Comparision of Cisco ISR 4000 routers
Model Comparison of Cisco Router ISR 4000 Series
Basic models :
Technical Specifications | ISR4461/K9 | ISR4451-X/K9 | ISR4431/K9 | ISR4351/K9 | ISR4331/K9 | ISR4321/K9 | ISR4221/K9 |
Aggregate Throughput | 1.5Gbps | 1 Gbps to
2 Gbps |
500 Mbps to
1 Gbps |
200 Mbps to
400 Mbps |
100 Mbps to
300 Mbps |
50 Mbps to
100 Mbps |
35 Mbps to 75 Mbps |
Total onboard WAN or LAN 10/100/1000 ports | 4 | 4 | 4 | 3 | 3 | 2 | 2 |
RJ-45-based ports | 4 | 4 | 4 | 3 | 2 | 2 | 2 |
SFP-based ports | 4 | 4 | 4 | 3 | 2 | 1 | 1 |
Enhanced service-module slots | 3 | 2 | 0 | 2 | 1 | 0 | 0 |
Doublewide service-module slots | 2 | 1 (assumes no singlewide SM-X modules installed) | 0 | 1 (assumes no singlewide SM-X modules installed) | 0 | 0 | 0 |
NIM slots | 3 | 3 | 3 | 3 | 2 | 2 | 2 |
OIR (all I/O modules) | Yes | Yes | Yes | Yes | Yes | Yes | No |
Onboard ISC slot | 1 | 1 | 1 | 1 | 1 | 1 | No |
Detail Comparison:
Models | 4221 | 4321 | 4331 | 4351 | 4431 | 4451 | 4461 |
Features | |||||||
Form factor | 1 RU Desktop | 1 RU Desktop | 1 RU | 2 RU | 1 RU | 2 RU | 3 RU |
Integrated WAN Ports | GE / SFP | GE / SFP | GE / SFP | 2 PoE GE / SFP | 2 PoE GE / SFP | 2 PoE GE / SFP | 2 x PoE GE/SFP; 2 x GE/SFP; 2 x 10 GE SFP+ |
GE | GE | GE / SFP | GE / SFP | 2 GE / SFP | 2 GE / SFP | ||
Performance | 35 Mbps | 50 Mbps | 100 Mbps | 200 Mbps | 500 Mbps | 1 Gbps | 1.5 Gbps |
Performance with Performance license | 75 Mbps | 100 Mbps | 300 Mbps | 400 Mbps | 1 Gbps | 2 Gbps | 3 Gbps |
Performance with Boost license | 1.2 Gbps | 2+ Gbps | 2+ Gbps | 2+ Gbps | 4+ Gbps | 4+ Gbps | 10+ Gbps |
Encrypted throughput (AES 256) | 75 Mbps | 100 Mbps | 500 Mbps | 500 Mbps | 900 Mbps | 1.6 Gbps | 7 Gbps |
Management port | 1 GE RJ-45 (Integrated out of band) | 1 GE RJ-45 (Integrated out of band) | 1 GE RJ-45 (Integrated out of band) | 1 GE RJ-45 (Integrated out of band) | 1 GE RJ-45 (Integrated out of band) | 1 GE RJ-45 (Integrated out of band) | 1 GE RJ-45 (Integrated out of band) |
Network Interface Modules (NIM) | 2 | 2 | 2 | 3 | 3 | 3 | |
Enhanced Services Modules (SM-X) | – | – | 1 x single wide | 2 x single wide or 1 x double wide | – | 2 x single wide or 1 x double wide | 3 x single wide; 2 x double wide; or 2 x singlewide plus 1 x doublewide |
Integrated Services Card (ISC) slots | – | 1 x PVDM 4 | 1 x PVDM 4 | 1 x PVDM 4 | 1 x PVDM 4 | 1 x PVDM 4 | – |
USB ports (type A) | 1 x USB 2.0 | 1 x USB 2.0 | 1 x USB 2.0 | 2 x USB 2.0 | 2 x USB 2.0 | 2 x USB 2.0 | 2 x USB 3.0 |
Default/maximum Flash | 8 GB | 4 GB/8 GB | 4 GB/16 GB | 4 GB/16 GB | 8 GB/32 GB | 8 GB/32 GB | 8 GB/32 GB |
Default/maximum DRAM | 4 GB fixed DRAM | 4 GB/8 GB | 4 GB/16 GB | 4 GB/16 GB | 4 GB/16 GB | 4 GB/16 GB | 8 GB/32 GB |
Power supply type | External: AC | External: AC, PoE | External: AC, PoE | External: AC, PoE, or DC | Internal AC, AC-PoE, or DC | Internal AC, AC-PoE, or DC | Internal AC, AC-PoE, or DC |
Redundant power supply | – | – | – | – | Yes, internal RPS | Yes, internal RPS | Yes, internal RPS |
Module online insertion and removal (OIR) | – | Yes | Yes | Yes | Yes | Yes | Yes |
