Cisco® 890 Series Integrated Services Routers combine Internet access, comprehensive security, and wireless services in a single, secure device that is easy to deploy and manage (Figure 1). The best-in-class Cisco 890 Series architecture has been specifically designed to deliver high performance with concurrent services, business continuity, and investment protection for enterprise small branch offices and service provider managed services applications.
Figure 1. Cisco 890 Series Integrated Services Router with Integrated 802.11n Access Point
Product Overview
Cisco 890 Series Integrated Services Routers are fixed-configuration routers that provide collaborative business solutions for secure voice and data communications to enterprise small branch offices (Figure 2). They are designed to deliver secure broadband, Metro Ethernet, wireless LAN (WLAN) connectivity, and business continuity. The routers also come with powerful management tools, such as the web-based Cisco Configuration Professional configuration management tool, which simplifies setup and deployment. Centralized management capabilities give network managers visibility and control of the network configurations at the remote site.
Cisco 890 Series Integrated Services Routers offer:
• High performance for secure broadband and Metro Ethernet access with concurrent services for enterprise small branch offices
• Business continuity and WAN diversity with redundant WAN links: Fast Ethernet, V.92, and ISDN Basic Rate Interface (BRI)
• Integrated secure 802.11a/g/n access point (optional) based on the draft 802.11n standard; dual-band radios for mobility and support for autonomous or Cisco Unified WLAN architectures
• Enhanced security including:
– Firewall with advance application and control for email, instant messaging (IM), and HTTP traffic
– Site-to-site remote-access and dynamic VPN services: IP Security (IPsec) VPNs (Triple Data Encryption Standard [3DES] or Advanced Encryption Standard [AES]), Dynamic Multipoint VPN [DMVPN], Group Encrypted Transport VPN with onboard acceleration, and Secure Sockets Layer [SSL] VPN)
– Intrusion prevention system (IPS): An inline, deep-packet-inspection feature that mitigates a wide range of network attacks
– Content filtering: A subscription-based integrated security solution that offers category-based reputation rating, keyword blocking, and protection against adware, malware, spyware, and URL blocking
• An 8-port 10/100 Fast Ethernet managed switch with VLAN support and 4-port support for Power over Ethernet (PoE) (optional) to power IP phones or external access points
• Metro Ethernet features include:
– One 1000BASE-T Gigabit Ethernet WAN port
– One 10/100BASE-T Fast Ethernet WAN port
– One 1-port Gigabit Ethernet (GE) Small Form-Factor Pluggable (SFP) socket for WAN connectivity
(Note: Only the 1000BASE-T Gigabit Ethernet WAN or the SFP is operational at a given time.)
– Intelligent hierarchical quality of service (HQoS): Supports hierarchical queuing and shaping
– Connectivity Fault Management (CFM), based on 802.1ag
– 802.3ah standard-based link operations, administration, and maintenance (OAM)
– Ethernet Local Management Interface (E-LMI) for the customer edge
– CFM Interworking and backward compatibility
– Performance management based on IP service-level agreement (SLA) for Ethernet
• Dedicated console and auxiliary ports for configuration and management
• Two USB 2.0 ports for security eToken credentials, booting, and loading configuration from USB
• Easy setup and deployment, and centralized and remote-management capabilities through web-based tools and Cisco IOS® Software
1Cisco 892F is supported only on the Cisco IOS Software Release 15.1(2)T2 and later
Figure 2. Typical Enterprise Small Branch-Office Deployment
Architecture Features and Benefits
Secure Network Connectivity
Cisco 890 Series Routers deliver high performance with integrated security and threat defense. Network security has become a fundamental building block of any network, and Cisco routers play an important role in embedding security at the customer's access edge. Cisco recognizes this requirement, so Cisco 890 Series Routers are equipped with security hardware acceleration and Cisco IOS Software (by default, a universal image with Advanced IP Services feature license). This Cisco IOS Software feature set facilitates hardware-based IPsec encryption on the motherboard and provides a robust array of security capabilities such as Cisco IOS Firewall, content filtering, IPS support, IPsec VPNs (DES, 3DES, and AES), SSL VPN, tunnel-less Group Encrypted Transport VPN, DMVPN, Easy VPN server and client support, Secure Shell (SSH) Protocol Version 2.0, and Simple Network Management Protocol (SNMP) in one solution set. Cisco IOS Content Filtering uses an innovative website caching and rating architecture to deliver the scalability and flexibility of an enterprise-class filtering solution at a breakthrough price point (Figure 3). This solution is scalable and easy to maintain, and is ideally suited for small businesses and enterprise small branch offices. Cisco 890 Series Routers come with a comprehensive security solution that protects organizations' networks from known and new Internet vulnerabilities and attacks while improving employee productivity.
