|
Company Name:Kino Technology Limited
Website:www.kino86.com
Address :Room 312, Honghua Building, No. 1 Guangyayuan Road, Bantian Street, Longgang District, Shenzhen city, Guangdong Province, China
Contact Person:kiki
Tel :+8613040881925
E-mail:kiki@szkiki.com
Wechat:+8613040881925
Whatspp: +8613040881925
Teams:kiki@szkiki.com
|
|
|
| Product >> Cisco >> ALL |
| |
|
Product_Id: |
71717121816 |
ProductName: |
3945E |
Specification: |
|
Product Notes: |
|
Product Category: |
Cisco |
| |
|
| Product Description |
Cisco 3945E Integrated Services Router (ISR G2 Flagship Enhanced Model) Full Product Description
1. Short Overview
TheCisco 3945Eis the top-tier enhanced 3U rack-mount second-generation Integrated Services Router (ISR G2) within the Cisco 3900 Series, released March 16, 2010 as the upgraded flagship variant of the standard Cisco 3945Cisco. It is built for enterprise headquarters, large regional central branches, high-density PBX voice gateways, and carrier-grade high-capacity business CPE running heavy mixed voice, data, video, zone firewall, IOS IPS, large-scale DMVPN IPsec, SRE virtualized workloads, and WAAS WAN optimization.
The core upgrade over the base 3945 is thefield-replaceable SPE250 Services Performance Engine, a higher-performance multi-core processor with stronger embedded crypto offload and higher wire-speed throughput, plus factory 1GB symmetric dual DIMM DRAM as standard. It maintains full backward compatibility with EHWIC/WIC/VIC/VWIC/SM/PVDM3/ISM modules from all ISR Gen1 and Gen2 platforms.
This router reached End-of-Sale (EoS) December 9, 2017, and End-of-Life (EoL) December 31, 2022, with all official Cisco TAC hardware and software maintenance discontinuedCisco. Modern upgrade alternatives are the Cisco ISR 4000 Series and Catalyst 8000 edge routers.
Naming & Variant Breakdown
-
CISCO3945E/K9: Standard AC flagship base router with universal IOS image and native embedded K9 AES/3DES crypto hardware
-
CISCO3945E-AC-IP/K9: AC PoE power supply variant with high-wattage inline power for 802.3af IP phones via switch EHWICs
-
CISCO3945E-DC/K9: 24–60V negative DC autoranging telecom power model for central office rack deployments
-
-SEC/K9: Pre-bundled Security license bundle enabling Zone-Based Firewall, IOS IPS, full IPsec/SSL/DMVPN encryption
-
-VOICE/K9: Unified Communications bundle pre-licensed for CME/SRST embedded voice call processing
-
-VSEC/K9: All-in-one integrated Voice + Security converged enterprise bundle
-
-AX/K9: Advanced services bundle supporting SRE virtualization, WAAS wide-area deduplication optimization
-
-AXV/K9: AX + full UC voice bundle with PVDM DSP capacity pre-provisioned
-
-HSEC+/K9: High-security enhanced bundle optimized for hundreds of concurrent IPsec tunnels, FIPS 140-2 Level 2 compliant with optional security shield kit
Core Differentiators vs Cisco 3945 (Standard Non-E Model)
-
SPE250 modular performance engine(SPE150 on base 3945): Faster multi-core CPU, larger crypto offload pipeline, aggregate throughput boosted to 180 Mbps vs 150 Mbps on 3945Cisco
-
Factory default 1GB symmetric dual 512MB ECC DIMMs (same max 2GB ceiling as 3945, no memory upgrade required out of box)Cisco
-
Optimized system bus for aggregated multi-port T1/E1/xDSL uplinks and massive concurrent voice/security workloads
-
Identical physical chassis, expansion slot layout, port layout, dual redundant internal hot-swappable power supplies, 3U rack form factor
-
Same slot count: 4 SM/SM-D service module slots, 4 universal EHWIC slots, 4 onboard PVDM3 DSP slots, 1 internal ISM auxiliary service slot
-
Four onboard Gigabit RJ45 ports plus two independent non-shared SFP fiber uplinks, dual USB 2.0, triple out-of-band management consoles, single removable CompactFlash storage
-
Identical IOS 15.x universal licensing architecture, DC/PoE power supply options, external RPS redundant power connector
2. Hardware Interface & Physical Specifications
Modular Expansion Architecture
-
