With the growing maturity of virtualization and cloud computing technologies, an increasing number of cloud service providers and telecommunications operators have begun to provide public cloud services. Enterprises can rent resources and services from public clouds as required and create their own virtual data centers (VDCs) or virtual private clouds (VPCs), which saves construction costs and improves service agility for enterprises. As a result, more enterprises have started migrating their applications to public clouds. However, the infrastructure and resources of most public clouds are shared by all tenants, and enterprises cannot deploy their own network devices on public clouds, which brings great networking challenges to enterprises and cloud service providers.
Enterprise branches are typically dispersed in different regions. On traditional networks, enterprises are faced with long construction periods and high manual maintenance costs when deploying network devices and application servers. Hence, they need to simplify branch infrastructure, improve service deployment capabilities, save investment, and simplify maintenance. With migration of applications to the cloud and rapid development of server and virtualization technologies, it has become a trend to provide both network functions and IT applications on a single server.
To follow the industrial trend and address the challenges, H3C has launched a brand-new virtual services router (VSR). Like physical routers released by H3C, the VSR uses H3C’s mature Comware network operating system. Running on a standard server virtual machine or bare metal server, it provides features (including routing, firewall, VPN, QoS, and configuration management) and user experience the same as physical routers. It can help enterprises establish secure, unified, and scalable intelligent branches and reduce the quantity and investment on branch infrastructure.

H3C VSR1000 runs on a virtual machine and is a license-controlled software product. Different licenses are available, providing the flexibility for users to select functions, features, and validity periods as needed.
Unlike routers with custom hardware, H3C VSR is a software router that runs on an industrial-standard server VM.
Powerful routing capabilities
🎯 The VSR is based on the industry leading Comware 7 platform:
- Supports IPv4/IPv6 static and dynamic routing protocols, including RIP/RIPng, OSPF/OSPFv3, IS-IS/IS-ISv6, and BGP/BGP4+.
- Supports policy-based routing (PBR) and rich routing policies as well as flexible control, scheduling, and accounting of network traffic, meeting the networking needs of enterprises and operators.
- Supports the SR/SRv6 feature that makes the network protocol simple, scalable, programmable and highly reliable, helping customers build a sustainable network.
- Ultra-lightweight deployment
🎯 The VSR enables ultra-lightweight deployment:
- Suitable for deployment in public clouds, accelerating service deployment by virtue of zero transportation and zero cabling.
- Supports VMware ESXi, Linux KVM, H3C CAS and other mainstream hypervisors, realizing rapid deployment, batch deployment, image backup, rapid recovery, and flexible migration by giving full play to virtualization.
- Provides ISO image, OVA template, IPE, QCOW2 and other release formats to adapt to deployment in various environments.
- Ultra-high service elasticity
🎯 The VSR provides ultra-high service elasticity:
- Allows enterprises to build networks in a virtualized environment and schedules and manages network resources and services on demand. For example, enterprises can flexibly adjust the number and type of network ports according to their needs without purchasing new hardware cards.
- Realizes smooth upgrade and device performance improvement as required by dynamically adjusting VM resources and licenses, meeting business growth requirements at any time.
- Extending enterprise networks to the cloud
🎯 Enterprises can realize the following features by deploying VSRs in public clouds:
- Manages the enterprise’s VPC network as part of the enterprise network, which ensures consistent network configuration, security policy, management policy, and IP address planning, and realizes unified enterprise network management.
- Implements unified traffic control and deploys consistent network services (such as QoS, firewall, load balancing, and WAN optimization) the same as physical routers at enterprise branches and provides consistent network service experience.
- Establishes end-to-end VPN connections between the enterprise headquarter and branches and the enterprise VPC to enable more secure access to public cloud applications. Meanwhile, end-to-end access avoids data transit at the headquarter, thus reducing the response time from cloud applications and improving the user experience of cloud applications.
🎯 Comprehensive SDN capabilities
- Supports management and control protocols such as OpenFlow, telemetry, and NETCONF, and supports management and control by H3C AD-WAN controllers or third-party controllers.
- Supports forwarding services such as segment routing, VXLAN, and EVPN, and allows definition of multiple forwarding models to meet different service networking requirements.
- Supports SRv6 and EVPN L3VPN over SRv6 policy/BE networking capability.
Item | Specifications |
Software package | H3C VSR1000 software image in ISO, OVA, QCOW2, or IPE format |
Hypervisor | VMware ESXi Linux KVM H3C CAS |
Public cloud | Alibaba Cloud Tencent Cloud eCloud Ctyun Huawei Cloud UniCloud Microsoft Azure |
VM resource | 1vCPU (2 GB memory); 4vCPU (4 GB memory); 8vCPU (8 GB memory) 8 GB disk 2 to 32 virtual network adapters Virtual network adapter type: E1000, VMXNET3, VirtIO, Intel 82599 SRIOV, Intel X710 SRIOV, Mellanox CX4, Mellanox CX5 |
Ethernet | Layer 3 Ethernet interface/subinterface ARP VLAN, IEEE 802.1Q PPPoE client |
IP routing | Static routing Dynamic routing: RIPv1/v2, OSPFv2, BGP, IS-IS Multicast routing: IGMPv1/v2/v3, PIM-DM, PIM-SM, PIM-SSM, MSDP Routing policy Routing iteration |
IP service | Basic forwarding/fast forwarding (unicast/multicast) Policy-based routing Ping, tracert DHCP server, DHCP relay, DHCP client DNS client, DNS proxy, DDNS FTP server, FTP client, TFTP client Telnet server, Telnet client NTPv3/NTPv4/SNTPv3/SNTPv4 |
IPv6 | Basic functions: IPv6 ND, IPv6 PMTU, IPv6 FIB, IPv6 ACL, DS-Lite IPv6 tunneling technology: Manual tunneling, automatic tunneling, GRE tunneling, 6to4 tunneling, ISATAP tunneling Static routing Dynamic routing: RIPng, OSPFv3, IS-ISv6, BGP4+ IPv6 multicast protocols: MLDv1/v2, PIM-DM, PIM-SM, PIM-SSM |
MPLS | LDP, LSM, static LSP, static CR-LSP L3VPN: Cross-domain MPLS VPN (option 1/2/3), nested MPLS VPN MPLS TE, RSVP TE |
SDN features | NETCONF, OpenFlow, Telemetry VXLAN, EVPN layer 2 virtual Ethernet link Segment routing SRv6 SRv6 policy SRv6 traffic engineering policy EVPN L3VPN over SRv6 EVPN L3VPN over SRv6 policy SRv6 policy traffic statistics SRv6 OAM BFD for SRv6 |
QoS | Traffic classification Traffic policy: CAR, LR Traffic shaping: GTS Congestion management: FIFO, WFQ, CBQ Congestion avoidance: Tail-drop, WRED |
Security | DDoS attack prevention, ARP attack prevention, URL filtering Firewall features: Packet filtering, ASPF, connection limit VPN features: IPsec VPN, SSL VPN, GRE VPN, L2TP VPN, etc. Other security features: SSHv1.5/2.0, SSL, NAT/NAPT, PKI, URPF |
Reliability | VRRP/VRRPv3 Multi-link-based load sharing and backup Association between NQA and routing, VRRP, and interface backup for end-to-end link detection and backup. |
Management and maintenance | User access management: Console port, AUX port, SSH, Telnet, FTP Local management: CLI, automatic configuration, file system Network management: SNMPv1/v2c/v3, IMC, NETCONF, Syslog, NQA, sFlow, NetStream, EAA |