Figure 3. Cisco IOS Content Filtering with a Cisco 890 Series Router
Metro Ethernet Connectivity
Cisco 890 Series Routers are ideal for service provider deployments as Metro Ethernet customer premises equipment (CPE). Cisco 891 and 892 Integrated Services Routers include two onboard WAN interfaces, one Gigabit Ethernet WAN port with an RJ-45 connector and a SFP socket (Cisco 892F only), and one Fast Ethernet WAN port to support the high-bandwidth demands of Metro Ethernet deployments. The router also provides failover protection and load balancing. The 8-port managed switch provides enough LAN ports for connecting multiple devices, and the optional PoE capability can supply power to IP phones or other devices. The Cisco 890 Series provides significant value to customers by simplifying deployment of Ethernet WAN services with end-to-end OAM, SLA monitoring and verification, and configuration management, resulting in increased operational efficiency and reduced operating expenses (OpEx).
The following Metro Ethernet features are supported for the Cisco 890 Series:
• E-LMI: Basic configuration for detection and isolation of connectivity in the Metro Ethernet network
• E-LMI: Automated configuration of customer edge based on profiles configured:
– Layer 2 connectivity management
– Ethernet LMI for the customer edge
• Metro Ethernet OAM:
– Debugging hierarchy of Ethernet networks
– Layer 2 service performance monitoring
• 802.1ag CFM:
– Uses domains to contain OAM flows and bound OAM responsibilities
• 802.3ah: Ethernet in the First Mile (EFM)
– Three types of packets: Continuity Check, Layer 2 Ping, and Layer 2 Traceroute
• IP SLA for Ethernet
Figure 4 shows a typical small branch-office Metro Ethernet deployment.
Figure 4. Typical Metro Ethernet Deployment
High Availability
Cisco 890 Series Routers enable customers to deliver high-performance, high-availability, mission-critical business applications (Figure 5). The Cisco IOS Software universal image with Advanced IP Services feature license (default) offers basic and advanced routing capabilities to deliver failover protection and load balancing. These capabilities include Virtual Router Redundancy Protocol (VRRP) (RFC 2338), Hot Standby Router Protocol (HSRP), Multigroup HSRP (MHSRP), and dial backup with external modem through a virtual auxiliary port. Cisco 890 Series Routers are integrated with ISDN BRI (892 model) or a V.92 analog modem (891 model) for a secondary WAN backup connection. If the primary Ethernet-access WAN is disconnected, the router detects this failure and fails over to the secondary backup WAN.
Figure 5. High Availability
Integrated Wireless LAN Capability
The Cisco 890 Series is ideal for enterprise small branch offices and small businesses that need to be connected to larger enterprise networks. These routers help extend corporate networks to secure remote sites while giving users access to the same applications found in a corporate office. They provide increased reliability for diversity of wireless data, voice, and video applications. When users require WLAN access, visibility and control of network security are even more critical at the remote site. The Cisco 890 Series meets this need with a single device that combines integrated 802.11a/g/n capabilities with security features such as Wi-Fi Protected Access (WPA), including authentication with IEEE 802.1X with Cisco Extensible Authentication Protocol (LEAP) and Protected EAP (PEAP), and encryption with WPA Temporal Key Integrity Protocol (TKIP). The Cisco 890 Series wireless models that include the integrated access point have full feature parity with the Cisco Aironet® 1250 Series Access Point and can be used in either autonomous or Cisco Unified WLAN modes. In Cisco Unified WLAN mode, as part of an enterprise WLAN architecture, all WLAN functions are centrally managed through Cisco Wireless LAN Controllers and the Cisco Wireless Control System (WCS).
Figure 6 shows a Cisco 890 Series Router deployed in an enterprise small branch-office WLAN application.
Figure 6. Enterprise Small Branch-Office WLAN
Manageability
Cisco 890 Series Routers support a whole suite of management tools to provide ease of use. Tools such as Cisco Configuration Professional use smart wizards and task-based tutorials, which resellers and customers can use to quickly and easily deploy, configure, and monitor a Cisco access router without requiring knowledge of the Cisco IOS Software command-line interface (CLI).