4 × SM / SM-D Double-Wide Service Module slots (Flagship exclusive high-density trunk resource)
Four rear high-density service slots configurable as four single-wide SM or paired into two double-wide SM-D high-bandwidth modules for voice trunking, security, virtualization, and storage:
-
SM-2T1/SM-4E1 multi-port channelized T1/E1 PRI voice trunk modules for large PBX interconnection
-
SM-CIDS-K9 dedicated inline intrusion detection modules
-
SRE900 virtualization modules for Windows/Linux application hosting, WAAS bandwidth deduplication optimization
-
SM-CUE storage modules for Unity Express voice mail, auto-attendant and persistent log retention
-
4 × Rear Universal EHWIC/WIC/VIC/VWIC slots
Each slot supports single-wide EHWIC, double-wide EHWIC-D, legacy HWIC, analog VIC, multi-flex VWIC voice cards; two slots accept double-wide high-bandwidth EHWIC-D modules:
-
EHWIC: ADSL2+, VDSL2, G.SHDSL, synchronous serial, 4-port GE switch, cellular 3G/4G wireless WAN cards
-
WIC: ISDN BRI, synchronous/asynchronous serial, analog modem WICs for Dial-on-Demand Routing (DDR) backup failover
-
VIC/VWIC: FXS/FXO/E&M analog station/trunk cards, fractional T1/E1 multi-flex voice trunks
-
4 × Motherboard PVDM3 DSP slots
Dedicated onboard Packet Voice Digital Signal Processor slots to handle VoIP codecs, G.168 echo cancellation, wideband G.722 high-fidelity audio, T.38 fax relay, and multi-party audio conferencing without consuming external expansion slots; quadruple DSP capacity supports up to 384 concurrent VoIP calls for large-scale IP phone deployments.
-
1 × Internal ISM (Internal Service Module) auxiliary slot
Supplementary internal slot for auxiliary storage, lightweight crypto acceleration, or secondary application offloading to complement SM service modules.
Fixed Built-in Rear Panel Ports
-
4 × Auto-MDI-X 10/100/1000BASE-T Gigabit Ethernet (GE0/0, GE0/1, GE0/2, GE0/3) + 2 independent non-shared SFP mini-GBIC fiber slots
Two native fiber SFP uplinks with no port-sharing limitation; all Gigabit ports fully support IEEE 802.1Q VLAN trunking, inter-VLAN routing, LACP link aggregation to isolate corporate, finance, engineering, guest, and sensitive POS payment subnetsCisco.
-
RJ45 Serial Console port (115.2 kbps max baud) – primary local out-of-band CLI management
-
Mini-USB Type-B Console port – lightweight secondary local management without RJ45 cables
-
RJ45 AUX port – remote emergency IT access via external PSTN analog modem
-
2 × USB 2.0 Type-A ports– high-speed offline configuration/log backup storage, two-factor crypto authentication tokens
-
Removable external CompactFlash (CF) slot – primary persistent storage for IOS universal images, full running configurations, persistent event logging
-
Dual internal hot-swappable power supply bays (AC / DC / PoE variants available)
-
Dedicated external RPS redundant power supply connector for extended mission-critical fault tolerance
-
Chassis ground lug + Kensington anti-theft lock slot for physical rack security
Memory & Performance Benchmarks
-
Processor: Multi-task multi-core PowerQUICC CPU integrated on field-replaceable SPE250 Services Performance Engine, with dedicated embedded hardware crypto FPGA acceleration
-
Default DRAM: 1024MB (1GB) symmetric dual 512MB ECC DIMMs; maximum expandable DRAM: 2048MB (2GB) via matching dual DIMM slots
-
Default Flash memory: 256MB CompactFlash; maximum supported Flash: 8GB CF card
-
Multi-service mixed voice/data/security throughput: Up to 180 Mbps aggregate wire-speed performance under full converged service load
-
Hardware crypto acceleration: Native AES-256, 3DES, DES IPsec, SSL/TLS, GRE VPN offloading; scalable via SM high-security modules for hundreds of concurrent site-to-site tunnels
-
Maximum concurrent site-to-site IPsec tunnels: Up to 450+, expandable with full 2GB DRAM and SRE virtualization security modules
-
Supported IOS releases: Cisco IOS 15.0(1)M through 15.7(3)M universal multi-service maintenance images; feature functions unlocked via permanent chassis-bound software licenses (SL-39-DATA-K9, SL-39-SEC-K9, SL-39-UC-K9)
