H3C网络数据产品

H3C S10500X-G Series Ethernet Core Switches

H3C S10500X-G Series Ethernet Core Switches

Details

268cd544-9ec8-4603-af20-f74fc73180c8


The H3C S10500X-G series switches are products specifically designed and developed by H3C Technologies Co., Ltd. (hereinafter referred to as H3C) for the core of cloud computing data centers and the core of next-generation smart parks. Based on H3C's proprietary Comware V7 operating system, the S10500X-G provides customers with a reliable and secure platform. Redundant design of key components such as the main controller, network boards, fans, and power supplies provides carrier-grade high reliability. It supports high-density GE/10GE/25GE/40GE/100GE Ethernet ports, mainstream technologies such as VXLAN, MDC, M-LAG, and IRF2, and integrates various network services such as MPLS VPN, IPv6, wireless, and traffic analysis. Furthermore, the H3C S10500X-G adopts green and energy-saving environmentally friendly design processes and complies with the "Restriction of Hazardous Substances in Electronic Equipment Standard (RoHS)".


Features


1. Advanced hardware design

It adopts the CLOS no-middleboard switching architecture, with complete separation of the forwarding plane and control plane. Currently, a single slot supports bidirectional 4.8T, providing continuous bandwidth upgrade capability.

 

With a hardware orthogonal design, the S10500X-G line card and the switching network board are completely orthogonal (90 degrees). Cross-line card service traffic is directly connected to the switching network board through the orthogonal connector, supporting cell switching. Backplane cabling is reduced to zero, greatly avoiding signal attenuation.

 

It supports 40GE and 100GE Ethernet standards, fully meeting the application and future development needs of non-blocking campus networks;

 

Supports high-density GE/10GE/25GE/40GE/100GE Ethernet ports to fully meet the needs of future application development;

 

Supports 400G high-speed Ethernet ports to meet the interconnection needs across campuses and data centers;

 

The chassis size has been redesigned, allowing for high-performance forwarding in a smaller size, thus maximizing the utilization of rack space.

 

It supports multi-fan frame design and can automatically allocate airflow when one of the fans fails.

 

Redundant design of key components such as main control slots, network board slots, fan frames, power supply frames, and main power switch can cope with emergencies and greatly improve the overall reliability of the equipment. The service board is connected to the main control board and the switching network board. When one of the switching network boards fails, the system automatically distributes traffic to other switching network boards.

 

2. Distributed multi-engine design

The S10500X-G adopts an innovative hardware design, providing the system with powerful control capabilities and millisecond-level high reliability through a fully distributed independent control engine, detection engine, and maintenance engine.

 

The distributed control engine provides a powerful control processing system for all business boards, easily handling various protocol messages and control messages, and supporting fine-grained control of protocol messages, providing the system with comprehensive resistance to protocol message attacks.

 

The distributed detection engine enables all service boards to perform rapid fault detection such as BFD and OAM in a distributed manner, and it works in conjunction with the control plane protocol to support rapid protection switching and rapid convergence. It can achieve millisecond-level fault detection to ensure uninterrupted service.

 

The distributed maintenance engine and intelligent CPU system support intelligent power management, enabling online device status checks and sequential power-on/off of individual boards (reducing power surges caused by simultaneous power-on of individual boards, improving device lifespan, and reducing electromagnetic radiation and system power consumption).

 

3. Network virtualization technology

It supports M-LAG (Multichassis Link Aggregation Group) cross-device link aggregation technology (formerly DRNI technology), which realizes cross-device link aggregation by virtualizing two physical devices into one device at the forwarding layer, keeping the control layer independent and the management interface integrated and unified, thereby improving the reliability of the single board level to the reliability of the device level.

 

Supports MDC (Multitenant Devices Context), which allows a single switch to be divided into multiple independent virtual switches. Each virtual switch created by MDC is isolated from each other and cannot communicate directly, providing high security. Virtual switches have independent hardware resources and management privileges, meeting the needs of multiple services/customers sharing a core switch and saving the cost of purchasing new network equipment and upgrading existing network equipment.

