
14
Cisco 1721, 1760, 2621XM, 2651XM, 2691, 3725, and 3745 Modular Access Routers and 7206-VXR NPE-400 Router FIPS 140-2 Non-Proprietary
OL-6083-01
The Cisco 1721, 1760, 2621XM, 2651XM, 2691, 3725, 3745, and 7206 VXR NPE-400 Routers
The cryptographic boundary is defined as encompassing the "top," "front," "left," "right," and "bottom"
surfaces of the case; all portions of the "backplane" of the case which are not designed to accommodate
a WIC or Network Module; and the inverse of the three-dimensional space within the case that would be
occupied by an installed WIC or Network Module. The cryptographic boundary includes the connection
apparatus between the WIC or Network Module and the motherboard/daughterboard that hosts the WIC
or Network Module, but the boundary does not include the WIC or Network Module itself. In other
words, the cryptographic boundary encompasses all hardware components within the case of the device
except any installed modular WICs or Network Modules. All of the functionality discussed in this
document is provided by components within this cryptographic boundary.
Cisco IOS features such as tunneling, data encryption, and termination of Remote Access WANs via
IPSec, Layer 2 Forwarding (L2F) and Layer 2 Tunneling Protocols (L2TP) make the Cisco 2600 an ideal
platform for building virtual private networks or outsourced dial solutions. Cisco 2600`s RISC-based
processor provides the power needed for the dynamic requirements of the remote branch office,
achieving wire speed Ethernet to Ethernet routing with up to 70 thousand packets per second (Kpps)
throughput capacity.
Cisco 2691 Module Interfaces
The interfaces for the router are located on the rear panel as shown in
Figure 11
.
Figure 11
Cisco 2691 Physical Interfaces
The Cisco 2691 router features console and auxiliary ports, dual fixed LAN interfaces, a Network
Module slot, two Cisco WAN interface card (WIC) slots, and a Compact Flash slot.
LAN support includes single and dual Ethernet options; 10/100 Mbps auto-sensing Ethernet; mixed
Token-Ring and Ethernet; and single Token Ring chassis versions. WAN interface cards support a variety
of serial, ISDN BRI, and integrated CSU/DSU options for primary and backup WAN connectivity, while
available Network Modules support multi-service voice/data/fax integration, departmental dial
concentration, and high-density serial options. The AIM slot supports integration of advanced services
such as hardware-assisted data compression and encryption. All Cisco 2600 series routers include an
auxiliary port supporting 115Kbps Dial-On-Demand Routing, ideal for back-up WAN connectivity.
When a Network Module is inserted, it fits into an adapter called the
Network Module expansion bus
.
The expansion bus interacts with the PCI bridge in the same way that the fixed LAN ports do; therefore,
no critical security parameters pass through the Network Module (just as they don't pass through the
LAN ports). Network modules do not perform any cryptographic functions.
99500
SEE MANU
AL BEFORE INST
ALLATION
AL
CD
LP
RD
TD
SEE MANU
AL BEFORE INST
ALLATION
DSU
56K
AL
CD
LP
RD
TD
SEE MANU
AL BEFORE INST
ALLATION
DSU
56K
EN
V0
BANK 4
BANK 3
BANK 2
BANK 1
BANK 0
NM-HDV
VWIC
2MFT-E1
SEE
MANUAL
BEFORE
INSTALLAT
ION
CTRLR E2
CTRLR E1
AL
LP
CD
2
3
5
6
9
4
8
7
1