Cisco VPN Security Routers: Setting The Standard in Site-to-Site VPN Solutions
Cisco VPN Security Routers: Setting The Standard in Site-to-Site VPN Solutions
Cisco VPN Security Routers: Setting The Standard in Site-to-Site VPN Solutions
Built on Cisco IOS® Software, Cisco VPN VPN security routers also support
security routers take advantage of manageable and scalable meshed VPN
best-in-market wide-area networking topologies. The Cisco Dynamic
services to set the standard in site-to-site Multipoint VPN (DMVPN) feature
VPN solutions. Important site-to-site VPN makes deployment of meshed VPNs
features of Cisco VPN security routers easier by automating provisioning of
include: connections between spoke sites.
• Support for diverse networking Furthermore, DMVPN dynamically
environments—IP security (IPSec) is a sets up connections based on network
unicast, IP-only protocol. Cisco VPN traffic patterns, increasing scalability of
security routers, using Cisco IOS meshed deployments.
Software features, accommodate • Timely, reliable delivery of
multicast and multiprotocol traffic, as latency-sensitive traffic—Bandwidth
well as routing across the VPN, management features of Cisco VPN
delivering flexible solutions for the security routers enable traffic to be
most diverse VPN environments. Cisco prioritized up to the application layer,
facilitating differentiated
Figure 1 quality-of-service (QoS) policies by true
Cisco IOS VPN Routers application type, not just TCP port
number. The result is increased
transmission reliability and better
response time of business-critical
applications running across the VPNs.
VPN Modular
Site Model Performance Tunnels Embedded Interfaces Interface Options
Branch Cisco 2691 80 Mbps 1000 Single -or- Serial, DSL, ATM, ISDN,
Office Dual 10/100BaseT E/FE, Voice
Cisco 7400 120 Mbps 5000 Dual 10/100/1000BaseT -none-
Cisco 3725 150 Mbps 2000 None, Single, -or- Serial, DSL, ATM, ISDN,
Dual 10/100BaseT E/FE, Voice
Cisco 7200 225 Mbps 5000 Dual 10/100/1000BaseT Serial, POS, ATM, ISDN,
E/FE/GE, Voice
“VPN Performance” is determined using IPSec Triple Data Encryption Standard (3DES) HMAC-SHA1 on 1400-byte packets
Using Internet transport, VPNs cut recurring WAN costs by 50 percent or more compared with traditional WAN
technologies such as Frame Relay. And unlike Frame Relay, VPNs can be easily and quickly extended to new
locations and extranet business partners.
VPNs enable secure use of cost-effective, high-speed links such as DSL to deliver revenue-generating applications
such as in-store online catalogs and ordering and efficiency tools such as online training.
Traditional WANs using Frame Relay, leased lines, or ATM provide traffic segregation, not transport security. VPNs
encrypt and authenticate traffic traversing the WAN to deliver true network security in an insecure, networked world.
VPN Tunneling
• IPSec (RFC 2401-2411, 2451)
• GRE (RFC 1701-1702)
• L2TP (RFC 2661)
• PPTP (RFC 2637)
Encryption
• ESP DES, 3DES, and AES (RFC 2406, 2451)
• MPPE RC4 (40/128 bit)
Authentication
• X.509 digital certificates (RSA signatures)
• Shared secrets
• Simple Certificate Enrollment Protocol
• RADIUS (RFC 2138)
• TACACS+
• CHAP/PAP (RFC 1994)
Integrity
• HMAC-MD5 & HMAC-SHA-1 (RFC 2403-2404)
Key Management
• Internet Key Exchange (RFC 2407-2409)
• IKE-XAUTH
• IKE-CFG-MODEIP Compression
• IPPCP-LZS (RFC 2401-2402)
Resiliency
• Hot Standby Router Protocol (HSRP)
• IKE Keep-Alives
• Routing across IPSec
• Dynamic Multipoint for IPSec
Management Options
• CiscoWorks VPN/Security Management Solution (VMS)
– The CiscoWorks Router Management Center, a component of Cisco VMS, provides scalable security
management for the configuration and deployment of VPN connections.
• Cisco VPN Solution Center for Service Provider Networks
• Secure command-line interface using secure shell (SSH) or kerberized telnet
Routing Protocols
• BGP4
• RIP/RIP2
• OSPF
• EIGRP/IGRP
• NHRP
• IS-IS
Security
• Context Based Access Control (CBAC) stateful firewall
• Java blocking
• Active audit intrusion detection
• Denial-of-service detection and prevention
Security Certifications
• FIPS-140-1, level 2
• ICSA IPsec
• Common Criteria IPSec
• For more information, visit
http://www.cisco.com/warp/public/779/largeent/issues/security/secvpncert.html
Cisco Systems has more than 200 offices in the following countries and regions. Addresses, phone numbers, and fax numbers are listed on the
C i s c o W e b s i t e a t w w w . c i s c o . c o m / g o / o f fi c e s
Argentina • Australia • Austria • Belgium • Brazil • Bulgaria • Canada • Chile • China PRC • Colombia • Costa Rica • Croatia
Czech Republic • Denmark • Dubai, UAE • Finland • France • Germany • Greece • Hong Kong SAR • Hungary • India • Indonesia • Ireland
Israel • Italy • Japan • Korea • Luxembourg • Malaysia • Mexico • The Netherlands • New Zealand • Norway • Peru • Philippines • Poland
Portugal • Puerto Rico • Romania • Russia • Saudi Arabia • Scotland • Singapore • Slovakia • Slovenia • South Africa • Spain • Sweden
S w i t z e r l a n d • Ta i w a n • T h a i l a n d • Tu r k e y • U k r a i n e • U n i t e d K i n g d o m • U n i t e d S t a t e s • Ve n e z u e l a • Vi e t n a m • Z i m b a b w e
All contents are Copyright © 1992–2002, Cisco Systems, Inc. All rights reserved. Cisco, Cisco Systems, Cisco IOS, and the Cisco Systems logo are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates
in the U.S. and certain other countries.
All other trademarks mentioned in this document or Web site are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
(0208R) LW3851 11/02