-
Voice capacity: PVDM2/PVDM3 DSP modules support up to 384 concurrent VoIP calls; Cisco CME embedded call processing for up to 300 IP phones, SRST survivable remote branch telephony, Unity Express voice mail hosted via SM-CUE storage modules
Physical & Power Parameters
-
Form factor: 3U standard 19-inch rack-mount metal chassis with integrated rack ears
-
Standard AC power supply: 100–240V 47–63Hz universal autoranging internal power supply, dual hot-swappable internal PSUs for native redundancy
-
DC variant (C3945E-DC): 24–60V negative DC telecom input for central office cabinet deployments
-
PoE variant (C3945E-AC-IP): Integrated inline power distribution delivering up to 360W PoE budget, expandable to 750W with external PoE boost accessories
-
Typical chassis power consumption: ~920W under fully loaded four SM, four EHWIC, four PVDM, ISM module configuration
-
Front panel status LEDs: System power, dual PSU fault alarm, CompactFlash activity, dual USB port status, PVDM/ISM health indicators, four EHWIC slot link/activity, four SM slot status, four Gigabit Ethernet + dual SFP link/activity
-
Operating environment
-
Operating temperature: 0°C to +40°C below 1800m altitude; 0°C to +25°C above 1800m up to 3000m
-
Relative humidity: 5–85% RH non-condensing
-
Dimensions (H × W × D): 133.35 × 438.15 × 476.25 mm (5.25 × 17.25 × 18.75 inches)
-
Fully loaded weight: ~13.8 kg (30.4 lbs) with complete expansion modules
-
No native chassis PoE output except for dedicated -AC-IP power supply variant.
3. Cisco IOS Universal Image Multiservice Feature Suite
Core Routing & Multi-WAN Connectivity
-
Full dual-stack IPv4 / IPv6 routing suite: Static routes, RIP v1/v2, OSPF, EIGRP, BGP, IS-IS, PIM multicast suite, BFD bidirectional forwarding detection
-
WAN encapsulation support: PPP, HDLC, Frame Relay, ATM, ISDN, PPPoE/PPPoA for DSL, Dial-on-Demand Routing (DDR) for automatic backup failover, MPLS L2/L3 VPN, GETVPN
-
HSRP/VRRP for router high availability redundancy; NHRP DMVPN hub-spoke multi-site overlay VPN architecture
-
NAT services: Static NAT, dynamic NAT, PAT overloading, multi-address NAT pools, NAT64 IPv4-IPv6 transition support
-
IEEE 802.1Q VLAN trunking, inter-VLAN routing, storm control, LACP link aggregation across four onboard Gigabit Ethernet ports and dual independent SFP fiber uplinks.
Unified Communications Voice & Fax Integration (Flagship Ultra-High-Density Voice Differentiator)
-
VoIP signaling protocols: H.323, SIP, MGCP, SCCP native support for large-scale Cisco Unified IP Phone deployments
-
Analog/digital telephony via VIC/VWIC + four PVDM3 DSPs + four SM voice trunk modules: FXS station ports, FXO PSTN trunk lines, E&M PBX tie connections, multi-port T1/E1 PRI channelized trunk interworking with third-party PBX platforms (Avaya, Siemens, Nortel)
-
T.38 real-time fax over IP, fax passthrough, store-and-forward fax routing
-
DSP-accelerated voice codecs: G.711, G.719, G.729a, G.726, wideband G.722 high-fidelity audio, video conferencing codec support
-
Enterprise telephony tools: Scalable multi-site dial plans, voice hunt groups, toll bypass to eliminate long-distance PSTN charges
-
CME embedded call manager, SRST survivable remote telephony, Unity Express voice mail/auto-attendant hosted via SM-CUE storage modules.
Enterprise QoS & WAN Optimization
-
Base QoS tools: Weighted Fair Queuing (WFQ), CBWFQ, per-interface traffic shaping
-
Advanced QoS (Data/UC license): Low Latency Queuing (LLQ), Frame Relay Traffic Shaping (FRTS), WRED congestion avoidance, DSCP/802.1p traffic marking
-
Link Fragmentation and Interleaving (LFI), cRTP VoIP header compression to eliminate voice jitter on low-speed DSL/ISDN backup links
-
NBAR2 next-generation deep packet inspection for application-aware traffic prioritization of business-critical software; SRE WAAS module for end-to-end WAN bandwidth deduplication and optimization.