Table 2 lists the features and benefits of the Cisco 890 Series Routers.
Table 2. Features and Benefits of Cisco 890 Series Routers
Feature
Benefit
Increased performance for concurrent services
• Router performance allows customers to take advantage of broadband network speeds while running secure, concurrent data, voice, video, and wireless services.
Integrated Gigabit Ethernet, SFP, and Fast Ethernet WAN ports
• Integrated ports offer flexibility in Ethernet WAN access, and the additional capability to deploy redundant WAN connections for failover protections and load balancing.
Integrated 8-port 10/100BASE-T managed switch
• Fully managed LAN switch ports connect multiple LAN devices and reduce the need for an additional LAN switch.
Integrated WAN backup
• ISDN BRI S/T (Cisco 892 and 892F) or analog modem (Cisco 891) port provides high availability by establishing a backup WAN connection if the primary connection fails.
Real-time clock
• Built-in, real-time clock maintains an accurate date and time for applications that require an accurate time stamp, such as logging and digital certificates.
Enhanced security
• An integrated stateful and application inspection firewall provides network perimeter security.
• High-speed IPsec 3DES and AES encryption offers data privacy over the Internet.
• Intrusion prevention enforces security policy in a larger enterprise or service provider network.
• Content filtering offers category-based URL classification and blocking, thus providing increased productivity and better use of company resources.
Optional dual-radio/dual-band IEEE 802.11n access point
• The Cisco 890 Series offers a secure, integrated access point in a single device. It supports both autonomous and unified modes. It is backward-compatible with 802.11a/b/g.
• The router supports IEEE 802.11n draft 2.0 and uses multiple-input, multiple-output (MIMO) technology that provides increased throughput, reliability, and predictability.
Separate console, auxiliary, and USB ports
• One auxiliary and one console port enable remote configuration and management.
• The router has two USB 2.0 flash memory or security eTokens. Integrated USB ports can be configured to work with an optional USB token for off-platform storage of VPN credentials or for deployment of configuration stored on USB flash-memory devices.
Unified wireless management
• Configuration and management of access points is automated and simplified without manual intervention.
• A unified hybrid remote-edge access point (HREAP) provides the following:
• WLAN services to remote and branch offices without deploying a wireless LAN controller at each location.
• Central configuration and control of unified WLAN services for remote offices through a WAN link.
• Flexibility in setting up wireless access at remote locations by specifying how traffic is to be bridged or tunneled.
Cisco Configuration Professional
• Cisco Configuration Professional uses smart wizards and task-based tutorials, which resellers and customers can use to quickly and easily deploy, configure, and monitor a Cisco access router without requiring knowledge of the Cisco IOS Software CLI.
Summary
Cisco 890 Series Integrated Services Routers combine increased network performance with advanced security and wireless technology to allow enterprise small branch-office customers to get the most from their broadband connections. Service providers and value-added resellers can take advantage of the Cisco 890 Series to provide a true business-class broadband service. The Cisco 890 Series delivers on the requirements of enterprise small branch offices and managed services providers.
Product Specifications
Tables 3 through 5 list software and hardware features of the Cisco 890 Series.
Table 3. Cisco IOS Software Features on Cisco 890 Series: Advanced IP Features Set (Default)
Feature
Description
IP and IP services features
• Routing Information Protocol Versions 1 and 2 (RIPv1 and RIPv2)
• Generic routing encapsulation (GRE) and Multipoint GRE (MGRE)
• Cisco Express Forwarding
• Standard 802.1d Spanning Tree Protocol
• Layer 2 Tunneling Protocol (L2TP)
• Layer 2 Tunneling Protocol Version 3 (L2TPv3)
• Network Address Translation (NAT)
• Dynamic Host Configuration Protocol (DHCP) server, relay, and client
• Optional internal adapter for inline PoE on 4 switch ports for IP phones or external wireless access points; 802.3af compliant and Cisco PoE compliant
For more information about the Cisco 890 Series, visit http://www.cisco.com/go/800. Table 6 lists the ordering information for Cisco 890 Series Integrated Services Routers and other available options.