 

4. Comprehensive IPv6 solution

The S10500X-G series switches fully support the IPv6 protocol family, including IPv6 static routing, RIPng, OSPFv3, IS-ISv6, BGP4+, and other IPv6 routing protocols. They also support a wide range of IPv4 to IPv6 transition technologies, such as IPv6 manual tunneling, 6to4 tunneling, ISATAP tunneling, and GRE tunneling, ensuring a smooth transition from IPv4 to IPv6.

 

5. Excellent security mechanism

The H3C S10500X-G provides a comprehensive security protection mechanism, ensuring network security across three planes: control, management, and forwarding.

 

In the control plane, a built-in protocol packet attack identification module is used to prevent attacks by protocol packets such as TCN and ARP. OSPF/BGP/IS-IS routing protocols use MD5 verification to prevent network paralysis caused by illegal route update packets. Trusted computing is supported, which can perform trusted authentication and trusted measurement on startup software.

 

On the management plane, SNMPv3 network management protocol, SSH V2, 802.1x and AAA/Radius-based user authentication, and hierarchical user permission management ensure the security of device management; it supports security card expansion such as firewall, intrusion prevention, SSLVPN, and Internet behavior management to meet the needs of integrated network security deployment.

 

In the forwarding plane, it supports fine-grained binding of various combinations of IP, VLAN, MAC, and port; it supports uRPF unicast reverse path forwarding to prevent unauthorized traffic from accessing the network; and it employs the longest match per packet forwarding mechanism to effectively resist virus attacks. The newly upgraded version supports full-port hardware-level encryption technology MACsec (802.1ae), with key lengths up to 256 bits, protecting Layer 2 protocols from attacks at the source. It also supports Cloudsec encryption technology to ensure the security of VXLAN-based service traffic.

 

6. Green and energy-saving design

From chassis hardware to chassis exterior design, a comprehensive green and energy-saving transformation has been implemented to respond to the strategic call for "carbon peaking and carbon neutrality":

 

The S10500X-G series switch chassis is designed with water-based paint and electroplating-free process, which greatly reduces carbon emissions;

 

Adopting a strict front-to-back and rear-to-front straight ventilation channel design, the chassis has low air resistance and higher fan cooling efficiency, meeting the needs of side-by-side rack deployment;

 

The fan features zoned cooling and precise intelligent speed control with a response time down to the second level, achieving overall power saving through intelligent cooling.


Networking applications

Network Application 1:IDC Solutions

The construction of IDC (Internet Data Center) mainly faces two types of threats: one is that when the business systems deployed in the IDC suddenly experience a large volume of traffic, the server overload will cause it to crash; the other is that there are security threats on the network (illegal access, DDoS attacks, and Layer 7 attacks against servers, etc.).

The H3C S10500X-G series core switches support high-density 10 Gigabit Layer 3 line-speed interface cards, meeting the performance requirements of IDC for core equipment; through virtualization technologies such as IRF and MDC, large-scale network deployment can be achieved.

Network Application 2: Multi-service Campus Network

The H3C S10500X-G, based on a unified hardware and software platform, provides an integrated wired and wireless solution, resolving the challenges of separating wired and wireless devices, network management, and user management. Through the S10500X-G wireless controller + FIT AP control architecture, it achieves centralized management and configuration of APs, centralized user access control, and automatic AP configuration file downloads and software version updates. It supports IPv6, wireless security, RF management, and cross-layer 3 roaming, meeting the needs of value-added services such as voice and video.


Product Specifications

genus sex

S10506X-G

S10508X-G

S10512X-G

Switching capacity

1071/3213Tbps

1904/5752Tbps

2856/8628Tbps

Packet forwarding rate

345,600Mpps

460,800Mpps

921,600Mpps

(Packet forwarding capability)

Main control board slot number

2

2

2

Number of slots on the switching board

4

6

6

Service board slot number

6

8

12

Fan slot number

2

3

3

Number of power module slots

4

6

8

Hardware architecture

orthogonalCLOS architecture

Ethernet features

support802.1Q

supportLLDP

Support staticMAC, Dynamic MAC, Black Hole MAC Configuration

supportMAC address learning limit

Support port mirroring(SPAN/ERSPAN/RSPAN) and streaming mirroring functionality

Support port aggregation

support802.1d(STP), 802.1w(RSTP), 802.1s(MSTP)

