and improves uplink performance from 1 Gb/s
Eases utilization of the main processor by transmitting Layer 2 packets directly via the MGF
Convergence
Specific Multicast (SSM) to manage IPv4 multicast networks; supports
many transmission of information;
Allows multicast traffic to be forwarded across BGP networks and kept separate from unicast traffic
• WAN Optimization
MSR performs optimization using TFO and a combination of DRE, Lempel-Ziv (LZ) compression to provide the
complete the negotiation to establish a TCP optimization session.}
•NAT-PT
Network Address Translation – Protocol Translation (NATtranslating between IPv4 and IPv6 packets. It performs IP address trans
IPv6 node.
• Address Resolution Protocol (ARP)
Determines the MAC address of anoth
Layer 2 network
• User Datagram Protocol (UDP) helper
Redirects UDP broadcasts to specific IP subnets to prevent server spoofing
•xDynamic Host Configuration Protocol (DHCP)
S
subnets
•SDN/OpenFlow
OpenFlow is the communications interface defined between the control and forwarding layers of a SDN (SoftwareNetworking) architecture. OpenFlow separates the data forwarding and routing decision functions. It keeps the flowforwarding function and employs a separate controller to make routing decisions. Open
more flow tables. MSR support OpenFlow 1.3.1
• Ideal multiservice platform
Provides WAN router, Ethernet switch, 3G/4G WAN, statful firewall, VPN, and SIP/voice gateway on MSRs
• Advanced hardware architecture
Provides multi
external CF cards are offered; new high-performance MIM modules (HMIM) supported
• New operation system
Ships with new Comware v7 operating system delivering the latest in virtualization and routing
• Open Application Platform architecture
P
creating capital and operational expense savings and lasting investment protection
•Field-programmable gate array (FPGA)
O
to 10 Gb/s
• Multi Gigabit Fabric (MGF)
• Internet Group Management Protocol (IGMP)
Utilizes Any-Source Multicast (ASM) or SourceIGMPv1, v2, and v3
• Protocol Independent Multicast (PIM)
Defines modes of Internet IPv4 and IPv6 multicasting to allow one-to-many and many-tosupports PIM Dense Mode (DM), Sparse Mode (SM), and Source-Specific Multicast(SSM)
• Multicast Source Discovery Protocol (MSDP)
Allows multiple PIM-SM domains to interoperate; is used for inter-domain multicast applications
• Multicast Border Gateway Protocol (MBGP)
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
7
Layer 2 switching
upports standard IEEE 802.1D STP, IEEE 802.1w Rapid Spanning Tree Protocol (RSTP) for faster convergence, and IEEE
Supports command switch to easily change switched ports to routed (maximum of four Fast Ethernet ports)
Quality of Service (QoS)
anages traffic uniformly, and hierarchically schedules traffic by user, network service, and application; provides more
Supports traffic shaping, MPLS QoS, MP QoS/LFI, and Control Plane Policing (CoPP).
Integration
to 7 services; monitors the health status
rovides enhanced stateful packet inspection and filtering; delivers advanced VPN services with Triple DES (3DES) and
n at high performance and low latency, URL filtering, and application
the
link
Additional information
implifies and streamlines deployment, management, and training through the use of a common operating system, thereby
llows new and custom features to be brought rapidly to market through engineering efficiencies, delivering better initial and
Provides support for RoHS and WEEE regulations
• Spanning Tree Protocol (STP)
S
802.1s Multiple Spanning Tree Protocol (MSTP)
• Internet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) protocol snooping
Controls and manages the flooding of multicast packets in a Layer 2 network
• Port mirroring
Duplicates port traffic (ingress and egress) to a local or remote monitoring port
• VLANs
Supports up to 4,094 VLANS or IEEE 802.1Q-based VLANs
• sFlow
Allows traffic sampling
• Define port as switched or routed
• Traffic policing
Supports Committed Access Rate (CAR) and line rate
• Congestion management
Supports FIFO, PQ, CQ, WFQ, CBQ, and RTPQ
• Weighted random early detection (WRED)/random early detection (RED)
Delivers congestion avoidance capabilities through the use of queue management algorithms
• Hierarchical quality of service (HQoS)/Nested QoS
M
granular traffic control and quality assurance services than traditional QoS
• Other QoS technologies
• Embedded NetStream
Improves traffic distribution using powerful scheduling algorithms, including Layer 4
of servers and firewalls
• Embedded VPN and firewall
P
Advancekd Encryption Standard (AES) encryptio
prioritization and enhancement
• SIP trunking
Delivers multiple concurrent calls on one link; the carrier authenticates only the link, rather than carrying each SIP call on
• OPEX savings
S
cutting costs as well as reducing the risk of human errors associated with having to manage multiple operating systems across
different platforms and network layers
• Faster time to market
A
ongoing stability
• Green initiative support
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
8
Management
in support
s network administrators to centrally manage all network elements with a variety of automated
tasks, including discovery, categorization, baseline configurations, and software images; the software also provides
multiple privilege levels with password protection; ACLs provide
ent Information Base (MIB) plus
ses standard SNMP to monitor essential network functions; supports events, alarm, history, and statistics group plus a
ffers different mechanisms for configuration updates; FTP allows bidirectional transfers over a TCP/IP network; trivial FTP
fer Protocol (SFTP) runs over an SSH
-
ll logs, traps, and debugging information
generated by the system and maintains them in order of severity; outputs the network information to multiple channels based
m port and terminal interface; provides access through terminal interface, telnet,