Table 6. Ordering Information
Product Part Number
Product Description
Integrated Services Routers
CISCO891-K9
Cisco 891 Gigabit Ethernet security router
CISCO891W-AGN-A-K9
Cisco 891W Gigabit Ethernet security router with 802.11n, FCC compliant
CISCO891W-AGN-N-K9
Cisco 891W Gigabit Ethernet security router with 802.11n, Australia compliant
CISCO892-K9
Cisco 892 Gigabit Ethernet security router
CISCO892W-AGN-E-K9
Cisco 892W Gigabit Ethernet security router with 802.11n, ETSI compliant
CISCO892F-K9*
Cisco 892 Gigabit Ethernet security router with SFP
CISCO892FW-A-K9*
Cisco 892 Gigabit security router with SFP and 802.11n, FCC compliant
CISCO892FW-E-K9*
Cisco 892 Gigabit security router with SFP and 802.11n, ETSI compliant
* Cisco 892F is supported only on Cisco IOS Software Release 15.1(2)T2 and later
Memory Options
MEM8XX-512U768D
512 MB DRAM upgrade to 768 MB for Cisco 891 and 892 models
MEM8XX-512U1GBD
512 MB DRAM upgrade to 1 GB for Cisco 892F models
Router Software
C890-universalk9-mz
Universal image for Cisco 890 Series routers
Access Point Software
ap801-k9w7-tar
Autonomous software image for ap801
ap801-rcvk9w8-tar
Lightweight Access Point Protocol (LWAPP) recovery image for ap801
Power over Ethernet Options
800-IL-PM-4
4-port 802.3af capable internal power module for Cisco 890 Series routers
Security Services
SL-CNFIL-890-1Y
One-year subscription to Content Filtering for Cisco 890 Series routers
SL-CNFIL-8xx-TRI
30-day free trial license for Cisco 890 Series routers
SSL
FL-WEBVPN-25-K9
Feature license SSL VPN for up to 25 users (incremental), for 12.4T based Cisco IOS Software releases only
FL-SSLVPN25-K9
Feature license SSL VPN for up to 25 users (incremental), for 15.x based Cisco IOS Software releases only
Supported SFP Types on the Cisco 892F Series
GLC-LH-SM
1000BASE-LX/LH SFP transceiver module for MMF and SMF, 1300-nm wavelength, dual LC/PC connector
For more information regarding Cisco 890 Series Routers and options, contact your local Cisco representative or visit: http://www.cisco.com/go/800.
To upgrade the Cisco IOS Software for the Cisco 890 Series, visit the Cisco Software Center.
Table 7 gives the Cisco IOS Software images for the Cisco 891 and 892 Integrated Services Routers.
Table 7. Cisco IOS Software Images for Cisco 890 Series
Series
Models
Image
Default Feature License
First Cisco IOS Software Release
Router Software
Cisco 890 Series
Cisco 891 and 892 models
C890-universalk9-mz
SL-890-AIS (Advanced IP Services Image feature)
12.4(22)YB and will be in 15.0[1]m.
S890VK9-12422YB
Cisco 892F Series
Cisco 892F
C890-universalk9-mz
SL-890-AIS (Advanced IP Services Image feature)
15.1(2)T2
S890VK9- 15102T2
Access Point Software
ap801
Cisco 891 and 892 models
ap801-k9w7-tar
ap801-rcvk9w8-tar (LWAPP recovery software)
-
12.4(10b)JA3
Cisco Services
Cisco Services for the Branch Office
Services from Cisco and our certified partners can help you reduce the cost and complexity of branch-office deployments. We have the depth and breadth of experience across technologies to architect a blueprint for a branch-office solution to meet your company's needs. Planning and design services align technology with business goals and can increase the accuracy, speed, and efficiency of deployment. Technical services help maintain operational health, strengthen software application functions, solve performance problems, and lower expenses. Optimization services are designed to continually improve performance and help your team succeed with new technologies. For more information, visit http://www.cisco.com/go/services.
Cisco SMARTnet® technical support for the Cisco 890 Series is available on a one-time or annual contract basis. Support options range from help-desk assistance to proactive, onsite consultation. All support contracts include:
• Major Cisco IOS Software updates in protocol, security, bandwidth, and feature improvements
• Full access rights to Cisco.com technical libraries for technical assistance, electronic commerce, and product information
• 24-hour access to the industry's largest dedicated technical support staff
For More Information
For more information about the Cisco 890 Series Integrated Services Router, visit http://www.cisco.com/go/800 or contact your local account representative.
For more information about Cisco products, contact: