On this page
01 What AccessIron was
AccessIron was the Foundry Networks entry into access routing, introduced in 2004 according to Foundry's own quarterly and annual filings (an earlier 2001 date circulates in forum posts but has no primary source). Where NetIron sat in the core, AccessIron was meant for the branch office and the WAN edge: a compact router with Ethernet on the LAN side and T1/E1, fractional T1, serial or ISDN interfaces toward the carrier, running a CLI in the IronWare style so that a Foundry-trained engineer could manage the WAN without learning a second command language. The routing hub covers the protocols involved.
The AR1200 series is the model name most often cited in forum posts and resale listings. Specific model numbers, interface counts and software versions are hedged here because surviving documentation is sparse and inconsistent.
02 Role in the network
An access router terminates a carrier circuit, encapsulates IP in PPP, HDLC or Frame Relay on the WAN side, and routes to the branch LAN. It usually adds NAT, access lists, a DHCP server and static or RIP routing toward headquarters, with OSPF on larger sites. AccessIron did those things. The intended buyer already ran FastIron switches in the branch and BigIron or NetIron at headquarters, and wanted one vendor and one CLI end to end.
| Aspect | AccessIron approach | Comment |
|---|---|---|
| WAN interfaces | T1/E1, fractional T1, serial, ISDN on some models | Circuit types typical of the mid-2000s branch |
| LAN side | Fast Ethernet | Fed a FastIron or EdgeIron switch |
| Routing | Static, RIP, OSPF; NAT and access lists | Adequate for branch use |
| CLI | IronWare style | Main differentiator for Foundry shops |
| Market outcome | Withdrawn within a few years | Branch routing stayed with established vendors |
03 Why it did not last
Foundry built its reputation on Ethernet switching ASICs, where it could beat larger vendors on price per port and forwarding rate. Branch routing rewarded different things: a huge catalogue of WAN interface cards, mature support for every carrier encapsulation, voice integration, and a global reseller channel that already sold one dominant brand. AccessIron offered none of those advantages, and the branch router market was consolidating around incumbents. Foundry withdrew the line around 2004 and concentrated on switching, load balancing and core routing, as described on the company history page.
FoundryNet is an independent archive and reference, not affiliated with Foundry Networks, Brocade, Broadcom or Extreme Networks. The AccessIron documentation is described here, not reproduced.
04 AccessIron in the filings and the archived product page
The dating of AccessIron is where forum memory and the company's own record part company. Foundry's results release for the second quarter of 2004, filed as an 8-K exhibit in July 2004, lists AccessIron enterprise WAN access routers among the products introduced during that quarter, and the release for the following quarter reports continued traction with them. The Form 10-K for 2004 states plainly that the line of AccessIron WAN aggregation routers was introduced in 2004, for T-carrier, E-carrier and T3 interconnection with carrier WAN services, with Ethernet ports on the LAN side. Treat mid-2004 as the documented launch; the earlier dates that circulate, including the approximate range in the summary at the top of this page, have no dated source behind them.
A June 2004 capture of the AccessIron product page fills in the models. The AR1202 and AR1204 carried two or four T1 or E1 ports, with VPN variants of each; the AR1208 and AR1216 carried eight or sixteen; the AR3201 and AR3202 carried one or two DS3 circuits, clear channel or channelised. Every model listed two 10/100 Ethernet ports, 256 MB of SDRAM and BGP, with 16 MB or 32 MB of flash. The feature list named Multilink PPP and Multilink Frame Relay, quality of service, VRRP, BGP multihoming, VLAN tagging, a built-in CSU/DSU, NAT, stateful packet inspection and a transparent Layer 2 mode the page called Virtual Ethernet. Datasheet PDFs captured from the same directory carry August and December 2004 in their file names, which is consistent with the filings.
| AccessIron function (2004) | Vendor-neutral equivalent today | Standard or reference |
|---|---|---|
| NxT1 or NxE1 bundles with Multilink PPP | Ethernet handoff from the carrier; bonding, if needed, by link aggregation or by an SD-WAN overlay | RFC 1990, PPP Multilink; IEEE 802.1AX |
| Clear channel or channelised DS3 | 1 GbE or 10 GbE carrier Ethernet access | MEF carrier Ethernet services |
| Built-in CSU/DSU | Carrier network interface device at the demarcation | Carrier specific |
| Frame Relay to headquarters | Carrier MPLS VPN or IPsec over the Internet | RFC 4364; RFC 4301 |
| VRRP for gateway failover | VRRP, unchanged in purpose | RFC 5798, VRRP version 3 |
| BGP multihoming across two carriers | BGP multihoming, unchanged; route origin validation added | RFC 4271; RFC 6811 |
| Stateful packet inspection and NAT on the router | Stateful firewall or next-generation firewall at the branch edge | RFC 3234 on middleboxes |
Two of those surviving functions are covered on this site: the VRRP election that keeps a default gateway alive and carrier MPLS VPN handoffs that replaced leased circuits.