Module online insertion and removel (OIR) | No | Yes | Yes | Yes | Yes | Yes | |
Server virtualization platform (UCS E-Series) and Network Compute Engine (NCE) | N/A | 4-core NCE | 2-core single-wide, 2-core NCE | 2-core single-wide, 2-core NCE | 4-core NCE | 2-core single-wide, 2-core NCE | 2-core single wide, 2-core NCE |
4-core single-wide, 4-core NCE | 4-core single-wide, 4-core NCE | 4-core single-wide, 4-core NCE | 4-core single wide, 4-core NCE | ||||
4-core double-wide | 4-core double-wide | 4-core double wide | |||||
6-core double-wide | 6-core double-wide | 6-core double wide | |||||
8-core double-wide | 8-core double-wide | 8-core double wide | |||||
12-core double-wide | 12-core double-wide | 12-core double wide | |||||
Full IOS XE SD-WAN support | Yes | Yes | Yes | Yes | – | – | – |
Advanced Security | |||||||
Cyberthreat protection through Trustworthy Systems framework | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Zone-based firewall and NAT services | VRF-Aware Firewall and Network Address Translation (NAT) | VRF-Aware Firewall and Network Address Translation (NAT) | VRF-Aware Firewall and Network Address Translation (NAT) | VRF-Aware Firewall and Network Address Translation (NAT) | VRF-Aware Firewall and Network Address Translation (NAT) | VRF-Aware Firewall and Network Address Translation (NAT) | VRF-Aware Firewall and Network Address Translation (NAT) |
Hardware VPN acceleration (DES, 3DES, AES) | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IPsec VPN services | FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
FlexVPN, Easy VPN remote server, Enhanced Easy VPN, Dynamic Multipoint VPN (DMVPN) Group Encrypted Transport VPN (GET VPN), V3PN, MPLS VPN |
SSL VPN | – | – | – | – | – | – | – |
Intrusion prevention | Yes (Snort for signature-based and Firepower as NGIPS) | Yes (Snort for signature-based and Firepower as NGIPS) | Yes (Snort for signature-based and Firepower as NGIPS) | Yes (Snort for signature-based and Firepower as NGIPS) | Yes (Snort for signature-based and Firepower as NGIPS) | Yes (Snort for signature-based and Firepower as NGIPS) | Yes (Snort for signature-based and Firepower as NGIPS) |
Anomaly detection and machine learning | Cisco Self Learning Networks (SLN) | Cisco Self Learning Networks (SLN) | Cisco Self Learning Networks (SLN) | Cisco Self Learning Networks (SLN) | Cisco Self Learning Networks (SLN) | ||
Network foundation protection | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 | ACL, FPM, control plan protection, control plane policing (CoPP), QoS, role-based CLI access, source-based RTBH, uRPF, SSHv2 |
Cisco Umbrella Branch Support | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Cisco Cloud Web Security | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Identity-based networking | – | – | – | – | – | – | – |
Cisco TrustSec | Security Group Tag Exchange Protocol (SXP), SGT over GETVPN | Security Group Tag Exchange Protocol (SXP), SGT over GETVPN | Security Group Tag Exchange Protocol (SXP), SGT over GETVPN | Security Group Tag Exchange Protocol (SXP), SGT over GETVPN | Security Group Tag Exchange Protocol (SXP), SGT over GETVPN | Security Group Tag Exchange Protocol (SXP), SGT over GETVPN | |
