top of page


Typical tasks performed by service routers

  • Data routing
  • Construction of secure network perimeter (Firewall)
  • Network attacks prevention and monitoring (IPS/IDS)
  • Service quality monitoring (SLA)
  • Filtering of network data by various criteria (including filtering by applications)
  • Organization of secure network tunnels between different offices of a company
  • Remote connection of staff members to office
  • Management and distribution of Internet channel width within an office by using QoS
  • Organization of redundant connection (by means of wires or 3G/LTE modem)
  • User termination and bandwidth limiting – BRAS (IPoE)

The family of ESR routers is a universal hardware platform capable of performing a wide range of tasks related to network security, data encryption, user termination etc. The product line includes models that can be used in networks of various sizes - from small enterprise networks to carrier networks and data centers.

Key features

  • Scalable solution for different fields of application

  • Flexible service configuration
  • Interfacing with the equipment of leading manufacturers
  • Hardware acceleration of data processing


Out of Stock
  • Packet processor - Broadcom XLP780


    • 4хCombo 10/100/1000BASE-T/ 1000BASE-X
    • 8x10GBASE-R SFP+/1000BASE-X
    • 1xConsole (RJ-45)
    • 2хUSB 2.0


    • Firewall/NAT/routing (1518B frames) - 39 Gbps,3210 kpps (4900 kpps for frames less than 1000B)
    • IPsec VPN (1456B frames) - 17 Gbps, 1463 kpps

    • IPS/IDS 10k rules - 1370 Mbps, 257 kpps

    System features

    • VPN tunnels - 500
    • Static routes - 11k
    • Concurrent sessions - 512k
    • VLAN support - up to 4k VLANs in accordance with 802.1Q
    • BGP routes - 2.8M
    • OSPF routes - 500k
    • RIP routes - 10k
    • MAC address table - 128k
    • FIB size - 3.0M
    • VRF Lite - 32

    Plug-in interfaces

    • USB 3G/4G/LTE modem
    • E1 TopGate SFP

    Remote Access VPN clients


    Remote Access VPN server


    Site-to-site VPN

    • IPsec: «policy-based» and «route-based» modes
    • DMVPN
    • DES, 3DES, AES, Blowfish, Camellia encryption algorithms
    • IKE MD5, SHA-1, SHA-2 message authentication


    • IPoGRE, EoGRE
    • IPIP
    • L2TPv3
    • LT (inter VRF-lite routing)

    L2 functions

    • Packet switching (bridging)
    • LAG/LACP (802.3ad)
    • VLAN (802.1Q)
    • Logical interfaces
    • VLAN-based MAC

    L3 functions (IPv4/IPv6)

    • NAT, Static NAT, ALG 
    • Static routes
    • Dynamic routing protocols RIPv2, OSPFv2/v3, BGP
    • Route filtering (prefix list)
    • VRF Lite
    • Policy Based Routing (PBR)
    • BFD for BGP, OSPF, static routes

    Network security functions

    • Intrusion Detection/Prevention system (IPS/IDS)1
    • Web filtering by URL, by content (cookies, ActiveX, JavaScript)
    • Zone-based Firewall
    • Firewall filtering based on L2/L3/L4 fields and applications
    • Support for access control lists on the base of L2/L3/L4 fields
    • Protection from DoS/DDoS attacks and notification on them
    • Logging of attack and rule triggering events

    SLA control functions

    • Eltex SLA
    • Channel parameters evaluation:
      • Delay (one-way/two-way)
      • Jitter (one-way/two-way)
      • Packet loss (one-way/two-way)
      • Packet Error Rate
      • Out-of-order delivery
    • Wellink SLA (wiSLA)1

    BRAS (IPoE)1

    • User termination
    • White/black URL lists
    • Quotas for traffic volume, session time, network applications
    • HTTP/HTTPS Proxy
    • HTTP/HTTPS Redirect
    • Session accounting via Netflow protocol
    • Interaction with ААА, PCRF
    • Bandwidth management by offices, SSID and user sessions
    • User authentication by MAC or IP address

    IP addressing management (IPv4/IPv6)

    • Static IP addresses
    • DHCP client
    • DHCP Relay Option 82
    • Embedded DHCP server options: 43, 60, 61, 150
    • DNS resolver
    • IP unnumbered 

    Quality of Service (QoS)

    • Up to 8 priority queues per port
    • L2 and L3 traffic prioritization (802.1p, DSCP, IP Precedence)
    • RED, GRED congestion avoidance algorithms
    • Precedence