
H3C WA6628E-T Wi-Fi 6 Rail Transit Access Point
An all-metal Wi-Fi 6 AP for trains and vehicles, with M12 connectors and resistance to strong electromagnetic interference.
Price on Request

An AI-accelerated chassis firewall with dual GPUs, CPUs and an AI chip, built for data centres, CGN and large enterprise edges.
Island-wide delivery to all 25 districts
| Models | M9000-AI-E8, M9000-AI-E16 |
|---|---|
| Supervisor engine module slots | 2 |
| Service module slots | M9000-AI-E8: 8; M9000-AI-E16: 16 |
| Switching fabric module slots | 4 |
| Redundancy design | Redundant supervisor engine modules, switching fabric modules, power supplies, and fan trays |
| Dimensions (H × W × D) | M9000-AI-E8: 264 × 440 × 857 mm (10.39 × 17.32 × 33.74 in), 6 RU; M9000-AI-E16: 841.7 × 440 × 640 mm (33.14 × 17.32 × 25.20 in), 19 RU |
| Weight | M9000-AI-E8: < 140 kg (308.64 lb); M9000-AI-E16: < 220 kg (485.01 lb) |
| Power consumption | M9000-AI-E8: < 2252 W; M9000-AI-E16: < 3360 W |
| Ambient temperature | Operating: 0°C to 45°C (32°F to 113°F) Storage: –40°C to +70°C (–40°F to +158°F) |
| Operating mode | Route, transparent, bridge |
| AAA | Portal, RADIUS, HWTACACS, PKI/CA (X.509 format) , and domain authentications Manual key, IKEv2, redundant VPN gateway, EAP authentication, IKEv2 redirection |
| Multiservice security gateway | Virtual multi-service security gateway Security zone Attack protection against malicious attacks, such as land, smurf, fraggle, ping of death, tear drop, IP spoofing, IP fragmentation, ARP spoofing, reverse ARP lookup, invalid TCP flag, large ICMP packet, address/port scanning, SYN flood, ICMP flood, UDP flood, and DNS query flood Dynamic packet filtering ASPF application layer packet filtering Static and dynamic blacklist function MAC-IP binding MAC-based ACL ICMPv6, DHCPv6 802.1Q VLAN transparent transmission MLD, ND |
| Security policy | ACL with rule matching criteria including security zone (security zone group), service, user, application, and time range. Security level evaluation for security policies, security policy optimization Fuzzy search for security policies, including redundant and unmatched security policies Policy grouping Policy creation, deletion, editing, migration on a third-party platform State validity-based security monitoring Access control by allowlist and denylist, one-key setting of allowlist and denylist |
| Routing | Static routing Dynamic routing protocols: RIP, OSPF, BGP, IS-IS Policy-based routing with support for traffic matching criteria including source IP address, destination IP address, source port number, destination port number, service, application type, user, user group, incoming interface, outgoing interface, and link state |
| Anti-virus protection | IPv4 and IPv6 dual-stack virus signature detection and protection, protecting against mail viruses, Web application viruses, common file viruses, Trojans, worms, malicious webpages, compressed data, shelling and compressed package (zip, gzip, tar) viruses Manual and automatic upgrade of the signature library, manual import of signature libraries Cloud virus signature library Stream-based processing Virus detection based on HTTP, FTP, SMTP, and POP3 Support for detection of Backdoor, Email-Worm, IM-Worm, P2P-Worm, Trojan, AdWare, and Virus Virus logs and reports |
| Web security protection | Web security detection CC attack prevention Server connection detection, allowing for learning parameter configuration Prevention against attacks such as webpage hanging horse and Trojan Prevention against brute force cracking of passwords for common Web services (including HTTP, FTP, SSH, SMTP, and IMAP) and common database software (such as MySQL, Oracle, and MSSQL) |