05 The command reference that outlived the product
The most durable trace of AccessIron is a URL. The Foundry command reference PDF was hosted under the AccessIron documentation path, and because it covered the IronWare command set broadly, forum posts and course notes linked to it as a general Foundry CLI reference for years after the routers themselves disappeared. Many visitors who follow those links are looking for switch commands, not WAN configuration. The CLI command reference page on this site is the place to go for that.
show version show interfaces brief show ip route show ip interface show running-config
06 Running an AccessIron today: what an operator must check
Almost nobody runs one, but units do turn up in branch cupboards where a carrier circuit was cancelled years ago and the router was never removed. The checks are short. Confirm whether any circuit is still terminated (a T1 port with alarms clear and traffic counters moving means a live contract someone is paying for). Confirm console access, since the management address is likely on a subnet nobody remembers. Copy the configuration off. Then decide the replacement: the table above maps each function. Whatever encryption the 2004 VPN image offers, treat it as unsuitable for anything sensitive; the specific algorithms are not stated here because no verified manual lists them.
ar1# show version (record platform, release and serial number) ar1# show interfaces brief (a serial or T1 interface in the up state is still connected to something) ar1# show ip route (static routes reveal where the branch expected headquarters to be) ar1# show ip bgp (an established session means a carrier still peers with this box) ar1# show running-config (copy it off before the unit is powered down) ar1# show log
Pitfalls seen with these units:
- Dating the line from forum posts; the filings put the launch in mid-2004, and any earlier date needs a source.
- Reading the model table as a datasheet; the archived page lists interface counts and memory, not throughput, and it disclaims its own accuracy.
- Assuming IronWare switch syntax carries over exactly; the AccessIron software was IronWare-style, and the command reference hosted under its documentation path is the only reason most people met it.
- Powering down a unit before checking whether the carrier circuit is still billed; the router is worthless, the contract is not.
- Expecting the transparent Layer 2 mode the product page called Virtual Ethernet to behave like a modern Ethernet over MPLS pseudowire; it bridged a LAN across a leased circuit, and a replacement needs a carrier Ethernet service or an overlay, not a like-for-like router.
One last check belongs to the person who inherits the cupboard rather than the router: the AccessIron command reference PDF that old links point at was hosted under this product's documentation path, so a saved copy of that PDF, with its capture date and hash recorded, is worth more to the next engineer than the router itself.
07 AccessIron today
The line is purely historical. T1 and E1 circuits have largely been replaced by Ethernet handoffs and broadband, so the WAN interfaces have no modern use, and there is no software or documentation support from any successor vendor. A surviving unit is a collector item. Its only practical role is as a small IronWare-style CLI trainer if the Ethernet side still works, and even then a FastIron switch is a better and more common choice. The larger router lines that did succeed are profiled with the rest of the catalogue in the archive overview.
08 Questions
What was the Foundry AccessIron?
An early-2000s access router line for branch offices and the WAN edge, with T1/E1, serial and Ethernet interfaces and an IronWare-style CLI. The AR1200 series is the commonly cited model name. Foundry withdrew the line within a few years.
Why did Foundry stop making AccessIron routers?
Branch routing needed a deep WAN interface catalogue, carrier encapsulation maturity and a channel that Foundry did not have. Its strengths were Ethernet switching and core routing, and it refocused on those around 2004.
Why do links to the AccessIron documentation still appear?
The Foundry command reference PDF lived under the AccessIron documentation path and served as a general IronWare CLI reference. Forums and course notes linked it for years, so the path attracts visitors who want switch commands, not router information.
Can an AccessIron router be used today?
Only as a curiosity. T1 and E1 circuits are rare, the software has been unsupported for nearly two decades, and no successor vendor provides firmware or documentation. A FastIron switch is a more useful IronWare-style CLI trainer.
How did AccessIron differ from NetIron?
NetIron was a chassis core router for ISPs and large campuses with full BGP tables and later MPLS. AccessIron was a compact branch router with carrier circuit interfaces, static or RIP and OSPF routing, NAT and access lists.
Which AccessIron models were there?
The product page captured in June 2004 listed the AR1202 and AR1204 (two or four T1 or E1 ports, with VPN variants), the AR1208 and AR1216 (eight or sixteen T1 or E1 ports) and the AR3201 and AR3202 (one or two DS3 circuits, clear channel or channelised). Each had two 10/100 Ethernet ports and BGP. Foundry's filings date the line's introduction to 2004.