nalyzes network performance and service quality by sending test packets, and provides network performance and service
rs such as jitter, TCP, or FTP connection delays; allows network manager to determine overall network
Integrates seamlessly into existing authentication services
Ease of deployment
Supports both USB disk auto deployment and 3G SMS auto deployment
Warranty and support
for warranty and support information included with your
; for details on the software releases
available with your product purchase, refer to http://www.hpe.com/networking/warrantysummary
• HPE Intelligent Management Center (IMC)
• Industry-standard CLI with a hierarchical structure
• Management security
• SNMPv1, v2, and v3
• Remote monitoring (RMON)
• FTP, TFTP, and SFTP support
• Debug and sampler utility
• Network Time Protocol (NTP)
• Information center
Integrates fault management, element configuration, and network monitoring from a central vantage point; builtfor third-party devices enable
configuration comparison tools, version tracking, change alerts, and more
Reduces training time and expenses, and increases productivity in multivendor installations
Restricts access to critical configuration commands; offers
Telnet and SNMP access; local and remote syslog capabilities allow logging of all access
Provide complete support of SNMP; provide full support of industry-standard Managem
private extensions; SNMPv3 supports increased security using encryption
U
private alarm extension group
O
(TFTP) is a simpler method using User Datagram Protocol (UDP); Secure File Trans
tunnel to provide additional security
Supports ping and trace route for both IPv4 and IPv6
Synchronizes timekeeping among distributed time servers and clients; keeps timekeeping consistent among all clock
dependent devices within the network so that the devices can provide diverse applications based on the consistent time
Provides a central repository for system and network information; aggregates a
on user-defined rules
• Management interface control
Provides management access through mode
or SSH
•Network Quality Analyzer (NQA)
A
quality paramete
performance and diagnose and locate network congestion points or failures
•Role-based security
Delivers role-based access control (RBAC); supports 16 user levels (0~15)
• Standards-based authentication support for LDAP
• Zero-touch deployment
• 1-year Warranty
See http://www.hpe.com/networking/warrantysummary
product purchase.
• Software releases
To find software for your product, refer to http://www.hpe.com/networking/support
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Standard Features
9
Resiliency and high availability
interconnecting multiple
devices through stack ports. The customer can manage all the devices in the IRF stack by managing the logical device, which
g
llows groups of two routers to dynamically back each other up to create highly available routed environments; supports
identifying potential problems as early as possible;
on
layer protocols such as
routing protocols and MPLS
Investment protection
Supports existing SIC and MIM modules, transceivers, and cables for investment protection
• Intelligent Resilient Fabric (IRF)
Intelligent Resilient Fabric (IRF), allows the customer build an IRF stack, namely a logical device, by
is cost-effective like a box-type device, and scalable and highly reliable like a chassis-type distributed device.
• Backup Center
Acts as a part of the management and backup function to provide backup for device interfaces; delivers reliability by switchin
traffic over to a backup interface when the primary one fails
• Virtual Router Redundancy Protocol (VRRP)
A
VRRP load balancing
• Embedded Automation Architecture (EAA)
Monitors the internal event and status of system hardware and software,
collects field information and attempts to automatically repair the issues; based on the user configuration, onsite informati
will be sent to technical support
• Bidirectional Forwarding Detection (BFD)
Detects quickly the failures of the bidirectional forwarding paths between two devices for upper-
•Re-use of existing SIC and MIM modules
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Configuration
Information
10
Build To Order:
BTO
Router Chassis
Rule#
Description
SKU
3, 4, 5,
HPE FlexNetwork MSR3064 Router
JG404A
•
• 3U - Height
3, 4, 5, 8
HPE FlexNetwork MSR3044 Router
JG405A
• 1 Fixed 10M/100M/1000M RJ45 ports
• 2U - Height
1, 2, 3, 4, 5,
8
HPE FlexNetwork MSR3044 Router LoCry
JG405A#A59
1, 2, 3, 4, 5,
8
HPE FlexNetwork MSR3024 AC Router
JG406A
• 2 Fixed 10M/100M/1000M RJ45 ports
• 1U - Height
HPE FlexNetwork MSR3024 AC Router PDU Cable NA/JP/TW
JG406A#B2B
• C15 PDU Jumper Cord (NA/MEX/TW/JP)
HPE FlexNetwork MSR3024 AC Router PDU Cable ROW
JG406A#B2C
• C15 PDU Jumper Cord (ROW)
HPE FlexNetwork MSR3024 AC Router 220V N.A. - English localized
JG406A#B2E
• NEMA L6-20P Cord (NA/MEX/JP/TW)
is a standalone unit with no integration. BTO products ship standalone are not part of a CTO or Rack-Shippable solution.
• 1 - HMIM module slot (1 - Full Height Slot) / 0 - DHMIM module slot (Double Width Full
Height Slot)
• 1 - VPM slot
• 2 USB 2.0 Port for 3G modem and USB disk
• 1 CON/AUX port and 1 USB console port
• 2GB DDR3 SDRAM Included (default=2GB \ max=2GB DDR SDRAM)
• AC Power Supply included
Page
QuickSpecs
HPE FlexNetwork MSR3000 Router Series
Configuration
Information
12
8
If this product is ordered for delivery to Russia, it must be ordered with the A59 option (also allowed
for other countries desiring Low Encryption), then #A59 is the required option for BTO, and must be
added in addition to #0D1 for CTO.
9
1 - DC Power Supply included
NOTE:
"Drop down under power supply should offer the following options and results: Switch/Router/Power
Supply to PDU Power Cord - #B2B in North America, Mexico, Taiwan, and Japan or #B2C ROW.
(Watson Default B2B or B2C for Rack Level CTO)
-
Localized Option (Wat
High Volt Switch/Router/Power Supply to Wall Power Cord - #B2E Option. (Offered only in North
America, Mexico, Taiwan, and Japan)"