| Deep packet inspection | Prevention of attacks such as hacker, worm/virus, Trojan, malicious code, spyware/adware Application scenario-specific security policy and attack defense template Application layer (HTTP, HTTPS, DNS, FTP, and SIP) flood attack defense Automatic generation of DDoS attack prevention policies through threshold-based and self-learning techniques Prevention of attacks such as buffer overflow, SQL injection, and IDS/IPS bypass Attack signature categories (based on attack types and target systems) and severity levels (including high, medium, low, and notification) Manual and automatic upgrade for the |
| HTTPS encrypted traffic inspection | SSL proxy and SSL decryption, decrypting the HTTPS traffic from the client (or server), implementing content security checks, auditing, and attack defense for the traffic Refined classification and decryption of URLs |
| Email/webpage/application layer filtering | Email filtering SMTP email address filtering Email subject/content/attachment filtering Webpage filtering HTTP URL/content filtering Java blocking ActiveX blocking SQL injection attack prevention |
| Intelligent bandwidth control | Bandwidth guarantee for specific users, IP addresses, interfaces, or services Traffic shaping Maximum traffic limit, minimum traffic limit, or connection limit setting by user or IP Application layer protocol-based flow control policy settings, including maximum/minimum bandwidth, guaranteed bandwidth, and protocol traffic priority |
| Load balancing | HTTP- and HTTPS-based application layer link load balancing Transparent DNS proxy, DNS filtering, intelligent DNS Server load balancing Global load balancing Link health monitoring Intelligent link selection |
| NAT | Many-to-one NAT, which maps multiple internal addresses to one public address Many-to-many NAT, which maps multiple internal addresses to multiple public addresses One-to-one NAT, which maps one internal address to one public address NAT capacity expansion through port reuse NAT of both source address and destination address, source NAT address pool usage alarm External hosts access to internal servers Internal address to public interface address mapping NAT support for DNS Setting effective period for NAT NAT ALGs for NAT ALG, including DNS, FTP, H.323, ILS, MSN, NBT, PPTP, and SIP NAT444, NA |
| VPN | L2TP VPN IPSec VPN GRE VPN SSL VPN IPv6 over IPv4 GRE tunnels |
| IPv6 | IPv6 status firewall IPv6 interzone policy IPv6 attack protection IPv6 connection limit IPv6 protocols such as ICMPv6, PMTU, Ping6, DNS6, TraceRT6, Telnet6, DHCPv6 Client, and DHCPv6 Relay IPv6 routing: RIPng, OSPFv3, BGP4+, static routing, policy-based routing, PIM-SM, and PIM-DM IPv6 transition techniques: NAT-PT, IPv6 tunneling, NAT64 (DNS64), and DS-LITE |
| High availability | Active/active and active/standby stateful failover IFF SCF Asymmetric-path mode stateful failover IKE-based IPsec VRRP Static and dynamic link aggregation ISSU Patch HA with support for software of different versions BFD |
| Configuration and management | Configuration management at the CLI Remote management through Web Device management through H3C IMC SNMPv3, compatible with SNMPv2c and SNMPv1 Security policy optimization by simulating deployment of security policies and comparing the results Compliance and legitimacy check of security policies by denylist, allowlist, application type, policy risk level, security rule, and hybrid rule. Security policy logs, NAT logs, attack defense logs, URL logs Logs containing any combinations of security policy, NAT, attack defense, and URL information Log sending at intervals |
| Environmental protection | EU RoHS compliance |

An all-metal Wi-Fi 6 AP for trains and vehicles, with M12 connectors and resistance to strong electromagnetic interference.

A 12-stream Wi-Fi 6 flagship with an 8x8 5 GHz radio and 10G uplink for stadiums, auditoriums and lecture halls.

A Wi-Fi 6 AP with a 4x4 5 GHz radio and 5G multigigabit uplink for demanding indoor deployments.

An outdoor Wi-Fi 6 AP with two 2x2 radios, switchable to dual 5 GHz, plus PoE-out for cameras or sensors.