Supports dynamic link aggregation, static port aggregation, and cross-board link aggregation.

supportVLANs of MAC/IP subnets/protocols/policies/ports

Routing features

Supports static routing,RIP、OSPF、IS-IS、BGP4等

Supports equal-cost routing

Supports policy-based routing

Supports routing policies

supportIPv4 and IPv6 dual protocol stack

supportIPv6 static routing, RIPng, OSPFv3, IS-ISv6, BGP4+

supportDHCPv6 Relay

supportDHCP Relay Agent

supportDHCP SNOOPING

supportDHCP OPTION 82

supportDHCP OPTION 43

supportVRRPv3

supportPingv6、Telnetv6、FTPv6、TFTPv6、DNSv6、ICMPv6

supportIPv4 to IPv6 transition technologies include: IPv6 manual tunneling, 6to4 tunneling, ISATAP tunneling, and GRE tunneling.

supportIPv6 equivalent routing

supportIPv6 policy routing

supportIPv6 routing policy

multicast

supportRouting protocols such as PIM-DM, PIM-SM, PIM-SSM, MSDP, MBGP, and Any-RP.

supportIGMP V1/V2/V3、IGMP V1/V2/V3 Snooping

supportPIM6-DM、PIM6-SM、PIM6-SSM

supportMLD V1/V2、MLD V1/V2 Snooping

Supports multicast policies and multicastQoS

Supports a mechanism for users to quickly leave.

Support multicast query

ACL/QoS

Support standards and extensionsACL

supportIngress/Egress ACL

supportVLAN ACL

Support global ACL

supportMAC Extended ACL

Supports two layersLayer 3 Port ACL

supportDiff-Serv QoS

supportQueue scheduling mechanisms such as SP, WRR, WFQ, and PQ.

supportCongestion avoidance mechanisms such as WRED and tail drop.

Supports traffic shaping

Support congestion avoidance

Support priority markingMark/Remark

supportActions such as CAR and Schedule

support802.1p, TOS, DSCP, EXP priority mapping

Support based onCombined stream classification of Layer 2 protocol header, Layer 3 protocol, Layer 4 protocol, 802.1p priority, etc.

Programmable and Automation

supportAnsible automation technology

Support throughPython/NETCONF/TCL/Resful APIs enable automated network orchestration, achieving automated DevOps operations and maintenance.

Intelligent Lossless Ethernet

supportPFC and AIECN, RoCEv2

SDN/VXLAN

supportVXLAN Layer 2 Switching

supportVXLAN Layer 3 Switching

supportVXLAN Routing Switch

supportVXLAN gateway

supportVXLAN, BGP EVPN features

supportVXLAN Distributed Control Plane of IS-IS+ENDP

Support the establishmentIPv6 VxLAN tunnels enable IPv4/IPv6 packet communication between different VxLANs.

Supports micro-segmentation

supportOpenFlow+Netconf VXLAN centralized control plane

Supports distributed systems Anycast gateway supports automated deployment of VxLAN Fabric.

MPLS/VPLS

supportL3 MPLS VPN

supportL2 VPN: VLL (Martini, Kompella)

supportMCE

supportMPLS OAM

supportVPLS,VLL

Supports layeringVPLS, and QinQ+VPLS access

supportP/PE function

supportLDP protocol

Virtualization technology

Supports cross-device link aggregation technologyM-LAG

Support horizontal virtualization IRF2

Support one-to-many technology MDC

Security Mechanism

supportEAD Security Solutions

supportPortal Certification

supportMAC authentication

supportIEEE 802.1x和IEEE 802.1x SERVER

supportAAA/Radius

supportHWTACACS supports command-line authentication.

supportSSHv1.5/SSHv2

supportACL flow filtering mechanism

supportPlaintext and MD5 Authentication of OSPF, RIPv2, and BGPv4 Messages

The command line supports a tiered protection approach to prevent unauthorized access by different users, providing different configuration permissions for different user levels.