Integrated Self-Defending Network Security Suite
-
Zone-Based Stateful Firewall (ZBFW): Deep application-layer inspection for HTTP, FTP, SIP, H.323 and all mainstream enterprise business protocols
-
IOS IPS inline signature-based intrusion prevention with real-time threat detection and automated connection blocking
-
Embedded hardware-accelerated VPN stack:
-
AES-256/3DES/DES IPsec site-to-site branch tunnels
-
Cisco Easy VPN Remote centralized security policy provisioning for remote branch locations
-
DMVPN scalable hub-spoke multi-site overlay networks
-
SSL VPN for browser-only remote worker access without client software
-
AAA security framework: PAP/CHAP authentication, RADIUS/TACACS+ centralized access control and complete audit logging
-
Standard/extended ACLs, dynamic ACLs, anti-DDoS traffic policing, security zone segmentation to isolate sensitive POS payment and finance subnets
-
FIPS 140-2 Level 2 certified with optional physical security shield kit for government regulated deployments.
Management, Automation & Operations
-
Triple out-of-band management interfaces: RJ45 Serial Console, Mini-USB Console, and AUX modem port for emergency offline IT maintenance
-
Secure remote management: SSHv2, HTTPS, SNMP v1/v2c/v3, TR-069 automated remote provisioning
-
Graphical configuration utility: Cisco Configuration Professional (CCP) for simplified zero-touch mass branch deployment
-
AutoInstall automated remote IOS image and configuration download over WAN links for nationwide branch rollouts
-
Removable CompactFlash storage for easy IOS upgrades, configuration backup, and centralized log archiving
-
Persistent syslog event logging, NTP time synchronization for consistent audit timestamps
-
Dual USB 2.0 ports for offline config storage and two-factor authentication security tokens
-
Cisco EnergyWise power management for intelligent energy consumption control of attached network devices.
4. Typical Deployment Scenarios
-
Large regional enterprise headquarters multi-service edge gateway: Multiple aggregated T1/E1 PRI voice trunk modules via SM-D double-wide service slots, dual fiber Metro Ethernet primary/secondary WAN uplinks via independent SFP ports, VDSL2 EHWIC copper backup link, four PVDM3 DSP modules supporting over 350 concurrent VoIP calls, four Gigabit Ethernet ports to segregate finance, engineering, staff, and guest VLANs, SRE900 virtualization module for local application hosting, high-volume DMVPN IPsec tunnels to corporate headquarters, integrated ZBFW/IPS security stack for enterprise compliance.
-
National multi-chain retail flagship voice gateway: ADSL2+ EHWIC primary broadband WAN, ISDN BRI WIC dial backup, CME embedded call processing for 200–300 on-site IP phones, SM-CIDS intrusion detection module for PCI DSS payment security, SM-CUE voice mail storage module for multi-location unified messaging.
-
Global carrier managed high-capacity enterprise CPE: Universal dual-standard DSL EHWIC copper broadband access, DC power variant for central office rack deployment, dual SM storage/optimization modules for tenant log retention and bandwidth control, DMVPN overlay to carrier central service hub, integrated firewall/IPS for tenant threat isolation and network segmentation.
-
Advanced enterprise networking flagship training lab core router: Universal four SM/EHWIC/WIC/VIC modularity to teach multi-port T1/E1 PRI voice trunking, dual independent fiber SFP uplinks, quadruple DSP VoIP gateway, hardware-accelerated high-volume IPsec VPN, and full unified communications gateway labs; factory 1GB DRAM and large CF capacity fully support feature-rich IOS 15.xM images unavailable on lower-tier 2900/2911/3925/3945 base models.
