Skip to content
[menu][close]

FOUNDRYNETNo. 001SEPTEMBER 2026FOUNDRY ARCHIVE

Original page: www.foundrynet.com/products/routers/accessiron/index.html (archived)

Foundry AccessIron: Access Routers for Branch and WAN Edge

AccessIron was a short-lived Foundry Networks attempt at branch and WAN edge routing, introduced in 2004 according to the company's own filings, extending the IronWare CLI to T1/E1 and serial interfaces. It is remembered mostly for the command reference PDF hosted under its documentation path.

Unofficial recordNot affiliatedNo documents hosted

On this page

01 What AccessIron was

AccessIron was the Foundry Networks entry into access routing, introduced in 2004 according to Foundry's own quarterly and annual filings (an earlier 2001 date circulates in forum posts but has no primary source). Where NetIron sat in the core, AccessIron was meant for the branch office and the WAN edge: a compact router with Ethernet on the LAN side and T1/E1, fractional T1, serial or ISDN interfaces toward the carrier, running a CLI in the IronWare style so that a Foundry-trained engineer could manage the WAN without learning a second command language. The routing hub covers the protocols involved.

The AR1200 series is the model name most often cited in forum posts and resale listings. Specific model numbers, interface counts and software versions are hedged here because surviving documentation is sparse and inconsistent.

02 Role in the network

An access router terminates a carrier circuit, encapsulates IP in PPP, HDLC or Frame Relay on the WAN side, and routes to the branch LAN. It usually adds NAT, access lists, a DHCP server and static or RIP routing toward headquarters, with OSPF on larger sites. AccessIron did those things. The intended buyer already ran FastIron switches in the branch and BigIron or NetIron at headquarters, and wanted one vendor and one CLI end to end.

Branch WAN edge pathBRANCH WAN EDGE PATH01Branch LANswitch02AccessIronrouter03T1/E1 circuit04Carriernetwork05HeadquarterscoreBranch WAN edge pathBRANCH WAN EDGE PATH01Branch LAN switch02AccessIron router03T1/E1 circuit04Carrier network05Headquarters core
The access router was the last Foundry device before the carrier.
AccessIron in outline. Interface lists vary by model and are qualitative.
AspectAccessIron approachComment
WAN interfacesT1/E1, fractional T1, serial, ISDN on some modelsCircuit types typical of the mid-2000s branch
LAN sideFast EthernetFed a FastIron or EdgeIron switch
RoutingStatic, RIP, OSPF; NAT and access listsAdequate for branch use
CLIIronWare styleMain differentiator for Foundry shops
Market outcomeWithdrawn within a few yearsBranch routing stayed with established vendors

03 Why it did not last

Foundry built its reputation on Ethernet switching ASICs, where it could beat larger vendors on price per port and forwarding rate. Branch routing rewarded different things: a huge catalogue of WAN interface cards, mature support for every carrier encapsulation, voice integration, and a global reseller channel that already sold one dominant brand. AccessIron offered none of those advantages, and the branch router market was consolidating around incumbents. Foundry withdrew the line around 2004 and concentrated on switching, load balancing and core routing, as described on the company history page.

NOTE

FoundryNet is an independent archive and reference, not affiliated with Foundry Networks, Brocade, Broadcom or Extreme Networks. The AccessIron documentation is described here, not reproduced.

04 AccessIron in the filings and the archived product page

The dating of AccessIron is where forum memory and the company's own record part company. Foundry's results release for the second quarter of 2004, filed as an 8-K exhibit in July 2004, lists AccessIron enterprise WAN access routers among the products introduced during that quarter, and the release for the following quarter reports continued traction with them. The Form 10-K for 2004 states plainly that the line of AccessIron WAN aggregation routers was introduced in 2004, for T-carrier, E-carrier and T3 interconnection with carrier WAN services, with Ethernet ports on the LAN side. Treat mid-2004 as the documented launch; the earlier dates that circulate, including the approximate range in the summary at the top of this page, have no dated source behind them.

A June 2004 capture of the AccessIron product page fills in the models. The AR1202 and AR1204 carried two or four T1 or E1 ports, with VPN variants of each; the AR1208 and AR1216 carried eight or sixteen; the AR3201 and AR3202 carried one or two DS3 circuits, clear channel or channelised. Every model listed two 10/100 Ethernet ports, 256 MB of SDRAM and BGP, with 16 MB or 32 MB of flash. The feature list named Multilink PPP and Multilink Frame Relay, quality of service, VRRP, BGP multihoming, VLAN tagging, a built-in CSU/DSU, NAT, stateful packet inspection and a transparent Layer 2 mode the page called Virtual Ethernet. Datasheet PDFs captured from the same directory carry August and December 2004 in their file names, which is consistent with the filings.