SGT over Ipsec | SGT over Ipsec | SGT over Ipsec | SGT over Ipsec | SGT over IPSEC | SGT over IPSEC | ||
SGT over DMVPN | SGT over DMVPN | SGT over DMVPN | SGT over DMVPN | SGT over DMVPN | SGT over DMVPN | ||
SGT-based ZBFW | SGT-based ZBFW | SGT-based ZBFW | SGT-based ZBFW | SGT-based ZBFW | SGT-based ZBFW | ||
Port/Layer 3 interface/IP/subnet-to-SGT mapping | Port/Layer 3 interface/IP/subnet-to-SGT mapping | Port/Layer 3 interface/IP/subnet-to-SGT mapping | Port/Layer 3 interface/IP/subnet-to-SGT mapping | Port/Layer 3 interface/IP/subnet-to-SGT mapping | Port/Layer 3 interface/IP/subnet-to-SGT mapping | ||
SGT export in Flexible NetFlow | SGT export in Flexible NetFlow | SGT export in Flexible NetFlow | SGT export in Flexible NetFlow | SGT export in Flexible NetFlow | SGT export in Flexible NetFlow | ||
Unified Communications | |||||||
Local conferencing | – | Yes | Yes | Yes | Yes | Yes | With PVDM4 on NIM module installed |
Digital signal processor support | – | PVDM4 | PVDM4 | PVDM4 | PVDM4 | PVDM4 | With PVDM4 on NIM module installed |
Cisco Unified Survivable Remote Site Telephony support | – | Up to 50 | Up to 100 | Up to 750 | Up to 1200 | Up to 1500 | Up to 1500 |
Cisco Unified Communications Manager Express support | – | Up to 50 | Up to 100 | Up to 250 | Up to 350 | Up to 450 | Up to 450 |
Cisco Unity Express (NM, SM, or ISM) | – | Use Cisco Unity Connection on UCSE | Use Cisco Unity Connection on UCSE | Use Cisco Unity Connection on UCSE | Use Cisco Unity Connection on UCSE | Use Cisco Unity Connection on UCSE | Use Cisco Unity Connection on UCSE |
Cisco Unified Border Element (CUBE) SIP/H.323 sessions | – | 100 | 400 | 1000 | 3000 | 6000 | – |
Nano Cisco Unified Border Element (Nano CUBE) sessions | – | – | – | – | – | – | – |
Digital voice and video | – | Up to 8 T1/E1 ports | Up to 12 T1/ E1 ports | Up to 24 T1/ E1 ports | Up to 24 T1/ E1 ports | Up to 40 T1/ E1 ports | Up to 48 T1/ E1 ports |
Analog/BRI voice | – | Up to 8 ports (FXS, FXO, E/M, BRI) | Up to 12 ports (FXS, FXO, E/M, BRI) using NIM; or 8 ports using NIM and up to 24 FXS and 4 FXO using SM-X slot | Up to 20 ports (FXS, FXO, E/M, BRI); or 12 using NIM and up to 48 FXS and 8 FXO in SM-X slot; or 12 using NIM and up to 72 FXS in SM-X slot | Up to 12 ports (FXS, FXO, E/M, BRI) | Up to 20 ports (FXS, FXO, E/M, BRI); or 12 using NIM and up to 48 FXS and 8 FXO in SM-X slot; or 12 using NIM and up to 72 FXS in SM-X slot | Up to 24 ports (FXS, FXO, E/M, BRI); or 12 using NIM and up to 24 FXS and 36 FXO in SM-X slot; or 12 using NIM and up to 144 FXS in SM-X slot |
Routing and Multicast | |||||||
IPv4 routing protocols | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR | RIP v1/v2, EIGRP, OSPF, BGP, PBR, PfR |
Multicast routing protocols | PIM-SM, mroute (static route), and MLD | PIM-SM, mroute (static route), and MLD | PIM-SM, mroute (static route), and MLD | PIM-SM, mroute (static route), and MLD | PIM-SM, mroute (static route), and MLD | PIM-SM, mroute (static route), and MLD | PIM-SM, mroute (static route), and MLD |