5. Standard Package Contents of CISCO3945E / 3945E-DC / 3945E-AC-IP
1 × Cisco 3945E 3U rack-mount chassis (no SM/EHWIC/WIC/VIC/PVDM3/ISM modules or AC power cord included)
IEC AC power cord (DC variants exclude AC cord)
RJ45 console rollover cable
Hardware installation quick start guide
Global safety, EMC, RoHS, regional telecom regulatory compliance documentation
Separately Sold Optional Accessories
-
EHWIC/WIC/VIC/VWIC WAN and analog/digital voice interface cards
-
SM / SM-D double-wide service modules (multi-T1/E1 trunk, IDS, SRE virtualization, Unity Express storage)
-
PVDM3 DSP voice compression modules for VoIP, wideband audio and T.38 fax relay
-
ISM Internal Service Modules for auxiliary storage and lightweight application offloading
-
DRAM memory expansion DIMMs (512MB / 1GB / 2GB symmetric matched pairs)
-
CompactFlash memory upgrades (256MB / 1GB / 4GB / 8GB)
-
CAT5e/CAT6 Gigabit Ethernet patch cords, RJ11 DSL/ISDN telephone line cables
-
External PoE injectors for non-PoE IP phones and wireless access points
-
External redundant power supply units (RPS) for extended high-availability deployments
-
FIPS physical security shield kit for FIPS 140-2 Level 2 certification
-
Spare C3900-SPE250/K9 performance engine replacement
Software Licensing Information
The Cisco 3945E runs a single universal IOS image covering all feature tiers; three permanent chassis-bound software license sets unlock distinct functionality with no recurring subscription fees:
-
SL-39-DATA-K9: Core routing, dual-stack IPv6, MPLS, advanced QoS, NBAR2 application classification, EnergyWise power management
-
SL-39-SEC-K9: Zone-based stateful firewall, IOS inline IPS, full AES/3DES IPsec/SSL/DMVPN encryption, advanced threat mitigation, anti-DDoS policing
-
SL-39-UC-K9: CME/SRST embedded voice call processing, Unity Express voice mail, full wideband VoIP codec support for PVDM3 DSP modules
Embedded K9 crypto hardware complies with US ITAR export regulations for global shipments.
Short Commercial Catalog Summary
The Cisco 3945E is the flagship legacy 3U rack-mountable high-density converged multiservice second-generation Integrated Services Router (ISR G2) within the entire Cisco 3900 Series, engineered for large enterprise multi-subnet headquarters, national retail headquarters, and telecommunications carriers requiring the upgraded SPE250 performance engine, factory 1GB DRAM, four SM high-density service module slots, quadruple PVDM3 DSP voice capacity, and 180 Mbps aggregate multi-service throughput superior to the standard Cisco 3945 and all lower-tier 3900 models. Key hardware upgrades over the base 3945 include the faster SPE250 modular service engine, factory-installed symmetric 1GB dual DIMM DRAM, and improved wire-speed throughput for heavy aggregated voice, security, virtualized SRE, and DMVPN workloads. Built on a multi-core CPU with dedicated embedded crypto FPGA acceleration, it features four universal rear EHWIC/WIC/VIC expansion slots, four high-density SM service module slots, four internal PVDM3 DSP voice slots for massive VoIP deployments, one internal ISM auxiliary acceleration slot, four fixed 10/100/1000 Gigabit Ethernet onboard ports plus two independent non-shared SFP fiber uplinks supporting IEEE 802.1Q VLAN trunking, removable high-capacity CompactFlash storage, dual USB 2.0 management ports, and triple out-of-band console access (RJ45 + Mini-USB + AUX). Running a single universal Cisco IOS 15.x image with modular permanent software licensing for Data, Advanced Security, and Unified Communications feature sets, it consolidates rack router, multi-Gigabit multi-VLAN switch, ultra-high-density VoIP voice gateway, zone-based stateful firewall, inline IPS intrusion prevention, high-volume hardware-accelerated multi-site VPN gateway, and enterprise-class QoS into one compact 3U rack unit, eliminating multiple standalone network appliances. Its core competitive advantage over all other 3900 series routers is the SPE250 high-performance engine, four-slot SM trunk architecture, quadruple onboard DSP voice capacity, and dual independent fiber SFP uplinks, making it the ideal mission-critical headquarters gateway for large PBX deployments and carrier-grade high-traffic CPE environments. As an end-of-life unsupported legacy platform, it is only suitable for lab environments, existing legacy network refresh replacements, and non-critical high-traffic production sites, with the Cisco ISR 4000 Series recommended as its modern performance, security, and voice-capable upgrade replacement. Limitations include single CompactFlash boot bank, USB 2.0 low-speed ports, and aging single-board multi-core architecture compared to next-generation ISR 4000 edge routing platforms. The router complies with UL, IEC, EN, EMC, and RoHS global indoor commercial wiring safety and electromagnetic compatibility standards, with optional FIPS 140-2 Level 2 certification for government regulated deployments.
|
|
|
| Click:21 Entry Time:2026-07-17 【Print】 【Close】 |
|
|
|
|