1-12
VPN 3002 Hardware Client Getting Started
OL-2854-01
Chapter 1 Understanding the VPN 3002 Hardware Client
Additional Software Features
Load Balancing
Load balancing lets you distribute sessions among two or more VPN Concentrators connected on the
same network to handle remote sessions. Load balancing directs sessions to the least loaded device, thus
distributing the load among all devices. It makes efficient use of system resources and provides increased
performance and high availability. Load balancing requires no configuration on the VPN 3002.
Simple Certificate Enrollment Protocol (SCEP)
You can enroll and install digital certificates on the VPN 3002 automatically or manually. The automatic
method is a new feature that uses the Simple Certificate Enrollment Protocol (SCEP) to streamline
enrollment and installation. SCEP is a secure messaging protocol that requires minimal user
intervention. This method is quicker than enrolling and installing digital certificates manually, but it is
available only if you are both enrolling with a CA that supports SCEP and enrolling via the web. If your
CA does not support SCEP, or if you enroll with digital certificates by a means other than the web (such
as through email or by a diskette), then you cannot use the automatic method; you must use the manual
method.
Reset/Restore Monitoring Statistics
You can now reset and restore statistical data to better note changes in that data. When you click Reset
on a monitoring or administration screen, the system temporarily resets a counter for the chosen statistics
without affecting the operation of the VPN 3002. You can then view statistical information without
affecting the actual current values of the counters or other management sessions. The function is like
that of a vehicle’s trip odometer, versus the regular odometer. Click Restore to return to the actual
statistical values.
XML Management
The VPN 3002 now supports an XML-based interface that lets you use an external management
application.
Cisco management applications, third-party applications that manage our products, and customers who
want to manage their devices using their own infrastructure can use this interface. This feature is enabled
by default; you do not have to configure it.
The XML data can be sent to or uploaded from the VPN Concentrator using HTTPS, SSH, or standard
file transfer mechanisms such as FTP or TFTP.
Reverse Route Injection (RRI)
You can configure the VPN Concentrator to add routes to its routing table for remote hardware or
software clients. The VPN Concentrator can then advertise these routes to its private network via RIP or
OSPF. This feature is called reverse route injection (RRI).
For example, with a VPN 3002 in network extension mode, network extension RRI automatically adds
hosts on the VPN 3002 private network to the VPN Concentrator’s routing table for distribution by either
RIP or OSPF.
RRI requires no configuration on the VPN 3002.