
All contents are Copyright © 1992–2006 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 7 of 10
Hardware Configuration 1U Scalable 2U Fixed 2U Scalable 2U Scalable 2U Fixed 2U
Dual Power Supply Single Optional Optional Optional Optional Yes
Client License Unlimited Unlimited Unlimited Unlimited Unlimited Unlimited
*Assumes maximum device memory and SEP-E modules (Cisco VPN 3020, 3030, 3060, and 3080 models). For planning purposes, a simultaneous IPsec user is
considered to be a remote-access VPN user connected in all-tunneling mode; this includes one IKE security association and two unidirectional IPsec security
associations. Network sizing should take into consideration number of sessions, throughput per user, and aggregate throughput of the remote-access environment
when choosing the appropriate Cisco VPN 3000 Series Concentrator model.
**Assumes maximum device memory and SEP-E modules (Cisco VPN 3020, 3030, 3060, and 3080 models). For planning purposes, a simultaneous SSL VPN
user is considered to be a clientless VPN user retrieving a Webpage at up to every 60 seconds. Users log in at the rate of one per second and pass data for the
duration of the test. The average retrieval time for the Webpage is less than or equal to five seconds.
TECHNICAL SPECIFICATIONS
Hardware
Processor Motorola PowerPC processor
Memory
●
Redundant system images (Flash)
●
Variable memory options (Figure 6)
Encryption
●
Cisco VPN 3005, 3015: Software
●
Cisco VPN 3020, 3030, 3060, and 3080: Hardware
Embedded LAN Interfaces
●
Cisco VPN 3005: Two autosensing, full-duplex 10/100BASE-TX Fast Ethernet (public/untrusted, private/trusted)
●
Cisco VPN 3015, 3020, 3030, 3060, and 3080: Three autosensing, full-duplex 10/100BASE-TX Fast Ethernet
(public/untrusted, private/trusted, and DMZ)
Instrumentation
●
Cisco VPN 3005: Unit status indicator (front panel); status LEDs for Ethernet ports (rear panel)
●
Cisco VPN 3015, 3020, 3030, 3060, and 3080: Status LEDs for system, expansion modules, power supplies, Ethernet
modules, and fan (front panel); status LEDs for Ethernet modules, expansion modules, and power supplies (rear panel)
●
Cisco VPN 3015, 3020, 3030, 3060, and 3080: Activity monitor displays the number of sessions, aggregate throughput, or
CPU utilization, and is push-button selectable
Software
Client Software Compatibility
●
Cisco SSL VPN Client for network-layer connectivity using an SSL-capable Web browser on remote system
●
Cisco IPsec VPN Client for Windows 98, ME, NT 4.0, 2000, and XP; Linux (Intel); Solaris (UltraSparc 32- and 64-bit); and Mac
OS X 10.2, 10.3, and 10.4, including centralized split-tunneling control and data compression
●
Microsoft PPTP, Microsoft Point-to-Point Encryption (MPPE), and Microsoft Point-to-Point Compression (MPPC); Microsoft
Challenge Handshake Authentication Protocol (MSCHAP) v1 and v2; and Extensible Authentication Protocol (EAP) and
RADIUS passthrough for EAP-Transport Layer Security (EAP-TLS) and EAP-Generic Token Card (EAP-GTC) support
●
Microsoft L2TP and IPsec for Windows 2000 and XP, including Windows XP Dynamic Host Control Protocol (DHCP) option for
route population
●
Microsoft L2TP and IPsec for Windows 98, ME, and NT Workstation 4.0
Tunneling Protocols
●
Cisco SSL VPN (HTTPS/SSL-based)
●
IPsec, PPTP, L2TP, L2TP/IPsec, NAT Transparent IPsec, Ratified IPsec/UDP (with autodetection and fragmentation
avoidance), IPsec/TCP
●
Support for Cisco EasyVPN (client and network extension mode)
Encryption/Authentication
●
IPsec Encapsulating Security Payload (ESP) using DES/3DES (56/168-bit) or AES (128/192/256-bit) with Message Digest
Algorithm 5 (MD5) or Secure Hashing Algorithm (SHA); or MPPE using 40/128-bit RC4
Key Management
●
Internet Key Exchange (IKE)
●
Diffie-Hellman (DH) groups 1, 2, 5, and 7 (ECDH)
●
RSA certificates (SSL and IPsec)
Routing
●
Routing Initiation Protocol (RIP), RIPv2, Open Shortest Path First (OSPF), Reverse Route Injection (RRI), static routing,
automatic endpoint discovery, NAT, and Classless Interdomain Routing (CIDR)
●
IPsec fragmentation policy control, including support for Path Maximum Transmission Unit (MTU) Discovery (PMTUD)
●
Interface MTU control
Third-Party Compatibility iPass Ready, Funk Steel-Belted RADIUS, Microsoft Internet Explorer, Netscape Communicator, Entrust, Baltimore, and SA Keon
High Availability
●
Virtual Router Redundancy Protocol (VRRP) for multichassis redundancy and multichassis failover
●
Remote-access load-balancing clusters supporting both SSL and IPsec connections
●
Destination pooling for client-based failover, re-establishment, and connection re-establishment
●
Redundant SEP modules (optional), power supplies, and fans (Cisco VPN 3015, 3020, 3030, 3060, and 3080 models)
Comentarios a estos manuales