Support is limitedTelnet login and password mechanism based on IP address

supportBinding of IP address, VLAN ID, MAC address, and port, etc.

supportuRPF

supportMACsec and Cloudsec encryption technologies

Supports primary and secondary data backup mechanism

support OPS (Open Programmable Systems)

Supports alarm and self-recovery after failure.

Support data logs

Supports configuring hardware cards for applications such as firewalls, intrusion detection, behavior management, and traffic control.*

System Management

supportFTP、TFTP、Xmodem

supportSNMP v1/v2c/v3

supportSmartMC

supportsFlow traffic statistics

supportgRPC and Telemetry Stream traffic visualization features

supportRMON

supportNTP clock, PTP clock function

Supports intelligent power management

supportConsole login

support256G storage

Supports alarms, events, and historical records.

Supports an online device status monitoring mechanism, enabling the detection of key components including the main control engine, backplane, chips, and storage.

Supports user access authentication and business on-demand services.

Supports unified user management, group-based, domain-based, and time-based authorization.

support BootROM upgrade and remote online upgrade

Supports hot patching, allowing for online patch upgrades.

Supports hierarchical user management and password protection

Supports command-line hierarchical protection, preventing unauthorized users from intruding.

support IP Source Guard supports protection against DoS attacks, ARP attacks, TCP SYN Flood attacks, UDP Flood attacks, broadcast storm attacks, and DDoS attacks.

support IPv6 RA Guard

support CPU hardware queues implement hierarchical scheduling and protection of control plane protocol messages.

Supports secure boot

Supports independent monitoring board functionality, supportsThe 1+1 redundancy backup function monitors the hardware operating status of the device in real time, including power load and power adjustment, automatic fan speed adjustment, and dynamic allocation of overall energy consumption.

reliability

The independent hardware switching board design achieves true separation of control and forwarding, and the switching board supports redundant backup.

Main control board supports1+1 redundancy backup, power supply supports M+N redundancy backup

The backplane adopts a passive design to avoid single points of failure.

All components support hot-swapping.

Supports different switch modes to optimize specific functions and meet the system resource requirements of users in different scenarios.

Supports real-time hot backup of various configuration data on the primary and backup main control boards.

Supports hot patching, allowing for online patch upgrades.

supportNSF/GR for OSFP/BGP/IS-IS等

Supports port aggregation and cross-board link aggregation.

supportThe INQA function, through the method of directly marking service packets and real-time detection technology of actual service flow, enables accurate packet loss monitoring and rapid fault localization capabilities in IP networks.

supportBFD for VRRP/BGP/IS-IS/OSPF/static routing, etc., implements a fast fault detection mechanism for each protocol, and supports a hardware BFD detection interval of 3.3ms.

Supports enhanced Ethernet ring networks, enabling enhanced ring networks across multiple campuses.100G speed ring network sub-millisecond fault switching

supportEthernet OAM (802.1ag and 802.3ah)

supportpublic relations

supportMonitor-Link

supportVCT

Support dualBoot functionality enables redundant backup, preventing the switch from failing to boot due to FLASH chip malfunction.

It supports optical port protection circuit design to monitor the status of optical modules. In the event of a fault, the faulty module can be isolated to ensure that the normal operation of other ports and the entire device is not affected.

supportSmart-Link

supportISSU technology enables full-service online upgrades

Supports enhanced Ethernet ring network elastic packet ring

Green and energy-saving

support802.3az Energy Efficient Ethernet

Supports intelligent fan speed control in different zones

Environmental requirements

Temperature range:0℃~45℃

Relative humidity:5%–95% (non-condensing)

powered by

AC:100V~240V

External dimensionsmm: Width × Depth × Height

440mm×520mm×442mm(10U)

440mm×640mm×530mm(12U)

440mm×640mm×796mm(18U)


Previous: none
Next: none
Previous: none
Next: none
Online
Customer service hotline
027-81566008 027-81566008
Service Hours:
8:00 - 24:00
Customer Service Team:
Online