
Release 3.5 New Software Features
6
Release Notes for Cisco VPN 3002 Hardware Client Release 3.5.2
Note To use RADIUS password expiry with a VPN 3002, you must enable
interactive hardware client authentication. This feature does not work for
individual user authentication.
Backup IPSec Servers
IPSec backup servers let a VPN 3002 Hardware Client connect to the central site
when its primary central-site VPN Concentrator is unavailable. You configure
backup servers for a VPN 3002 either on the VPN 3002 or on a group basis at the
VPN Concentrator. If you configure backup servers on the central-site VPN
Concentrator, that VPN Concentrator pushes the backup server list to the
VPN 3002 hardware clients in the group.
Load Balancing
Load balancing lets you distribute sessions among two or more VPN
Concentrators connected on the same network to handle remote sessions. Load
balancing directs sessions to the least loaded device, thus distributing the load
among all devices. It makes efficient use of system resources and provides
increased performance and high availability. Load balancing requires no
configuration on the VPN 3002.
Simple Certificate Enrollment Protocol (SCEP)
You can enroll and install digital certificates on the VPN 3002 automatically or
manually. The automatic method is a new feature that uses the Simple Certificate
Enrollment Protocol (SCEP) to streamline enrollment and installation. SCEP is a
secure messaging protocol that requires minimal user intervention. This method
is quicker than enrolling and installing digital certificates manually, but it is
available only if you are both enrolling with a CA that supports SCEP and
enrolling via the web. If your CA does not support SCEP, or if you enroll with
digital certificates by a means other than the web (such as through email or by a
diskette), then you cannot use the automatic method; you must use the manual
method.
Comentarios a estos manuales