CISCO2921/K9

Cisco 2921 Router w/3 GE,4 EHWIC,3 DSP,1 SM,256MB CF,512MB DRAM,IPB

2921 spec

Modularity Features and Benefits:

The Cisco 2900 Series provides significantly enhanced modular capabilities offering investment protection for customers. Taking advantage of common interface cards across a network greatly reduces the complexity of managing inventory requirements, implementing large network rollouts, and maintaining configurations across a variety of branch-office sizes.


ISR Modules


Cisco Service Module



• Each service module slot offers high-data-throughput capability:

• Up to 4 Gbps aggregate toward the route processor.

• Up to 2 Gbps aggregate to other module slots over MGF.

• Service module (SM) slots are highly flexible with support for double-wide service modules (SM-Ds), which are Service Modules that require two SM slots. SM-Ds in the Cisco 2921 and 2951 provide flexibility for higher-density modules.

• A service module slot replaces the network module and the extension module for voice/fax (EVM) slots and is offered on Cisco 2911, 2921, and 2951 ISRs.

• An adapter module enables backward compatibility with existing network modules, enhanced network modules (NMEs), and EVMs.

• Service module slots provide twice the power capabilities relative to the network-module slots, allowing for flexibility for higher-scale and better-performance modules.

• Power to service module slots can be managed by extensions similar to the Cisco EnergyWise framework, so your organization can reduce energy consumption in your network infrastructure. Full EnergyWise support will be available in future software releases.
Cisco Enhanced High-Speed WAN Interface Card (EHWIC)


• The EHWIC slot provides enhancements to the prior generation’s high-speed WAN interface card (HWIC) slots while provide maximum investment protection by natively supporting HWICs, WAN interface cards (WICs), voice interface cards (VICs), and voice/WAN interface cards (VWICs).

• Four integrated EHWIC slots on the Cisco 2901, 2911, 2921, and 2951 allow for more flexible configurations.

• Each HWIC slot offers high-data-throughput capability:

• Up to 1.6 Gbps aggregate toward the route processor.

• Up to 2 Gbps aggregate to other module slots over the MGF.

• Flexibility to support double-wide modules is enabled by combining two EHWIC slots. Up to 2 doublewide HWIC (HWIC-D) modules are supported.

Cisco High-Density Packet Voice Digital Signal Processor (DSP) Module (PVDM3) Slots on Motherboard

• PVDM3 slots natively support PVDM3 modules, providing support for richer density for rich-media voice and video.

• Each PVDM3 slot connects back to the system architecture through a 2 Gbps aggregate link through the MGF.

• Investment protection for PVDM2 modules is supported through an adapter module.

• Power to the PVDM slots can be managed by extensions similar to the Cisco EnergyWise framework, so your organization can reduce energy consumption in your network infrastructure. Full EnergyWise support will be available in future software releases.


Cisco 2921 Integrated Services Router (ISR) delivers highly secure data, voice, video, and application services for small offices.

Product FAQ

Q: Does this router Cisco 2921/K9 come with LAN port modules?

A: NO, as for 2921 it comes with no LAN port. But for routers more advanced than Cisco2901 support SM slots, you can chose SM, like SM-ES3G-16-P, support Layer2/3 ports can you use them as LAN ports.

Q: Are these2921/k9, 3945/k9 have the same IOS?

A: NO, they have the different part number but their features are similar.

Q: I’ve got a 2921 used to connect to physical sites over a WAN connection (BT Fibre). I was wondering if someone can tell me (or point me to) what speeds the 2921 can support in terms of throughput. We do dynamic routing but we don’t so any encryption or NAT.

A: It says 2921 can support 245.76 mbps

Q: I purchased brand new router from Cisco 2921 also I purchased an SFP-Transceiver (GLC-SX MM) along with this Router. However the Router does not Supporting SFP Transceiver. Currently the Router is having Universal IOS: “c2900-universalk9-mz.SPA.151-3.T1.bin”. Kindly provide the IOS i woud like to use. Is the same is IOS compatibility, thanks.

A: MAJOR untested bug in IOS 15.0(1) M3 which was the default image when we bought the devices *** AVOID IOS 15.0 series *** There are several bugs related to SFPs like: Does does recognize SFP does not recognize some EHWIC cards such as, but not limited to EHWIC 1GE-SFP-CU.

Q. What is the exact HSEC-k9 license?

A. The HSEC-K9 license removes the curtailment enforced by the U.S. government export restrictions on the encrypted tunnel count and encrypted throughput. HSEC-K9 is available only on the Cisco 2921, Cisco 2951, Cisco 3925, Cisco 3945, Cisco 3925E, and Cisco 3945E. With the HSEC-K9 license, the ISRG2 router can go over the curtailment limit of 225 tunnels maximum for IP Security (IPsec) and encrypted throughput of 85-Mbps unidirectional traffic in or out of the ISR G2 router, with a bidirectional total of 170 Mbps. The Cisco 1941, 2901, and 2911 already have maximum encryption capacities within export limits.

Q. What countries are classified license-free zones?

A. Countries belonging to the EU license-free zone include Australia, Austria, Belgium, Bulgaria, Canada, Cypress, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Japan, Latvia, Lithuania, Luxembourg, Malta, Netherlands, New Zealand, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey, United Kingdom, and the United States.

Q: We know the ISR2 series included VPN hardware acceleration but there is a “HSEC” which included an “advanced” encryption card. We are just trying to get my head around it. Is the HSEC bundle really needed over the standard SEC bundle? Now we need to support a 50meg Internet connection with 4 Site-to-Site VPNs and use of the firewall, NAT and QOS on each router. We are looking at the Cisco2921-SEC/K9 bundle. Does this sound about right?

A: If your internet link is 50mb, then a 2921 (non-HSEC) can handle the encryption/decryption. The standard SEC license comes with a software-based rate limiter of 85 Mbps each way. If the protocol does not handle loss/retransmissions very well, throughput can easily plummet. Testing in a lab environment with two Cisco 2921s, I saw speeds drop to 25 Mbps. Also info on the HSEC license can be found here in regards to what it is and what t does for you. It allows for addition through for encrypted traffic NASA higher number of VPN tunnels.

Q: We have installed a 60 day license for the security k9. The Cisco 2900 router we got. And we are trying to set up a client to site vpn on this and it still does not recognize the ipsec and isakmp commands. Is there a command I need to do to now enable ipsec and isakmp?

A: Make sure your Cisco 2900 took the license, issue ‘show license’ and verify. Show license shows that it is in there and active. I rebooted and it still throws an error whenever i issue crypto ipsec or crypto isakmp Here is your problem: from “show license” License State: Active, Not in Use, EULA accepted “not in use” is the key. Try using “license modify priority securityk9 high” or the config command “license boot module c2900 tech securityk9” to make this feature in use, rather than not in use.