In this solution, the VSRs are deployed as gateways for connecting enterprise networks to the cloud. They are deployed on data center servers to provide VPNs between enterprise VPCs and headquarters/branches, ensuring security of enterprise tenants.
The VSR can bring the following benefits to enterprises:
- Manages the enterprise’s VPC network as part of the enterprise network, which ensures consistent network configuration, security policy, management policy, and IP address planning, and realizes unified enterprise network management.
- Implements unified traffic control and deploys consistent network services (such as QoS, firewall, load balancing, and WAN optimization) the same as physical routers at enterprise branches, and provides consistent network service experience.
- Establishes end-to-end VPN connections between the enterprise headquarter and branches and the enterprise VPC to enable more secure access to public cloud applications. Meanwhile, end-to-end access avoids transit at the headquarter, thus reducing the response time to cloud applications and improving the user experience of cloud applications.
The VSR can bring the following benefits to cloud service providers:
- Extends the MPLS network to enterprise VPC to provide enterprises with manageable end-to-end cloud connection services and enhanced operational capabilities.
- Enables the VPC network to be managed by enterprises to simplify tenant management and reduce maintenance costs.

In the e-government cloud solution, the data center uniformly manages server resources and allocates them to departments for application installation and data storage. Security isolation between the departments must be guaranteed, and there are also requirements for information sharing and data exchange. In addition, leaders in the municipal government and community/street offices need to access data of departments as needed.
The VSR deployed in the data center acts as a VPN gateway and provides the following:
- Data isolation and sharing control between departments.
- Secure access to data of departments by departmental members, municipal government, and community/street offices.
The VSR deployed in the community/street office acts as an access gateway and provides functions such as gateway access and VPN security.

In the networking scenario for connecting branches to the cloud, VSRs are deployed on public clouds as hub nodes. When the primary public cloud fails, the branch services can be switched to the standby public cloud to improve reliability. VSRs allows management from H3C’s AD-WAN controller for deployment of the AD–WAN headquarter-branch solution, which enables unified management of devices across the network, link quality visualization, service traffic visualization, and intelligent traffic scheduling, thus providing good user experience of enterprise services.
The VSR1000 software can be downloaded and installed for free. To use a VSR1000, purchase a license as required.
| Product ID | Description |
| LIS-VSR1000-C1-Y1 | H3C VSR1000 License (Comware V7, Standard Edition, 1 vCPU, 1 Year) |
| LIS-VSR1000-C1-Y3 | H3C VSR1000 License (Comware V7, Standard Edition, 1 vCPU, 3 Years) |
| LIS-VSR1000-C1 | H3C VSR1000 License (Comware V7, Standard Edition, 1 vCPU, Permanent) |
| LIS-VSR1000-C4-Y1 | H3C VSR1000 License (Comware V7, Standard Edition, 4 vCPUs, 1 Year) |
| LIS-VSR1000-C4-Y3 | H3C VSR1000 License (Comware V7, Standard Edition, 4 vCPUs, 3 Years) |
| LIS-VSR1000-C4 | H3C VSR1000 License(Comware V7,STANDARD Edition,4vCPUs,Permanent) |
| LIS-VSR1000-C8-Y1 | H3C VSR1000 License (Comware V7, Standard Edition, 8 vCPUs, 1 Year) |
| LIS-VSR1000-C8-Y3 | H3C VSR1000 License (Comware V7, Standard Edition, 8 vCPUs, 3 Years) |
| LIS-VSR1000-C8 | H3C VSR1000 License (Comware V7, Standard Edition, 8 vCPUs, Permanent) |
| LIS-VSR1000-CX-Y1 | H3C VSR1000 License(Comware V7, Standard Edition, 1Year) |
| LIS-VSR1000-AD | H3C VSR1000 Feature License(Comware V7, Advanced Features) |




Reviews
There are no reviews yet.