IPv6 routing protocols | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR | EIGRP, RIP, OSPFv3, IS-IS, BGP, PBR |
Wireless LAN | |||||||
Integrated 802.11 b/g/n access point | – | – | – | – | – | – | – |
Integrated 802.11 a/b/g/n access point | – | – | – | – | – | – | – |
Unified and autonomous mode | – | – | – | – | – | – | – |
RP-TNC connectors for field-replaceable | – | – | – | – | – | – | – |
Optional high-gain antennas | – | – | – | – | – | – | – |
Diversity (dual antennas) | – | – | – | – | – | – | – |
Wireless LAN controller module | – | Available on UCS E-Series | Available on UCS E-Series | Available on UCS E-Series | Available on UCS E-Series | Available on UCS E-Series | Available on UCS E-Series |
Wireless WAN | |||||||
3G/4G LTE cellular | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Cat 6 LTE Advanced | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
GPS support | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Indoor antenna | Yes (Various antenna using 2 x TNC connectors supporting MIMO) | Yes (various antennas using 2 x TNC connectors supporting MIMO) | Yes (various antennas using 2 x TNC connectors supporting MIMO) | Yes (various antennas using 2 x TNC connectors supporting MIMO) | Yes (various antennas using 2 x TNC connectors supporting MIMO) | Yes (various antennas using 2 x TNC connectors supporting MIMO) | Yes (various antennas using 2 x TNC connectors supporting MIMO) |
Outdoor antennas | – | – | – | – | – | – | – |
Integrated Switching | |||||||
Maximum switched Ethernet ports | 2 x 8 | 16 | 40 | 72 | 24 | 72 | 120 |
Maximum switched Ethernet LAN ports with PoE | – | 16 | 40 | 72 | 24 | 72 | 120 |
Maximum PoE power without PoE boost | – | 120W | 250W | 500W | 250W | 500W | 360W |
Maximum PoE power with PoE boost | – | 260W | 500W | 950W | 530W | 990W | 720W |
EtherSwitch Service Module type (width) | – | – | 1 x single wide | 2 x single wide or 1 x double wide | – | 2 x single wide or 1 x double wide | 3 x single wide; 2 x double wide; or 2 x single wide plus 1 x double wide |
Application Services | |||||||
Intelligent Path Control | PfR | PfR | PfR | PfR | PfR | PfR | PfR |
SD-Access | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Network Contention Control | QoS, HQoS | QoS, HQoS | QoS, HQoS | QoS, HQoS | QoS, HQoS | QoS, HQoS | QoS, HQoS |
Application Visibility | NBAR v2 | NBAR v2 | NBAR v2 | NBAR v2 | NBAR v2 | NBAR v2 | NBAR v2 |
WAN Optimization | – | ISR-WAAS | ISR-WAAS; vWAAS on UCS E-Series | ISR-WAAS; vWAAS on UCS E-Series | ISR-WAAS | ISR-WAAS; vWAAS on UCS E-Series | ISR-WAAS; vWAAS on UCS E-Series |
Akamai Connect | – | Yes | Yes | Yes | Yes | Yes | Yes |
Cisco Application Centric Infrastructure | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module |
Cisco Application Centric Infrastructure | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module | Application Policy Infrastructure Controller (APIC) with Enterprise Module |
Leave a Reply
Want to join the discussion?Feel free to contribute!