ROUTER

OR-8000

SKU OKT-OR8000 · From $2,640

Enterprise edge routing and stateful firewall at 40 Gbps, line-rate where it counts.

  • 40 Gbps stateful firewall and 28 Gbps AES-256-GCM IPsec — hardware AES-NI, not software.
  • 8 million concurrent sessions at 480k new sessions/s for high-churn edge workloads.
  • Full BGP4 / OSPF / IS-IS routing with WireGuard and IPsec IKEv2 to 5,000 tunnels.
OKTET OR-8000 — ROUTER ROUTER
STUDIO REFERENCE UNIT 01
01

Throughput

40 Gbps firewall · 28 Gbps IPsec VPN

02

Ports

8× SFP+ 10GbE · 2× RJ45 2.5GbE

03

Sessions

8,000,000 concurrent / 480k new/s

04

Management

BGP · CLI · REST · SNMP

02 / SPECIFICATION

Every number, published.

Measured on the bench, both directions, no marketing throughput.
01

Interfaces

WAN / LAN ports8× SFP+ (10GbE / 1GbE)
Copper ports2× RJ45 100M/1G/2.5G
Management port1× RJ45 10/100/1000 out-of-band
Console1× RJ45 RS-232, 1× USB-C
Expansion1× module bay (LTE / extra SFP28)
02

Performance

Firewall throughput40 Gbps (1518-byte), 22 Gbps (IMIX)
IPsec VPN throughput28 Gbps (AES-256-GCM, AES-NI)
Concurrent sessions8,000,000
New sessions/s480,000
Routing protocolsBGP4, OSPF, IS-IS, PIM, VRRP
TunnelsWireGuard, IPsec IKEv2, GRE, 5,000 peers
03

Power & Environment

Power supplies2× 350W hot-swap (1+1 redundant)
Typical draw126 W
Cooling3+1 hot-swap fans, front-to-back
Operating temperature0 °C to 45 °C
MTBF228,000 hours (25 °C)
Form factor1U, 440 × 400 × 44 mm
03 / FACEPLATE

The front panel, to the octet.

Each interface is octet-numbered and colour-keyed by media. Hover a cell for its role.

01fiber
02fiber
03fiber
04fiber
05copper
06copper
07copper
08console
  • Fiber / SFP
  • Copper / RJ45
  • Console
04 / GALLERY

Photographed as hardware.

OKTET OR-8000 detail 01
01 / 04
OKTET OR-8000 detail 02
02 / 04
OKTET OR-8000 detail 03
03 / 04
OKTET OR-8000 detail 04
04 / 04
05 / ENGINEERING NOTES

The OR-8000 is the edge router and firewall for a site that terminates real bandwidth. The numbers we publish are paired with their test conditions: 40 Gbps of stateful firewall throughput at 1518-byte frames, 22 Gbps at IMIX — the mixed-size traffic distribution that resembles actual internet load — and 28 Gbps of IPsec with AES-256-GCM using the hardware AES-NI path. We list the IMIX figure because the 1518-byte number alone would tell you how the box performs on a traffic pattern you will never see.

Session capacity is eight million concurrent flows at 480,000 new sessions per second, which is the dimension that matters for NAT-heavy edges and any workload with high connection churn — DNS, short-lived API calls, scanning traffic. Routing is the full enterprise set: BGP4 for multi-homing and transit, OSPF and IS-IS for the interior, PIM for multicast, VRRP for gateway redundancy. VPN covers both WireGuard and IPsec IKEv2, scaling to 5,000 concurrent tunnels for hub-and-spoke or remote-access designs.

The chassis is built to stay up. Two 350W supplies run 1+1 redundant, three fans run 3+1, all hot-swap and front-serviceable. A single expansion bay takes an LTE module for out-of-band or last-resort WAN failover, or an SFP28 module for a 25G uplink. Typical draw is 126 W; rated MTBF is 228,000 hours.

Deployment note: Terminate dual WAN on ports 01 and 02 with BGP to each upstream for active-active or active-standby. Keep the OOB management port (07) on a separate physical path — its value is being reachable when the data plane is not. Optics and DAC are ordered via OF-SFP10; the LTE and SFP28 expansion modules are ordered separately by part number. Ships with the firewall in default-deny posture — build the allow policy before cutting production traffic over.

06 / NEXT

Spec it against the rest of the line.

Drop the OR-8000 into the Network Builder, or browse the full catalog.

OKT-OR8000 · OKTET — INFRASTRUCTURE, TO SPEC.