1-4
VPN Acceleration Module 2+ (VAM2+) Installation and Configuration Guide
OL-5979-03
Chapter 1 Overview
Features
•
Data Encryption Standard (DES) standard mode with 56-bit key: Cipher Block Chaining (CBC)
•
3-Key Triple DES (168-bit) algorithms at speeds up to 292 Mbps
•
128/192/256-bit Advanced Encryption Standard (AES) in hardware
•
Performance to OC3 full duplex with 300 byte packets
•
Up to 5000 tunnels for DES/3DES/AES
•
Provides compression with IPSec at no extra overhead (LZS)
•
Secure Hash Algorithm (SHA)-1 and Message Digest 5 (MD5) hash algorithms
•
Rivest, Shamir, Adelman (RSA) public-key algorithm
•
Diffie-Hellman Groups 1, 2 and 5
•
Online Insertion and Removal (OIR)
Features
This section describes the SA-VAM2+ features, as listed in
Table 1-1
.
Table 1-1
SA-VAM2+ Features
Feature
Description/Benefit
Throughput
1
1.
As measured with IPSec 3DES HMAC-SHA1 on 1400-byte packets.
Up to 292 Mbps using 3DES on the Cisco 7200VXR routers,
and up to 392 Mbps using 3DES on the Cisco 7301 router
Note
The number of IPSec tunnels depends on packet size
Number of IPSec protected tunnels
2
2.
Number of tunnels supported varies based on the total system memory installed.
Up to 5000 tunnels
3
Number of tunnels per second
Up to 50
Hardware-based encryption
Data protection: IPSec DES, 3DES, AES, IPv6 IPSec
Authentication: RSA and Diffie-Hellman
Data integrity: SHA-1 and Message Digest 5 (MD5)
VPN tunneling
IPsec tunnel mode; Generic Routing Encapsulation (GRE) and
Layer 2 Tunneling Protocol (L2TP) protected by IPSec
Hardware-based compression
Layer 3 IPPCP LZS
Standards supported
IPSec/IKE: RFCs 2401-2411, 2451
IPPCP: RFC 2393, 2395
(Optional) Port Adapter Jacket Card
The Port Adapter Jacket Card is available on the
Cisco 7200VXR router with the NPE-G1 or NPE-G2
4
processor.
Note
The Port Adapter Jacket Card supported on the
Cisco 7200VXR router with the NPE-G2 is available
on Cisco IOS Release 12.4(4)XD1 or later.
The Port Adapter Jacket Card supported on the
Cisco 7200VXR router with the NPE-G2 is available
on Cisco IOS Release 12.4(4)XD or later.