AccessIron functions and their current equivalents. Routing survived as is; the circuit types and the built-in circuit hardware did not.
AccessIron function (2004)Vendor-neutral equivalent todayStandard or reference
NxT1 or NxE1 bundles with Multilink PPPEthernet handoff from the carrier; bonding, if needed, by link aggregation or by an SD-WAN overlayRFC 1990, PPP Multilink; IEEE 802.1AX
Clear channel or channelised DS31 GbE or 10 GbE carrier Ethernet accessMEF carrier Ethernet services
Built-in CSU/DSUCarrier network interface device at the demarcationCarrier specific
Frame Relay to headquartersCarrier MPLS VPN or IPsec over the InternetRFC 4364; RFC 4301
VRRP for gateway failoverVRRP, unchanged in purposeRFC 5798, VRRP version 3
BGP multihoming across two carriersBGP multihoming, unchanged; route origin validation addedRFC 4271; RFC 6811
Stateful packet inspection and NAT on the routerStateful firewall or next-generation firewall at the branch edgeRFC 3234 on middleboxes

Two of those surviving functions are covered on this site: the VRRP election that keeps a default gateway alive and carrier MPLS VPN handoffs that replaced leased circuits.

05 The command reference that outlived the product

The most durable trace of AccessIron is a URL. The Foundry command reference PDF was hosted under the AccessIron documentation path, and because it covered the IronWare command set broadly, forum posts and course notes linked to it as a general Foundry CLI reference for years after the routers themselves disappeared. Many visitors who follow those links are looking for switch commands, not WAN configuration. The CLI command reference page on this site is the place to go for that.

Illustrative IronWare-style commands relevant to a WAN edge router
show version
show interfaces brief
show ip route
show ip interface
show running-config

06 Running an AccessIron today: what an operator must check

Almost nobody runs one, but units do turn up in branch cupboards where a carrier circuit was cancelled years ago and the router was never removed. The checks are short. Confirm whether any circuit is still terminated (a T1 port with alarms clear and traffic counters moving means a live contract someone is paying for). Confirm console access, since the management address is likely on a subnet nobody remembers. Copy the configuration off. Then decide the replacement: the table above maps each function. Whatever encryption the 2004 VPN image offers, treat it as unsuitable for anything sensitive; the specific algorithms are not stated here because no verified manual lists them.

Illustrative inventory of an inherited AccessIron, if the image accepts these forms
ar1# show version
  (record platform, release and serial number)
ar1# show interfaces brief
  (a serial or T1 interface in the up state is still connected to something)
ar1# show ip route
  (static routes reveal where the branch expected headquarters to be)
ar1# show ip bgp
  (an established session means a carrier still peers with this box)
ar1# show running-config
  (copy it off before the unit is powered down)
ar1# show log

Pitfalls seen with these units:

  • Dating the line from forum posts; the filings put the launch in mid-2004, and any earlier date needs a source.
  • Reading the model table as a datasheet; the archived page lists interface counts and memory, not throughput, and it disclaims its own accuracy.
  • Assuming IronWare switch syntax carries over exactly; the AccessIron software was IronWare-style, and the command reference hosted under its documentation path is the only reason most people met it.
  • Powering down a unit before checking whether the carrier circuit is still billed; the router is worthless, the contract is not.
  • Expecting the transparent Layer 2 mode the product page called Virtual Ethernet to behave like a modern Ethernet over MPLS pseudowire; it bridged a LAN across a leased circuit, and a replacement needs a carrier Ethernet service or an overlay, not a like-for-like router.

One last check belongs to the person who inherits the cupboard rather than the router: the AccessIron command reference PDF that old links point at was hosted under this product's documentation path, so a saved copy of that PDF, with its capture date and hash recorded, is worth more to the next engineer than the router itself.

07 AccessIron today

The line is purely historical. T1 and E1 circuits have largely been replaced by Ethernet handoffs and broadband, so the WAN interfaces have no modern use, and there is no software or documentation support from any successor vendor. A surviving unit is a collector item. Its only practical role is as a small IronWare-style CLI trainer if the Ethernet side still works, and even then a FastIron switch is a better and more common choice. The larger router lines that did succeed are profiled with the rest of the catalogue in the archive overview.

08 Questions

What was the Foundry AccessIron?

An early-2000s access router line for branch offices and the WAN edge, with T1/E1, serial and Ethernet interfaces and an IronWare-style CLI. The AR1200 series is the commonly cited model name. Foundry withdrew the line within a few years.

Why did Foundry stop making AccessIron routers?

Branch routing needed a deep WAN interface catalogue, carrier encapsulation maturity and a channel that Foundry did not have. Its strengths were Ethernet switching and core routing, and it refocused on those around 2004.

Why do links to the AccessIron documentation still appear?

The Foundry command reference PDF lived under the AccessIron documentation path and served as a general IronWare CLI reference. Forums and course notes linked it for years, so the path attracts visitors who want switch commands, not router information.

Can an AccessIron router be used today?

Only as a curiosity. T1 and E1 circuits are rare, the software has been unsupported for nearly two decades, and no successor vendor provides firmware or documentation. A FastIron switch is a more useful IronWare-style CLI trainer.

How did AccessIron differ from NetIron?

NetIron was a chassis core router for ISPs and large campuses with full BGP tables and later MPLS. AccessIron was a compact branch router with carrier circuit interfaces, static or RIP and OSPF routing, NAT and access lists.

Which AccessIron models were there?

The product page captured in June 2004 listed the AR1202 and AR1204 (two or four T1 or E1 ports, with VPN variants), the AR1208 and AR1216 (eight or sixteen T1 or E1 ports) and the AR3201 and AR3202 (one or two DS3 circuits, clear channel or channelised). Each had two 10/100 Ethernet ports and BGP. Foundry's filings date the line's introduction to 2004.