OR-8000
SKU OKT-OR8000 · From $2,640
Enterprise edge routing and stateful firewall at 40 Gbps, line-rate where it counts.
- 40 Gbps stateful firewall and 28 Gbps AES-256-GCM IPsec — hardware AES-NI, not software.
- 8 million concurrent sessions at 480k new sessions/s for high-churn edge workloads.
- Full BGP4 / OSPF / IS-IS routing with WireGuard and IPsec IKEv2 to 5,000 tunnels.
Throughput
40 Gbps firewall · 28 Gbps IPsec VPN
Ports
8× SFP+ 10GbE · 2× RJ45 2.5GbE
Sessions
8,000,000 concurrent / 480k new/s
Management
BGP · CLI · REST · SNMP
Every number, published.
Interfaces
| WAN / LAN ports | 8× SFP+ (10GbE / 1GbE) |
|---|---|
| Copper ports | 2× RJ45 100M/1G/2.5G |
| Management port | 1× RJ45 10/100/1000 out-of-band |
| Console | 1× RJ45 RS-232, 1× USB-C |
| Expansion | 1× module bay (LTE / extra SFP28) |
Performance
| Firewall throughput | 40 Gbps (1518-byte), 22 Gbps (IMIX) |
|---|---|
| IPsec VPN throughput | 28 Gbps (AES-256-GCM, AES-NI) |
| Concurrent sessions | 8,000,000 |
| New sessions/s | 480,000 |
| Routing protocols | BGP4, OSPF, IS-IS, PIM, VRRP |
| Tunnels | WireGuard, IPsec IKEv2, GRE, 5,000 peers |
Power & Environment
| Power supplies | 2× 350W hot-swap (1+1 redundant) |
|---|---|
| Typical draw | 126 W |
| Cooling | 3+1 hot-swap fans, front-to-back |
| Operating temperature | 0 °C to 45 °C |
| MTBF | 228,000 hours (25 °C) |
| Form factor | 1U, 440 × 400 × 44 mm |
The front panel, to the octet.
Each interface is octet-numbered and colour-keyed by media. Hover a cell for its role.
- Fiber / SFP
- Copper / RJ45
- Console
Photographed as hardware.
The OR-8000 is the edge router and firewall for a site that terminates real bandwidth. The numbers we publish are paired with their test conditions: 40 Gbps of stateful firewall throughput at 1518-byte frames, 22 Gbps at IMIX — the mixed-size traffic distribution that resembles actual internet load — and 28 Gbps of IPsec with AES-256-GCM using the hardware AES-NI path. We list the IMIX figure because the 1518-byte number alone would tell you how the box performs on a traffic pattern you will never see.
Session capacity is eight million concurrent flows at 480,000 new sessions per second, which is the dimension that matters for NAT-heavy edges and any workload with high connection churn — DNS, short-lived API calls, scanning traffic. Routing is the full enterprise set: BGP4 for multi-homing and transit, OSPF and IS-IS for the interior, PIM for multicast, VRRP for gateway redundancy. VPN covers both WireGuard and IPsec IKEv2, scaling to 5,000 concurrent tunnels for hub-and-spoke or remote-access designs.
The chassis is built to stay up. Two 350W supplies run 1+1 redundant, three fans run 3+1, all hot-swap and front-serviceable. A single expansion bay takes an LTE module for out-of-band or last-resort WAN failover, or an SFP28 module for a 25G uplink. Typical draw is 126 W; rated MTBF is 228,000 hours.
Deployment note: Terminate dual WAN on ports 01 and 02 with BGP to each upstream for active-active or active-standby. Keep the OOB management port (07) on a separate physical path — its value is being reachable when the data plane is not. Optics and DAC are ordered via OF-SFP10; the LTE and SFP28 expansion modules are ordered separately by part number. Ships with the firewall in default-deny posture — build the allow policy before cutting production traffic over.
Spec it against the rest of the line.
Drop the OR-8000 into the Network Builder, or browse the full catalog.
OKT-OR8000 · OKTET — INFRASTRUCTURE, TO SPEC.